clintswan: (Default)
[personal profile] clintswan
I just looked at my email and I received an email from myself this morning when I KNOW I was was alseep.

It has a zipped file attached with a text file and a DAT file within.

WTF!!!

Any techno geeks out there can help me out as to WTF happened?

Date: 2002-06-22 04:21 pm (UTC)
From: [identity profile] ours-garou.livejournal.com

What were the names of the files attached to that e-mail?

Date: 2002-06-22 04:47 pm (UTC)
From: [identity profile] clintswan.livejournal.com
DLGSTRFR.TXT and Editio.bat

with a sublect line of De la partition tronqu

Date: 2002-06-22 04:56 pm (UTC)
From: [identity profile] ours-garou.livejournal.com

I can't find a viral match for that particular filename/subject. I suspect it's SPAM. Spammers will sometimes "spoof" e-mail so that it appears to come from your address. (Thus prventing you from chewing them a new one, since if you reply, you'll reply to yourself.) The subject line "Truncated Partition" (the English translation of the French subject you gave me) suggests that the files are intended to help with hard drive damage in some fashion. But I wouldn't play around with those files. Just nuke them.

If you haven't already, install a good virus scanner like Norton Antivirus, and keep its definition files up-to-date. That'll help you sleep a little easier at night.

From: [identity profile] clintswan.livejournal.com
Return-Path: <jose@gabinoadvertising.com>
Received: from rly-xj05.mx.aol.com (rly-xj05.mail.aol.com [172.20.116.42]) by air-xj03.mail.aol.com (v86_r1.13) with ESMTP id MAILINXJ33-0622140220; Sat, 22 Jun 2002 14:02:20 -0400
Received: from rly-ip02.mx.aol.com (rly-ip02.mx.aol.com [152.163.225.160]) by rly-xj05.mx.aol.com (v86_r1.13) with ESMTP id MAILRELAYINXJ55-0622140204; Sat, 22 Jun 2002 14:02:04 -0400
Received: from logs-mtc-ta.proxy.aol.com (logs-mtc-ta.proxy.aol.com [64.12.105.5]) by rly-ip02.mx.aol.com (v83.35) with ESMTP id RELAYIN8-0622140156; Sat, 22 Jun 2002 14:01:56 -0400
Received: from Apuabibm (ACAA6D68.ipt.aol.com [172.170.109.104])
by logs-mtc-ta.proxy.aol.com (8.10.0/8.10.0) with SMTP id g5MI0Dq404083
for <txcrewcut@aol.com>; Sat, 22 Jun 2002 14:00:13 -0400 (EDT)
Date: Sat, 22 Jun 2002 14:00:13 -0400 (EDT)
Message-Id: <200206221800.g5MI0Dq404083@logs-mtc-ta.proxy.aol.com>
From: txcrewcut <txcrewcut@aol.com>
To: txcrewcut@aol.com
Subject: De la partition tronqu
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=LRX98p0j4V2EGKX3059e9l2p6Nv4270
X-Apparently-From: TWOCOWBOYSFUN@aol.com
From: [identity profile] ours-garou.livejournal.com

If you check the original header you posted (which is somewhat scrambled because of all the unescaped "<" and ">" characters in it, which web browsers read as HTML tags), you'll see....

Return-Path: <jose@gabinoadvertising.com>

So, yeah, like I thought. SPAM. Roundfile it and set up a mail rule to block e-mail that comes from your own e-mail address. That'll keep people from doing this to you again.

Date: 2002-06-22 04:21 pm (UTC)
From: [identity profile] visualeffect.livejournal.com
Delete it. Spammers often disguise the FROM: field to make it look like you sent it, or even that someone sent it. Checking the header you can see it was sent from an IP other than yours.

Never open any attachment that you are wary about, unless you use something that scans your mail for Viri.

Date: 2002-06-22 04:37 pm (UTC)
From: [identity profile] michaelnolan.livejournal.com
It's most likely a virus.

<lj user=micks> has it right ...

Date: 2002-06-22 05:31 pm (UTC)
From: [identity profile] henare.livejournal.com
it's safe to throw it away--the files almost certainly contain a virus load. if you know anything about dos commands you can use notepad to look inside the .bat file to see what's there ... but it's safer to just delete the message (and the files, which are almost certainly stored on your hard disk by now).

and go get an antivirus! you can download a trial version from www.symantec.com and you can *buy* a copy for about $19 (after rebates) from compusa usually ...

Date: 2002-06-23 06:20 am (UTC)
From: [identity profile] atl10sbum.livejournal.com
Hi.. It is definately a virus. I have been receiving zip files from our companies server with attachments at all hours, and I know our offices are not even open, so I just delete. good luck

Date: 2002-06-24 09:03 am (UTC)
From: [identity profile] zoxobear.livejournal.com
Yeh always just delete things such as that, chances are you already have a virus on your system, that is sending to random entrys on your address book. Do you use Outlook Express?
Do you have a virii scan program on your system currently? If not definately look into
getting one, even if you just download a trial version to check your system it is definately
a good idea.

..:: ZoxoBear ::..
http://www.livejournal.com/users/zoxobear

Profile

clintswan: (Default)
Clint Swanson

October 2015

S M T W T F S
    123
45678910
11121314151617
18192021222324
25262728293031

Most Popular Tags

Style Credit

Expand Cut Tags

No cut tags
Page generated Dec. 27th, 2025 01:15 am
Powered by Dreamwidth Studios