[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] email virus help



On Tue, 2003-01-07 at 16:59, David Lucas wrote:
> I get "returned email" that has a virus in it.
> Here is the header info
> ***************************
> Full headers are:
> Return-Path: <$g>
> Received: from mail.cdbyrd.net (pool-151-197-184-41.phil.east.verizon.net 
> [151.197.184.41])
> by www.yetiservices.com (8.10.2/8.10.2) with SMTP id h07LcLO18231
> for <cs@xxxxxxxxxx>; Tue, 7 Jan 2003 15:38:21 -0600
> Message-Id: <200301072138.h07LcLO18231@/" 
> EUDORA="AUTOURL"www.yetiservices.com>
> From: Mail Delivery System<MAILER-DAEMON@xxxxxxxxxx>
> To: cs@xxxxxxxxxx
> Subject: Undelivered Mail Returned to Sender -Ayanas Resume1
> Date: Tue,07 Jan 2003 16:38:28 PM
> X-Mailer: Microsoft Outlook Express 5.50.4133.2400
> MIME-Version: 1.0
> Content-Type: multipart/mixed;
> boundary=vqwxofn
> **********************************

This looks like yaha/lentin.  I had someone on Verizon sending tons of
these looking like they came from my server.  Finally called their tech
support and the guy not only had the virus, but also had a mail server
on his machine sending stuff out! 

Check out this on the virus:
http://securityresponse.symantec.com/avcenter/venc/data/w32.yaha.k@xxxxxxx


Email to security@xxxxxxxxxxx is about all you can do.  Unfortunately,
they are not very responsive.


-- 
Marie Gonzalez