|
Below is the information. It shows that that it's coming from
a local host, yet it's not. Mail server has been scanned for viruses/trogans and
found none.
Anyone got an idea what's going, what I'm not seeing, virus or
if it's a program bug?
Also note...the header info....is after the
content...strange.
Vir####.Log
05/05/2005 09:52:27 Q332A2EFE02785ED2 Outlook 'CR' vulnerability [From: "Spe] in line 5 05/05/2005 09:52:27 Q332A2EFE02785ED2 Scanned: CONTAINS A VIRUS [MIME: 0 0] 05/05/2005 09:52:27 Q332A2EFE02785ED2 From: [EMAIL PROTECTED] To: [EMAIL PROTECTED] [incoming from 127.0.0.1] 05/05/2005 09:52:27 Q332A2EFE02785ED2 Subject: We're Giving Away a Vacation valued at $2000 Sys####.log
05:05 09:52 SMTPD(332a2efe02785ed2) [192.168.0.135] connect 69.60.105.46 port 61615 05:05 09:52 SMTPD(332a2efe02785ed2) [69.60.105.46] EHLO greenmail.eucalyptusgreen.com 05:05 09:52 SMTPD(332a2efe02785ed2) [69.60.105.46] MAIL FROM:<[EMAIL PROTECTED]> 05:05 09:52 SMTPD(332a2efe02785ed2) [69.60.105.46] RCPT TO:<[EMAIL PROTECTED]> 05:05 09:52 SMTPD(332a2efe02785ed2) [69.60.105.46] d:\IMail\spool\D332a2efe02785ed2.SMD 4993 D##############.SMD
Received: from greenmail.eucalyptusgreen.com [69.60.105.46] by mail.ameripride.org with ESMTP (SMTPD32-8.15) id A32B2EFE0278; Thu, 05 May 2005 09:52:27 -0500 Received: by greenmail.eucalyptusgreen.com (PowerMTA(TM) v3.0c2) id hf8p8i01g747; Thu, 5 May 2005 10:40:03 -0400 (envelope-from <info @ eucalyptusgreen.com>) Date: Thu, 5 May 2005 10:39:57 -0400 From: "Special Promotions" <info @ eucalyptusgreen.com> Subject: We're Giving Away a Vacation valued at
$2000
To: jim.totten @ ameripride.org
Message-ID: <qY-Z6oEdpZZJYDM01xrKzg@>
Date: Thu, 5 May 2005 10:39:57 -0400 (EDT)
Mime-Version: 1.0
Content-Type: multipart/alternative;
boundary="=_qY-Z6oEdpZZJYDM01xrKzg"
--=_qY-Z6oEdpZZJYDM01xrKzg
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 8bit
Content-Disposition: inline
[message content]
X-Declude-Sender: info @ eucalyptusgreen.com
[127.0.0.1]
X-Declude-Spoolname: D332A2EFE02785ED2.SMD X-Declude-Note: Scanned by Declude 2.0.6 (http : //www.declude.com/x-note.htm) for spam. X-Declude-Scan: Score [0] at 09:52:28 on 05 May 2005 X-Declude-Tests: None X-Country-Chain: X-Declude-Virus: Detected [Outlook 'CR' Vulnerability] [from IP 127.0.0.1 ((Private IP))]. --- [This E-mail scanned for viruses by Declude Virus] Q##############.SMD
Qd:\IMail\spool\D332a2efe02785ed2.SMD Hmail.ameripride.org I332a2efe02785ed2 Wd:\IMail\mail_ameripride_org E0, S<info @ eucalyptusgreen.com> NRCPT TO:<jim.totten @ ameripride.org> R<jim.totten @ mail.ameripride.org> |
- Re: [Declude.Virus] Declude virus bug? Doug Anderson
- Re: [Declude.Virus] Declude virus bug? Nick
- Re: [Declude.Virus] Declude virus bug? Doug Anderson
