Hi Freax,
zuerst habe ich eine Mail bekommen mit dem Text
Zitat
Please see the attached zip file for details.
und einem Anhang "your_details.zip".
Hier der Mail Header:
ZitatAlles anzeigenReturn-Path: <sales@panda.co.jp>
Received: from ALBUS (albus.imtek.uni-freiburg.de [132.230.182.141])
by uranus.kasserver.com (8.11.6/8.11.6) with ESMTP id h5S7Vcg25704
for <...@m2k1.net>; Sat, 28 Jun 2003 09:31:38 +0200
Message-Id: <200306280731.h5S7Vcg25704@uranus.kasserver.com>
From: <sales@panda.co.jp>
To: ...@m2k1.net
Subject: Re: Movie
Date: Sat, 28 Jun 2003 9:31:35 +0200
Importance: Normal
X-Mailer: Microsoft Outlook Express 6.00.2600.0000
X-MSMail-Priority: Normal
X-Priority: 3 (Normal)
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="CSmtpMsgPart123X456_000_000A4A19"
X-UIDL: nV,"!pm="!bX*!!8]J!!
--CSmtpMsgPart123X456_000_000A4A19
Content-Type: text/plain;
charset="iso-8859-1"
Content-Transfer-Encoding: 7bit
Please see the attached zip file for details.
--CSmtpMsgPart123X456_000_000A4A19
Content-Type: application/x-zip-compressed;
name="your_details.zip"
Content-Transfer-Encoding: base64
Content-Disposition: attachment;
filename="your_details.zip
Direkt darauffolgend erhielt ich eine Email mit folgendem Inhalt:
Zitat
WebShield SMTP on server imapav1 intercepted and deleted your mail with subject "Re:
Movie" because it detected virus "W32/Sobig.e@MM" in attachment "your_details.zip".
Header:
ZitatAlles anzeigenReturn-Path: <MAILER-DAEMON@uranus.kasserver.com>
Received: from siclopc2.epfl.ch (siclopc2.epfl.ch [128.178.50.221])
by uranus.kasserver.com (8.11.6/8.11.6) with ESMTP id h5S7TRg25387
for <...@m2k1.net>; Sat, 28 Jun 2003 09:29:27 +0200
Received: from imapav1.epfl.ch (imapav1.epfl.ch [128.178.50.106])
by siclopc2.epfl.ch (8.12.9/8.12.9) with SMTP id h5S7RiVj007355
for <...@m2k1.net>; Sat, 28 Jun 2003 09:27:44 +0200 (MEST)
Message-Id: <200306280727.h5S7RiVj007355@siclopc2.epfl.ch>
X-Mailer: Network Associates, Inc. Webshield SMTP, Version 4.5 MR1a
Date: Sat Jun 28 09:29:21 2003
To: ...@m2k1.net
Subject: Virus Detected by Network Associates, Inc. Webshield SMTP V4.5 MR1a
X-UIDL: ]Q;!!Qm;"!>R_!!);&#!
Woher kommmt die zweite Mail?
Warum ist der Return-Path MAILER-DAEMON@... ?
Hat mein Provider einen Virenscanner auf dem Mailserver laufen o.ä.?
Mein Virenscanner "Sophos Anti-Virus" mit dem neuesten Update (vor dem Ausführen geupdated) hat den Virus übrigens nicht gefunden - werde aber nachher nochmal genauer scannen wenn ich mehr Zeit hab.
-SF³