刚刚清理邮箱时,我在新浪的邮箱收到一封自称是反病毒程序的来信,还带着一个名为autofile3.eml大小0.14k的附件。原文如下:
寄件人:Antivirus-Daemon@cn99.com
收件人:***********
日期:06-07-02 20:36:53
附件:autofile3.eml(0.14k)
主题:Sender Virus-alert (sender:***********)
This is a mail anti-virus program at host mail.cn99.com
The mail system received a message from you (**********@sina.com)
destined to
linda@bentium.net
that contains either infected or suspicious file(s)
and it has not reached the above destination(s).
Antivirus message(s):
infected with Win32.HLLM.MyDoom.29
Please clean up your machine using antivirus software before trying
to send any new mail, and resend the message if you need. Or or ask
your system administrator for help.
Please, do not respond to *this* message you're reading now --
your response will be lost. I, the antivirus program, will be unable
to read your response, sorry... :)
Received: from sina.com (unknown [61.51.***.**])
by mail.cn99.com (Postfix) with ESMTP id 442015A8E
for <linda@bentium.net>; Sun, 2 Jul 2006 20:36:42 +0800 (CST)
From: *********@sina.com
T linda@bentium.net
Subject: Mail Transaction Failed
Date: Sun, 2 Jul 2006 20:37:09 +0800
MIME-Version: 1.0
Content-Type: multipart/mixed;
boundary="----=_NextPart_000_0001_67809472.C3FA904F"
X-Priority: 3
X-MSMail-Priority: Normal
Message-Id: <20060702123642.442015A8E@mail.cn99.com>
Received: from sina.com (unknown [61.51.***.**]) by mail.cn99.com (Postfix) with ESMTP id 442015A8E for ; Sun, 2 Jul 2006 20:36:42 +0800 (CST) From: ***********@sina.com T linda@bentium.net Subject: Mail Transaction Failed Date: Sun, 2 Jul 2006 20:37:09 +0800 MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="----=_NextPart_000_0001_67809472.C3FA904F" X-Priority: 3 X-MSMail-Priority: Normal Message-Id: <20060702123642.442015A8E@mail.cn99.com>
我大概翻译一下吧:
我是host mail.cn99.com的反病毒程序。邮件系统收到了一封你(我的邮箱地址)发给linda@bentium.net的信件,这封信包含被感染的或者可疑的文件,它未能到达上面的地址。
反病毒信息:
被Win32.HLLM.MyDoom.29感染。
请在发送新的邮件或你需要回复邮件之前使用杀毒软件尝试清理你的机器。或者向你的网络管理员请求帮助。
请不要回复你正在阅读的这封信,你的回复将被丢失。我,反病毒程序,不会阅读你的回复,对不起……:)
大概就是这样吧。这是7月初收到的信,但我敢肯定我从来没有给linda@bentium.net发过邮件,我也不知道这是谁的地址。而且,我从来不使用客户端程序发送邮件,一直都是直接上网用网络邮箱,即使我的电脑有病毒,也不可能让我的新浪邮箱给它发邮件吧?
这究竟是怎么回事呀?不知道大家有没有收到过类似的邮件?这是真的反病毒程序邮件,还是挂羊头卖狗肉的病毒(附件)邮件?我实在不敢下载那个附件……
请各位高人帮我分析一下。