[TowerTalk] Pete Smith Virus...
Pete Smith
n4zr at contesting.com
Sun Jun 22 23:36:34 EDT 2003
At 05:49 PM 6/22/03 -0700, Dino Darling wrote:
>Hey Pete, check your system, you are sending out a virus (possibly)!
>
No, happily. This is characteristic of this particular virus's design. It
takes part of a real message received by the infected machine, modifies the
sender's address to substitute a different ISP, and attaches itself. If
you look closely, you'll see the following:
The return address given is n4zr at ix.netcom.com. My ISP is adelphia.net and
I use contesting.com for all my reflector posts.
The truncated body of the message is part of one I posted on towertalk
about 4-5 weeks ago.
The full header shows this is coming from someone in Finland -- If one of
the towertalkians in OH recognizes:
"Received: from ux1 (CDL.kdyn.saunalahti.fi [195.197.108.150])
by gw01.mail.saunalahti.fi (Postfix) with SMTP
id 4412D9CA09; Mon, 23 Jun 2003 02:41:33 +0300 (EEST)"
as belonging to a particular friend or colleague, perhaps you can tell him
or her. I suspect this is probably a dynamically-assigned IP address, but
don't know this ISP.
73, Pete N4ZR
The World HF Contest Station Database was updated 17 June 03.
Are you current? www.pvrc.org/wcsd/wcsdsearch.htm
More information about the TowerTalk
mailing list