G
Gabriele Neukam
To the owner of the broadband connected computer of said IP number
213.84.28.220:
Obviously, you are reading this newsgroup. Since September 1st, I have
been receiving worm mails and bounces (when your has forged my address
into the from: field), by now more than half a hundred infected mails.
Please clean your machine from this NetSky.P
I can prove that you are reading this group. One of the mails today
forged the mail address of Art Kopp, who gives others advice about how
to get rid of viruses; he himself never has something like this. But the
worm put his address into the From: field.
This is the header of the infected mail:
----- Header -----
Return-Path: <[email protected]>
Received: from t-online.de ([213.84.28.220]) by mailin00.sul.t-online.de
with esmtp id 1C7dpf-1D3Weu0; Wed, 15 Sep 2004 19:44:39 +0200
From: (e-mail address removed)
To: (e-mail address removed)
Subject: Re: Secure delivery
Date: Wed, 15 Sep 2004 19:44:53 +0200
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-TOI-SPAM: u;0;2004-09-15T17:44:50Z
X-TOI-MSGID: e1f718f6-9668-4671-9d5d-a119b44d1f70
X-Seen: true
X-Mailer: T-Online eMail 4.111
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0016----=_NextPart_000_0016"
----- End of Header -----
And this is the rest:
This is a multi-part message in MIME format.
------=_NextPart_000_0016----=_NextPart_000_0016
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit
Partial message is available.
------=_NextPart_000_0016----=_NextPart_000_0016
Content-Type: application/octet-stream;
name="msg.txt
..scr"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="msg.txt
..scr"
And then the worm begins.
DO SOMETHING ABOUT IT!
Gabriele Neukam
(e-mail address removed)
213.84.28.220:
Obviously, you are reading this newsgroup. Since September 1st, I have
been receiving worm mails and bounces (when your has forged my address
into the from: field), by now more than half a hundred infected mails.
Please clean your machine from this NetSky.P
I can prove that you are reading this group. One of the mails today
forged the mail address of Art Kopp, who gives others advice about how
to get rid of viruses; he himself never has something like this. But the
worm put his address into the From: field.
This is the header of the infected mail:
----- Header -----
Return-Path: <[email protected]>
Received: from t-online.de ([213.84.28.220]) by mailin00.sul.t-online.de
with esmtp id 1C7dpf-1D3Weu0; Wed, 15 Sep 2004 19:44:39 +0200
From: (e-mail address removed)
To: (e-mail address removed)
Subject: Re: Secure delivery
Date: Wed, 15 Sep 2004 19:44:53 +0200
MIME-Version: 1.0
X-Priority: 3
X-MSMail-Priority: Normal
X-TOI-SPAM: u;0;2004-09-15T17:44:50Z
X-TOI-MSGID: e1f718f6-9668-4671-9d5d-a119b44d1f70
X-Seen: true
X-Mailer: T-Online eMail 4.111
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0016----=_NextPart_000_0016"
----- End of Header -----
And this is the rest:
This is a multi-part message in MIME format.
------=_NextPart_000_0016----=_NextPart_000_0016
Content-Type: text/plain;
charset="Windows-1252"
Content-Transfer-Encoding: 7bit
Partial message is available.
------=_NextPart_000_0016----=_NextPart_000_0016
Content-Type: application/octet-stream;
name="msg.txt
..scr"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="msg.txt
..scr"
And then the worm begins.
DO SOMETHING ABOUT IT!
Gabriele Neukam
(e-mail address removed)