Falsche Error und Mailer Daemons!

Hallo,

gestern kamen zwischen 13.30 und 15 Uhr 3 Mails mit gefälschten Fehlermeldungen. Unser Name ist aus-ge-X-t.

  1. Subject: Error ([email protected])
    Partial message is available and has been sent as a binary attachment.
    mit Anhang data23855.zip

  2. Subject: Mail Delivery failure ([email protected])
    Partial message is available and has been sent as a binary attachment.
    mit mit nicht existentem Link www.ngi.de/inmail/XXXXXX/mread.php?sessionid-17933 und Anhang message.pif

  3. From: Mail Delivery Subsystem
    Subject: Returned mail: see transcript for details
    Received message has been sent as an encoded attachment.
    mit Anhang data25719.pif

Die Return-Paths sind wohl falsch ([email protected] bzw. [email protected]) bzw. leer.

Gruß
Black Eddy

Hier die Mails:
1)
Message-ID:
Return-Path:
Delivered-To: [email protected]
Received: (qmail 19494 invoked from network); 3 Apr 2004 08:30:10 -0000
Received: from unknown (HELO ngi.de) ([82.83.70.160]) (envelope-sender ) by 0 (qmail-ldap-1.03) with SMTP for ; 3 Apr 2004 08:30:10 -0000
From: [email protected]
To: [email protected]
Subject: Error ([email protected])
Date: Sat, 3 Apr 2004 11:00:41 +0200
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="----=_NextPart_000_0016----=_NextPart_000_0016"
X-Priority: 1
X-MSMail-Priority: High
X-Mozilla-Status: c001
X-Mozilla-Status2: 00000000
X-UIDL: 1080981014.19573.mx2,S=39247
Inhalt:
This is a multi-part message in MIME format.
------=_NextPart_000_0016----=_NextPart_000_0016
Content-Type: text/plain; charset=„Windows-1252“
Content-Transfer-Encoding: 7bit
Mail Delivery Failed - This mail couldn’t be represented
------------- failed message -------------
yZGmäGQle&zRHQl7+MFKX2g:open_mouth:zQ(effcM7BpH!2-!kD
5?O?wppNfn9#TSqN’(SJüoP(8gNT9Kß*äqeA|#x*ivYoW
tOSBeAR
Return-Path:
Delivered-To: [email protected]
Received: (qmail 21270 invoked from network); 3 Apr 2004 09:21:56 -0000
Received: from unknown (HELO ngi.de) ([82.83.70.160]) (envelope-sender ) by 0 (qmail-ldap-1.03) with SMTP for ; 3 Apr 2004 09:21:56 -0000
From: [email protected]
To: [email protected]
Subject: Mail Delivery failure ([email protected])
Date: Sat, 3 Apr 2004 11:52:27 +0200
MIME-Version: 1.0
Content-Type: multipart/related; type=„multipart/alternative“; boundary="----=_NextPart_000_001B_01C0CA81.7B015D10"
X-Priority: 1
X-MSMail-Priority: High
X-Mozilla-Status: c001
X-Mozilla-Status2: 00000000
X-UIDL: 1080984119.21297.mx2,S=40178
Inhalt:
This is a multi-part message in MIME format.
------=_NextPart_000_001B_01C0CA81.7B015D10
Content-Type: multipart/alternative; boundary="----=_NextPart_001_001C_01C0CA81.7B015D10"
------=_NextPart_001_001C_01C0CA81.7B015D10
Content-Type: text/plain; charset=„iso-8859-1“
Content-Transfer-Encoding: quoted-printable
------=_NextPart_001_001C_01C0CA81.7B015D10
Content-Type: text/html; charset=„iso-8859-1“
Content-Transfer-Encoding: quoted-printable

Mail Delivery - This mail couldn’t be displayed
------------- failed message -------------
!*-A(z9dDH(a:4rglzWvs%tQ5,bIePy1$&sLtab%8>
EVEHRyMä%01’tq’KN7üV1-2;+ßXZL4<?_k ~5EFG,Pnw7
3u&WVCi32%0BjRük(B;KSv0kHörö6)u59Kr842gnW5H
Partial message is available and has been sent as a binary attachment.
Or you can view the message at:
www.ngi.de/inmail/XXXXXX/mread.php?sessionid-17933–…

Hallo,

gestern kamen zwischen 13.30 und 15 Uhr 3 Mails mit
gefälschten Fehlermeldungen. Unser Name ist aus-ge-X-t.

  1. Subject: Error ([email protected])
    Partial message is available and has been sent as a binary
    attachment.
    mit Anhang data23855.zip

  2. Subject: Mail Delivery failure ([email protected])
    Partial message is available and has been sent as a binary
    attachment.
    mit mit nicht existentem Link
    www.ngi.de/inmail/XXXXXX/mread.php?sessionid-17933 und Anhang
    message.pif

  3. From: Mail Delivery Subsystem

Subject: Returned mail: see transcript for details
Received message has been sent as an encoded attachment.
mit Anhang data25719.pif

Die Return-Paths sind wohl falsch ([email protected] bzw.
[email protected]) bzw. leer.

Hallo Black Eddy
die mails hab ich auch seit einiger Zeit, das ist vermutlich der Wurm W/32 Netsky, schau mal hier:
http://www.sophos.de/virusinfo/analyses/w32netskyq.html
Gruß
Rainer

die mails hab ich auch seit einiger Zeit, das ist vermutlich
der Wurm W/32 Netsky, schau mal hier:
http://www.sophos.de/virusinfo/analyses/w32netskyq.html
Gruß
Rainer

Ja, der ist es. Mein Virenscan gibt ihm den Namen, wenn er ebensolche mails rausschmeißt.
Grüße
Irene