Whoops, I spoke too soon! Sorry Selma, it's not coming from your machine. I am getting more of these, including bounce notices for mail that I haven't sent. Thus it appears that someone with list members addresses in their mail program is sending the virus with our addresses in the "from" field - I should have realized this when I saw the actual sender address for the mail from "selma" was from "rogers.com", a Canadian ISP. The infected machine is at IP 24.157.146.211:cpe.net.cable.rogers.com This will be a Canadian Futurework subscriber. -PV
---------- Forwarded message ---------- Date: Wed, 20 Aug 2003 15:30:06 -0700 (PDT) From: pete <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: [Futurework] New mail worm in ".pif" file - "Re: That movie" Got this today from Selma (I presume) with a 100k mail worm attached. It seems able to get by our site's virus detector, but it only affects microsoft machines, so it was no problem for me. That will not be the case for many of you. Please note that the worm works by hoping you will confuse ".pif", an obsolete form of windoze executable, with ".pdf", a compressed text file format. We will probably see several more of these, as this is apparently a cleverly crafted little beggar. >Date: Wed, 20 Aug 2003 17:20:50 --0400 >From: [EMAIL PROTECTED] >To: [EMAIL PROTECTED] >Subject: Re: That movie > >Please see the attached file for details. The giveaway is the attachment, an executable with a size of 103kB, called "Your_document.pif" . Already now I've seen another, prbably from a spammer, with the header "Re: Your application", and the attachment is also called "Your_document.pif", and also 103kB. -PV _______________________________________________ Futurework mailing list [EMAIL PROTECTED] http://scribe.uwaterloo.ca/mailman/listinfo/futurework _______________________________________________ Futurework mailing list [EMAIL PROTECTED] http://scribe.uwaterloo.ca/mailman/listinfo/futurework