Whoops, I spoke too soon! Sorry Selma, it's not coming from your 
machine. I am getting more of these, including bounce notices for mail 
that I haven't sent. Thus it appears that someone with list members
addresses in their mail program is sending the virus with our
addresses in the "from" field - I should have realized this when
I saw the actual sender address for the mail from "selma" was
from "rogers.com", a Canadian ISP. The infected machine is at
IP 24.157.146.211:cpe.net.cable.rogers.com  This will be a Canadian
Futurework subscriber. -PV

---------- Forwarded message ----------
Date: Wed, 20 Aug 2003 15:30:06 -0700 (PDT)
From: pete <[EMAIL PROTECTED]>
To: [EMAIL PROTECTED]
Subject: [Futurework] New mail worm in ".pif" file - "Re: That movie"


Got this today from Selma (I presume) with a 100k mail worm attached.
It seems able to get by our site's virus detector, but it only
affects microsoft machines, so it was no problem for me. That
will not be the case for many of you. Please note that the worm works
by hoping you will confuse ".pif", an obsolete form of windoze
executable, with ".pdf", a compressed text file format. We will
probably see several more of these, as this is apparently a cleverly
crafted little beggar.


>Date: Wed, 20 Aug 2003 17:20:50 --0400
>From: [EMAIL PROTECTED]
>To: [EMAIL PROTECTED]
>Subject: Re: That movie
>
>Please see the attached file for details.

The giveaway is the attachment, an executable with a size of 103kB,
called "Your_document.pif" .


Already now I've seen another, prbably from a spammer, with the
header "Re: Your application", and the attachment is also called
"Your_document.pif", and also 103kB.

       -PV


_______________________________________________
Futurework mailing list
[EMAIL PROTECTED]
http://scribe.uwaterloo.ca/mailman/listinfo/futurework


_______________________________________________
Futurework mailing list
[EMAIL PROTECTED]
http://scribe.uwaterloo.ca/mailman/listinfo/futurework

Reply via email to