logo Welcome, Guest. Please Login or Register.
2024-05-15 11:36:05 CoV Wiki
Learn more about the Church of Virus
Home Help Search Login Register
News: Read the first edition of the Ideohazard

  Church of Virus BBS
  Mailing List
  Virus 2003

  RE: virus: Appeal for advice
« previous next »
Pages: [1] Reply Notify of replies Send the topic Print 
   Author  Topic: RE: virus: Appeal for advice  (Read 820 times)
Blunderov
Archon
*****

Gender: Male
Posts: 3160
Reputation: 8.90
Rate Blunderov



"We think in generalities, we live in details"

View Profile WWW E-Mail
RE: virus: Appeal for advice
« on: 2003-09-02 13:32:08 »
Reply with quote

This is nothing to do with virus but I thought I would just ask anyway:

I have been getting a lot of mail returned to me as undeliverable. The
trouble is I never sent out the mail which is being returned to me. Some
mail is entitled 'that movie', a title which I have never used, some is
entitled 'my details' which IS a title I have used sometimes in my
former scambaiting activities.

I have checked and rechecked my machine for all worms and viruses - I'm
clean. In fact I have completely reformatted ALL my drives and
reinstalled from scratch just in case I had unknown malevolent code
somewhere.

Is someone using my address somehow? ( I have another web based address,
besides my mweb address; citizenx@postmaster.co.uk) I'm quite puzzled
about what is going on. Probably it is a coincidence but quite a number
of the returned mails have been addressed to military addresses which is
somewhat alarming.

Here is a sample. I have never sent any mail entitled 'Your application'
to anyone, let only anyone in the US Military.

<q>
Received: from  akomta3 (proxyip8.us.army.mil [140.183.234.122]) by
rly-yc04.mx.aol.com (v95.1) with ESMTP id MAILRELAYINYC42-1ce3f533cdfbb;
Mon, 01 Sep 2003 08:34:39 -0400
Received: from mailrouter.us.army.mil (akomta3 [10.234.26.13])
by mailrouter.us.army.mil (AKO MTA - MTA3)
with ESMTP id <0HKJ00G6KC9QWL@akomta3.us.army.mil> for
cjones2420@aol.com
(ORCPT clifford.byrd@us.army.mil); Mon, 01 Sep 2003 08:34:39 -0400
(EDT)
Received: from DOLLY (adsl-67-65-239-156.dsl.lbcktx.swbell.net
[67.65.239.156])
by mailrouter.us.army.mil (AKO MTA - MMP3)
with ESMTP id <0HKJ00953C83V7@mailrouter.us.army.mil> for
cjones2420@aol.com
(ORCPT clifford.byrd@us.army.mil); Mon, 01 Sep 2003 08:34:38 -0400
(EDT)
Date: Mon, 01 Sep 2003 07:33:45 +0500
From: squooker@mweb.co.za
Subject: Re: Your application
To: clifford.byrd@us.army.mil
Message-id: <0HKJ00956C83V7@mailrouter.us.army.mil>
MIME-version: 1.0
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
Content-type: multipart/mixed;
boundary="Boundary_(ID_AxgRPz7g1BODm9AIwm7CxA)"
Importance: Normal
X-Priority: 3 (Normal)
X-MSMail-priority: Normal
X-MailScanner: Found to be clean
X-AOL-IP: 140.183.234.122
X-AOL-SCOLL-SCORE: 0:XXX:XX
X-AOL-SCOLL-URL_COUNT: 0
</q>

All of which is Greek to me, or nearly so. I would be most grateful to
any virus boffin who has the time and is able to give me some advice
about all this.

Thanks
Blunderov




---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged
JD
Adept
****

Gender: Male
Posts: 542
Reputation: 7.26
Rate JD





View Profile
RE: virus: Appeal for advice
« Reply #1 on: 2003-09-02 13:52:55 »
Reply with quote

Hi Blunderlov,

Don't worry about it. This is the Sobig.e worm spoofing your address
elsewhere. It is part of its normal behaviour, You can safely ignore these
returned messages as they are not evidence that you are infected. 

