WTF? Anyone explain this to me? (Unrepairable Virus Detected. )

Brutuskend

Lifer
Apr 2, 2001
26,558
4
0
I just got this in my mail box. I checked my send mail and there is nothing there to this address. Also my Virus deff.s are up to date and my box HAS been scanned and comes up clean.
-----------------------------------------------------------------------------------------------------------------------------------------------------

The original message was received at Tue, 27 Jan 2004 09:06:05 -0500 (EST) from [69.56.37.169]


*** ATTENTION ***

Your e-mail is being returned to you because there was a problem with its delivery. The address which was undeliverable is listed in the section
labeled: "----- The following addresses had permanent fatal errors -----".

The reason your mail is being returned to you is listed in the section
labeled: "----- Transcript of Session Follows -----".

The line beginning with "<<<" describes the specific reason your e-mail could not be delivered. The next line contains a second error message which is a general translation for other e-mail servers.

Please direct further questions regarding this message to your e-mail administrator.

--AOL Postmaster



----- The following addresses had permanent fatal errors ----- <rmdm7194@aol.com>

----- Transcript of session follows -----
... while talking to air-yi03.mail.aol.com.:
>>> DATA
<<< 554 TRANSACTION FAILED - Unrepairable Virus Detected. Your mail has not been sent. 554 <rmdm7194@aol.com>... Service unavailable
-----------------------------------------------------------------------------------------------------------------------------------------------------

details
-----------------------------------------------------------------------------------------------------------------------------------------------------

The original message was received at Tue, 27 Jan 2004 09:06:05 -0500 (EST) from [69.56.37.169]


*** ATTENTION ***

Your e-mail is being returned to you because there was a problem with its delivery. The address which was undeliverable is listed in the section
labeled: "----- The following addresses had permanent fatal errors -----".

The reason your mail is being returned to you is listed in the section
labeled: "----- Transcript of Session Follows -----".

The line beginning with "<<<" describes the specific reason your e-mail could not be delivered. The next line contains a second error message which is a general translation for other e-mail servers.

Please direct further questions regarding this message to your e-mail administrator.

--AOL Postmaster



----- The following addresses had permanent fatal errors ----- <rmdm7194@aol.com>

----- Transcript of session follows -----
... while talking to air-yi03.mail.aol.com.:
>>> DATA
<<< 554 TRANSACTION FAILED - Unrepairable Virus Detected. Your mail has not been sent. 554 <rmdm7194@aol.com>... Service unavailable
-----------------------------------------------------------------------------------------------------------------------------------------------------

This address is NOT in my contacts, and it doesn't show up when I search my folders.
 

minendo

Elite Member
Aug 31, 2001
35,560
22
81
Wrong. That is the newest worm that is out. See the stickied thread here in OT.
 

Brutuskend

Lifer
Apr 2, 2001
26,558
4
0
I haven't opened any ZIP files or ANY files from anyone I don't know (or people I DO know for that matter)
 

minendo

Elite Member
Aug 31, 2001
35,560
22
81
Originally posted by: Brutuskend
I haven't opened any ZIP files or ANY files from anyone I don't know (or people I DO know for that matter)
The email you received is the worm itself. It is not an actual undeliverable message.

 

aux

Senior member
Mar 16, 2002
533
0
0
Originally posted by: minendo
Originally posted by: Brutuskend
I haven't opened any ZIP files or ANY files from anyone I don't know (or people I DO know for that matter)
The email you received is the worm itself. It is not an actual undeliverable message.

Not necessarily. It could be the worm itself, but could be a bounce message from an attempt to send the virus with a spoofed From: (or Return-to: ) address. I have seen both of them today.

Edit: space between : and ) to avoid :)
 

Brutuskend

Lifer
Apr 2, 2001
26,558
4
0
Originally posted by: minendo
Originally posted by: Brutuskend
I haven't opened any ZIP files or ANY files from anyone I don't know (or people I DO know for that matter)
The email you received is the worm itself. It is not an actual undeliverable message.

oops...

I guess I shouldn't have read it them HUH? :eek:

I DID just search for shimgapi.dll and nothing shows up....
 

Brutuskend

Lifer
Apr 2, 2001
26,558
4
0
Originally posted by: DeadByDawn
69.56.37.169

is this your ip address??

No

EDIT: Scanned Reg. and there is no...

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\_CurrentVersion\Run "TaskMon" = %SysDir%\taskmon.exe
 

Hubris

Platinum Member
Jul 14, 2001
2,749
0
0
Don't worry about it, dude. If your scan is showing clean, then you're fine. Easiest thing in the world to spoof adresses, or a freind of a friend of a friend has you in the contact list and the virus stole it and used it to send to people. Not much you can do in either case.