hammered_dulcimers
[Top] [All Lists]

[HD] Virus - Worm Question

To: hammered dulcimers <hammered_dulcimers@lists.fmp.com>
Subject: [HD] Virus - Worm Question
From: Maynard Johnson <roguecello440@mac.com>
Date: Mon, 12 Mar 2007 10:51:19 -0400
Delivered-to: hdlist@bobcatos.com
Delivered-to: hammered_dulcimers@lists.fmp.com
List-archive: <http://lists.fmp.com/pipermail/hammered_dulcimers>
List-help: <mailto:hammered_dulcimers-request@lists.fmp.com?subject=help>
List-id: hammered dulcimers <hammered_dulcimers.lists.fmp.com>
List-post: <mailto:hammered_dulcimers@lists.fmp.com>
List-subscribe: <http://lists.fmp.com/mailman/listinfo/hammered_dulcimers>, <mailto:hammered_dulcimers-request@lists.fmp.com?subject=subscribe>
List-unsubscribe: <http://lists.fmp.com/mailman/listinfo/hammered_dulcimers>, <mailto:hammered_dulcimers-request@lists.fmp.com?subject=unsubscribe>
Old-received-spf: none (Address does not pass the Sender Policy Framework) SPF=HELO; sender=smtpout.mac.com; remoteip=::ffff:17.250.248.183; remotehost=smtpout.mac.com; helo=smtpout.mac.com; receiver=shakti.fmp.com;
Old-received-spf: none (Address does not pass the Sender Policy Framework) SPF=MAILFROM; sender=roguecello440@mac.com; remoteip=::ffff:17.250.248.183; remotehost=smtpout.mac.com; helo=smtpout.mac.com; receiver=shakti.fmp.com;
Old-received-spf: none (Address does not pass the Sender Policy Framework) SPF=FROM; sender=roguecello440@mac.com; remoteip=::ffff:17.250.248.183; remotehost=smtpout.mac.com; helo=smtpout.mac.com; receiver=shakti.fmp.com;
Old-return-path: <roguecello440@mac.com>
Reply-to: hammered dulcimers <hammered_dulcimers@lists.fmp.com>
Sender: hammered_dulcimers-bounces+hdlist=bobcatos.com@lists.fmp.com
I've been getting a lot of emails lately containing zip or pif files  
about 70 KB in size.  My Norton Antivirus identifiies them as  
infected, usually with a variant of the Mytob worm.

I'm posting to the list because the most recent on came from  
fbridgeway@juno.com (Is that Brett?).  Several others come from  
addresses that look familiar from the music world.  And long headers  
often do not show any indication that they come from a different  
address.  The fridgeway email, according to an internic whois search,  
originated at Embarq Corporation in Winter Park FL.

So either the worm is VERY good at spoofing addresses, or someone in  
Florida is infected and has a lot of dulcimer and folk music emails  
on their machine.

Maynard Johnson
Kitchen Musician Website
http://www.kitchenmusician.net/
Jink and Diddle School of Scottish Fiddling
http://www.kitchenmusician.net/jink/jink.html


_______________________________________________
Hammered_dulcimers mailing list
Hammered_dulcimers@lists.fmp.com
http://lists.fmp.com/mailman/listinfo/hammered_dulcimers
Unsubscribe: Hammered_dulcimers-unsubscribe@lists.fmp.com

<Prev in Thread] Current Thread [Next in Thread>
  • [HD] Virus - Worm Question, Maynard Johnson <=