You can read more here:

http://in.tech.yahoo.com/030626/137/25gzb.html

Regards

Jonathan



-----Original Message-----
From: owner-virus@lucifer.com [mailto:owner-virus@lucifer.com] On Behalf Of
Blunderov
Sent: 02 September 2003 18:32
To: virus@lucifer.com
Subject: RE: virus: Appeal for advice

This is nothing to do with virus but I thought I would just ask anyway:

I have been getting a lot of mail returned to me as undeliverable. The
trouble is I never sent out the mail which is being returned to me. Some
mail is entitled 'that movie', a title which I have never used, some is
entitled 'my details' which IS a title I have used sometimes in my former
scambaiting activities.

I have checked and rechecked my machine for all worms and viruses - I'm
clean. In fact I have completely reformatted ALL my drives and reinstalled
from scratch just in case I had unknown malevolent code somewhere.

Is someone using my address somehow? ( I have another web based address,
besides my mweb address; citizenx@postmaster.co.uk) I'm quite puzzled about
what is going on. Probably it is a coincidence but quite a number of the
returned mails have been addressed to military addresses which is somewhat
alarming.

Here is a sample. I have never sent any mail entitled 'Your application'
to anyone, let only anyone in the US Military.

<q>
Received: from  akomta3 (proxyip8.us.army.mil [140.183.234.122]) by
rly-yc04.mx.aol.com (v95.1) with ESMTP id MAILRELAYINYC42-1ce3f533cdfbb;
Mon, 01 Sep 2003 08:34:39 -0400
Received: from mailrouter.us.army.mil (akomta3 [10.234.26.13])  by
mailrouter.us.army.mil (AKO MTA - MTA3)  with ESMTP id
<0HKJ00G6KC9QWL@akomta3.us.army.mil> for cjones2420@aol.com  (ORCPT
clifford.byrd@us.army.mil); Mon, 01 Sep 2003 08:34:39 -0400
(EDT)
Received: from DOLLY (adsl-67-65-239-156.dsl.lbcktx.swbell.net
[67.65.239.156])
by mailrouter.us.army.mil (AKO MTA - MMP3)  with ESMTP id
<0HKJ00953C83V7@mailrouter.us.army.mil> for cjones2420@aol.com  (ORCPT
clifford.byrd@us.army.mil); Mon, 01 Sep 2003 08:34:38 -0400
(EDT)
Date: Mon, 01 Sep 2003 07:33:45 +0500
From: squooker@mweb.co.za
Subject: Re: Your application
To: clifford.byrd@us.army.mil
Message-id: <0HKJ00956C83V7@mailrouter.us.army.mil>
MIME-version: 1.0
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
Content-type: multipart/mixed;
boundary="Boundary_(ID_AxgRPz7g1BODm9AIwm7CxA)"
Importance: Normal
X-Priority: 3 (Normal)
X-MSMail-priority: Normal
X-MailScanner: Found to be clean
X-AOL-IP: 140.183.234.122
X-AOL-SCOLL-SCORE: 0:XXX:XX
X-AOL-SCOLL-URL_COUNT: 0
</q>

All of which is Greek to me, or nearly so. I would be most grateful to any
virus boffin who has the time and is able to give me some advice about all
this.

Thanks
Blunderov




---
To unsubscribe from the Virus list go to
<http://www.lucifer.com/cgi-bin/virus-l>

---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged
rhinoceros
Archon
*****

Gender: Male
Posts: 1318
Reputation: 8.27
Rate rhinoceros



My point is ...

View Profile WWW E-Mail
RE: virus: Appeal for advice
« Reply #2 on: 2003-09-02 14:03:16 »
Reply with quote

[Blunderov]
I have been getting a lot of mail returned to me as undeliverable. The trouble is I never sent out the mail which is being returned to me. Some mail is entitled 'that movie', a title which I have never used, some is entitled 'my details' which IS a title I have used sometimes in my former scambaiting activities.

<snip>


[rhinoceros]
No need to worry, Blunderov. We all receive them these days.

Someone who had your e-mail address in their address book was infected by a virus. Then the virus started sending out infected e-mails to addresses it found there, using your own address, which was also found there, as a return address ("From:") .

Some of these emails were sent to addresses which were no longer valid. So, those messages were "returned" to you as undelivered, because they appeared as sent by you.

And don't worry about looking bad. One can easily see in the headers that the "From:" address was not really the address from which they were sent from.


