Guest guest Posted March 4, 2004 Report Share Posted March 4, 2004 I would like to explain. I know that there are many viruses going around. They are everywhere. I have a email account. I have a . mail is a web based program and does not reside on my computer but on 's. Both the email account and run anti virus email programs continuously to scan for email viruses. I also have an antivirus program on my computer. As I understand viruses, they will replicate and send out more viruses, usually to the persons listed in their address book and then those replicate, etc. If the ones that I received were from people I would understand that, but these were supposedly from .com and then supposedly from myself. How did they they get through the antispam software of .com and with it's up to date antivirus software and replicate? It seemed like that there were changes in the headers that appeared unlike replications that I would expect to see in a virus program, but I am not that knowledgable about email addressing, which is why I threw it out to the group. If I sound a little paranoid, maybe I am that or a little gun shy at least at this point. I won't go into a lot of details and I cannot remember some of them, but this group and a few others have had quite a bit of trouble with . Nothing in overt way, but very strange indeed. At one point, this group and a couple of others were experiencing long delays in posts making it to the board. They could be anywhere from one hour to 6 or 7 hours to get to the board after posting. I felt that this group was being hit more severly than some of the other hand full of groups ( most of them were alternative medicine or at least alternative something) experiencing it. Well, after some collective digging on the part of affected people, they came up with the information that for a few groups the messages were being sent to some address in Arizona where they would lie for an undetermined amount of time before they would be sent on. This went on for weeks. Prior to that, I was locked out of about half of the of the management functions for our for about 8 months. They were the ones where you could see who and what was being posted other than regular messages from the group and other things. My queries to were unfruitful. One day I seemed to detect that someone was rummaging around in the but didn't determine who. At first I thought that I must be one of the moderators. But no, it was someone who had access to level controls because when they were messing around they somehow screwed up somethings. Not myself nor the moderators have access to those type of controls to change things.I wont tell you all that happened but I can show you some artifacts from that time. We lost two years of information off the front page. I will explain. This group was started in Oct 2001. There was a display as on all that displays the number of messages posted each month covering a full year and for showing all of the years. This happened in Jan 2003. At that time our calender of postings started over from Jan. 2003 which currently shows something like 25 postings for Jan. 2003. All of 20001 disappeared. All of 2002 disappeared and all of Jan. 20003 disappeared. It started over from there at the end of January 2003 and shows 25 for that month. I do not know of any other board being affected in the same way and when I brought the problem up to , I got nothing. About this same time is when about half the controls went on the fritz. They didn't affect the running of the group, but it did limit my ability to get information on some group activities and to see what things were going on. That went on for about a year. If you wish, go to the home page and compare the start date with what displays in the years and months of a past calender of postings for this group. As I said before, I can't find any other group who has been affected similarly. There were a number of other things that happened over the course of time with the group and my personal email account. I wont go into them now. One thing that seems to be happening now, but do not know if it is happening to other groups is when someone wants to change their membership status it takes weeks sometimes to do so. Weeks??? When they put in an email request to change to no mail or whatever, it can go on for weeks without being changed. Some have put in dozens of requests to no avail. It still takes weeeks. Wow, I have heard of slow servers, but that is ridiculous. LOL. Most everyone gets mad eventually and leaves the group, but the request takes days or weeks and then they get even madder. So, if someone can explain the emails in depth I would appreciate it. And if they can explain the other things with any reasonable explaination I would appreciate it also. paranoiacally yours, Frank , " Eloise Bailey " <pray@w...> wrote: > I received three of these today.....just the sender was changed.......one > was from my ISP....worldnet........I later got a warning from World Net > about it....so it is just going all over....all of mine had different > numbers for passwords.......so it is all over........ > > Eloise > . > > > > Here are the headers for the spam/virus message sent to the group. > > Anyone with some real expertise to help with these headers in the > > group? > > > > The group has been the target of many things to hurt it and I am > > usually under attack personally in one form or another almost > > continuously, not to mention the 300 spam emails a day I receive. > > > > Frank > > > > > > X-Apparently-califpacific via 66.218.78.170; Wed, 03 > > Mar 2004 17:15:55 -0800 > > Return-Path: <sentto-4198251-19031-1078362912- > > califpacific=@r...> > > Received: from 66.218.66.64 (HELO n1.grp.scd.) > > (66.218.66.64) by mta237.mail.scd. with SMTP; Wed, 03 Mar > > 2004 17:15:55 -0800 > > X-eGroups-Return: sentto-4198251-19031-1078362912- > > califpacific=@r... > > Received: from [66.218.66.96] by n1.grp.scd. with NNFMP; 04 > > Mar 2004 01:15:13 -0000 > > X-Sender: califpacific > > X-Apparently-alternative_medicine_forum > > Received: (qmail 75405 invoked from network); 4 Mar 2004 01:14:51 - > > 0000 > > Received: from unknown (66.218.66.166) by m13.grp.scd. with > > QMQP; 4 Mar 2004 01:14:51 -0000 > > Received: from unknown (HELO bonnie) (138.88.169.121) by > > mta5.grp.scd. with SMTP; 4 Mar 2004 01:14:50 -0000 > > alternative_medicine_forum > > Message-ID: <bvkyggneatshfqgplmn > > > X-eGroups-Remote-IP: 138.88.169.121 > > X-eGroups-administration > > califpacific Add to Address Book > > X--Profile: califpacific > > MIME-Version: 1.0 > > Mailing-List: list ; > > contact -owner > > Delivered-mailing list > > Precedence: bulk > > List-Un: <- > > > > > Wed, 03 Mar 2004 20:14:49 -0500 > > Email account utilization > > warning. > > Reply-to: > > Content-Type: multipart/alternative; boundary= " QXPYepu6zv3Bwo0JjT5- > > lCFMNeSF6T2OwocyYt9 " > > Content-Length: 1308 > > > > > > , " califpacific " > > <califpacific> wrote: > > > Dear Group, > > > > > > I did not send this email, but it was probably sent by someone in > > the > > > group. > > > > > > From what I understand, this is a somewhat typical virus email. > > > > > > This group is configured so that all attachments are removed, so > > you > > > will not get a virus from it, but someone tried to infect our > > > membership. If you receive an email from me not through the group, > > > delete it as it is not from me. > > > > > > All of you should be using an antivirus program anyway as there are > > a > > > lot of jerks out there, who cannot construct much in their lives, > > so > > > they feel some power in their weak little pointy heads if the can > > > hurt or destroy. They are typical low class losers. > > > > > > Frank > > > > > > > > > > > > , > > califpacific > > > wrote: > > > > Dear user of " .com " mailing system, > > > > > > > > We warn you about some attacks on your e-mail account. Your > > > computer may > > > > contain viruses, in order to keep your computer and e-mail > > > account safe, > > > > please, follow the instructions. > > > > > > > > For further details see the attach. > > > > > > > > In order to read the attach you have to use the following > > > password: 74340. > > > > > > > > Sincerely, > > > > The .com team > > > http://www. > > > > > > > > > > > > Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.