If you are still curious about the route this message followed, you can follow the "Received from" "by" lines, starting from the last one and going upwards. Keep in mind that some of the bottom "Received from" "by" lines can also be fake.
Report to moderator   Logged
Blunderov
Archon
*****

Gender: Male
Posts: 3160
Reputation: 8.90
Rate Blunderov



"We think in generalities, we live in details"

View Profile WWW E-Mail
RE: virus: Appeal for advice
« Reply #3 on: 2003-09-02 14:02:39 »
Reply with quote

Thanks very much! It is a great relief to know that. Do you happen to
know why this virus seems to like the US Military so much?

Best Regards
Blunderov

-----Original Message-----
From: owner-virus@lucifer.com [mailto:owner-virus@lucifer.com] On Behalf
Of Jonathan Davis
Sent: 02 September 2003 07:53 PM
To: virus@lucifer.com
Subject: RE: virus: Appeal for advice

Hi Blunderlov,

Don't worry about it. This is the Sobig.e worm spoofing your address
elsewhere. It is part of its normal behaviour, You can safely ignore
these
returned messages as they are not evidence that you are infected. 

You can read more here:

http://in.tech.yahoo.com/030626/137/25gzb.html

Regards

Jonathan




---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged
Blunderov
Archon
*****

Gender: Male
Posts: 3160
Reputation: 8.90
Rate Blunderov



"We think in generalities, we live in details"

View Profile WWW E-Mail
RE: virus: Appeal for advice
« Reply #4 on: 2003-09-02 14:25:00 »
Reply with quote

Thank you Rhinoceros! Apparently all that header stuff is not nearly as
much Greek to you as it is to me Having thought about what you say, I
have decided to stop worrying about whether I am an oft-recurring
address in US military address books, which is also quite a weight off
my mind. Probably, it seems to me, I can continue to leave my cell phone
on.

Best Regards
Blunderov



-----Original Message-----
From: owner-virus@lucifer.com [mailto:owner-virus@lucifer.com] On Behalf
Of rhinoceros
Sent: 02 September 2003 08:03 PM
To: virus@lucifer.com
Subject: RE: virus: Appeal for advice


[Blunderov]
I have been getting a lot of mail returned to me as undeliverable. The
trouble is I never sent out the mail which is being returned to me. Some
mail is entitled 'that movie', a title which I have never used, some is
entitled 'my details' which IS a title I have used sometimes in my
former scambaiting activities.

<snip>


[rhinoceros]
No need to worry, Blunderov. We all receive them these days.

Someone who had your e-mail address in their address book was infected
by a virus. Then the virus started sending out infected e-mails to
addresses it found there, using your own address, which was also found
there, as a return address ("From:") .

Some of these emails were sent to addresses which were no longer valid.
So, those messages were "returned" to you as undelivered, because they
appeared as sent by you.

And don't worry about looking bad. One can easily see in the headers
that the "From:" address was not really the address from which they were
sent from.


If you are still curious about the route this message followed, you can
follow the "Received from" "by" lines, starting from the last one and
going upwards. Keep in mind that some of the bottom "Received from" "by"
lines can also be fake.


----
This message was posted by rhinoceros to the Virus 2003 board on Church
of Virus BBS.
<http://virus.lucifer.com/bbs/index.php?board=54;action=display;threadid
=29195>
---
To unsubscribe from the Virus list go to
<http://www.lucifer.com/cgi-bin/virus-l>


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged
Ant
Neophyte
**

Gender: Male
Posts: 12
Reputation: 0.00





View Profile WWW
Re: virus: Appeal for advice
« Reply #5 on: 2003-09-02 15:10:52 »
Reply with quote

[[ author reputation (0.00) beneath threshold (3)... display message ]]

Report to moderator   Logged
rhinoceros
Archon
*****

Gender: Male
Posts: 1318
Reputation: 8.27
Rate rhinoceros



My point is ...

View Profile WWW E-Mail
RE: virus: Appeal for advice
« Reply #6 on: 2003-09-02 15:25:11 »
Reply with quote

[Ant]
"... was not really the address from which they were sent from."

One too many from, here. The superfluous preposition meme strikes again!


[rhinoceros]
Heh... This meme catches on easily in these parts of the world...

Hey! You have an eye for the detail. You will find it useful here!

« Last Edit: 2003-09-02 15:26:56 by rhinoceros » Report to moderator   Logged
Walter Watts
Archon
*****

Gender: Male
Posts: 1571
Reputation: 8.89
Rate Walter Watts



Just when I thought I was out-they pull me back in

View Profile WWW E-Mail
Re: virus: Appeal for advice
« Reply #7 on: 2003-09-02 17:51:23 »
Reply with quote

I got the same message undeliverable from:

"Received: from  akomta3 (proxyip8.us.army.mil [140.183.234.122]"

and have never sent to that address, Blunderov.

My PC is virus-free.

My suggestion, after a visit to "HouseCall" that says your PC is OK is to not worry
about it.

Take Care,
Walter



Blunderov wrote:

> This is nothing to do with virus but I thought I would just ask anyway:
>
> I have been getting a lot of mail returned to me as undeliverable. The
> trouble is I never sent out the mail which is being returned to me. Some
> mail is entitled 'that movie', a title which I have never used, some is
> entitled 'my details' which IS a title I have used sometimes in my
> former scambaiting activities.
>
> I have checked and rechecked my machine for all worms and viruses - I'm
> clean. In fact I have completely reformatted ALL my drives and
> reinstalled from scratch just in case I had unknown malevolent code
> somewhere.
>
> Is someone using my address somehow? ( I have another web based address,
> besides my mweb address; citizenx@postmaster.co.uk) I'm quite puzzled
> about what is going on. Probably it is a coincidence but quite a number
> of the returned mails have been addressed to military addresses which is
> somewhat alarming.
>
> Here is a sample. I have never sent any mail entitled 'Your application'
> to anyone, let only anyone in the US Military.
>
> <q>
> Received: from  akomta3 (proxyip8.us.army.mil [140.183.234.122]) by
> rly-yc04.mx.aol.com (v95.1) with ESMTP id MAILRELAYINYC42-1ce3f533cdfbb;
> Mon, 01 Sep 2003 08:34:39 -0400
> Received: from mailrouter.us.army.mil (akomta3 [10.234.26.13])
>  by mailrouter.us.army.mil (AKO MTA - MTA3)
>  with ESMTP id <0HKJ00G6KC9QWL@akomta3.us.army.mil> for
> cjones2420@aol.com
>  (ORCPT clifford.byrd@us.army.mil); Mon, 01 Sep 2003 08:34:39 -0400
> (EDT)
> Received: from DOLLY (adsl-67-65-239-156.dsl.lbcktx.swbell.net
> [67.65.239.156])
>  by mailrouter.us.army.mil (AKO MTA - MMP3)
>  with ESMTP id <0HKJ00953C83V7@mailrouter.us.army.mil> for
> cjones2420@aol.com
>  (ORCPT clifford.byrd@us.army.mil); Mon, 01 Sep 2003 08:34:38 -0400
> (EDT)
> Date: Mon, 01 Sep 2003 07:33:45 +0500
> From: squooker@mweb.co.za
> Subject: Re: Your application
> To: clifford.byrd@us.army.mil
> Message-id: <0HKJ00956C83V7@mailrouter.us.army.mil>
> MIME-version: 1.0
> X-Mailer: Microsoft Outlook Express 6.00.2600.0000
> Content-type: multipart/mixed;
> boundary="Boundary_(ID_AxgRPz7g1BODm9AIwm7CxA)"
> Importance: Normal
> X-Priority: 3 (Normal)
> X-MSMail-priority: Normal
> X-MailScanner: Found to be clean
> X-AOL-IP: 140.183.234.122
> X-AOL-SCOLL-SCORE: 0:XXX:XX
> X-AOL-SCOLL-URL_COUNT: 0
> </q>
>
> All of which is Greek to me, or nearly so. I would be most grateful to
> any virus boffin who has the time and is able to give me some advice
> about all this.
>
> Thanks
> Blunderov
>
> ---
> To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

--

Walter Watts
Tulsa Network Solutions, Inc.

"Reminding you to help control the human population. Have your sexual partner spayed
or neutered."


---
To unsubscribe from the Virus list go to <http://www.lucifer.com/cgi-bin/virus-l>

Report to moderator   Logged

Walter Watts
Tulsa Network Solutions, Inc.


No one gets to see the Wizard! Not nobody! Not no how!
Pages: [1] Reply Notify of replies Send the topic Print 
Jump to:


Powered by MySQL Powered by PHP Church of Virus BBS | Powered by YaBB SE
© 2001-2002, YaBB SE Dev Team. All Rights Reserved.

Please support the CoV.
Valid HTML 4.01! Valid CSS! RSS feed