Auriez-vous une idée de leur origine et comment arrêter ça ? Je suis à peu près sûr que mes PC ne sont pas infectés, car ils sont éteints la nuit et ils ont un antivirus+ le firewal XP. J'ai aussi vérifié sur mon site s'il n'y avait pas de fichier suspect, et ce n'est pas le cas.
Une copie du code source d'un de ces mails dès fois que ça puisse servir :
Delivered-To: online.fr-s.billard@free.fr
Received: (qmail 606 invoked from network); 19 Feb 2008 05:58:23 -0000
Received: from 195.229.156.190 (HELO mail1.aus.edu) (195.229.156.190)
by mrelay1-g25.free.fr with SMTP; 19 Feb 2008 05:58:23 -0000
Received: from mail1.aus.edu (localhost [127.0.0.1])
by mail1.aus.edu (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
2007)) with ESMTP id <0JWH00L751X9JP10@mail1.aus.edu> for s.billard@free.fr;
Tue, 19 Feb 2008 09:58:21 +0400 (GST)
Received: from scmail. ([195.229.158.190])
by mail1.aus.edu (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
2007)) with ESMTP id <0JWH00LWC1X9JD60@mail1.aus.edu> for s.billard@free.fr;
Tue, 19 Feb 2008 09:58:21 +0400 (GST)
Received: from process-daemon.mailclust.aus.edu by mailclust.aus.edu
(Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
id <0JWH00I011L23F00@mailclust.aus.edu> for s.billard@free.fr; Tue,
19 Feb 2008 09:58:21 +0400 (GST)
Received: from mailclust.aus.edu
(Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
id <0JWH00HR41X9WK00@mailclust.aus.edu>; Tue, 19 Feb 2008 09:58:21 +0400 (GST)
Date: Tue, 19 Feb 2008 09:58:21 +0400 (GST)
From: Internet Mail Delivery <postmaster@mailclust.aus.edu>
Subject: [Real SPAM] Delivery Notification: Delivery has failed
To: s.billard@free.fr
Message-id: <0JWH00HR61X9WK00@mailclust.aus.edu>
MIME-version: 1.0
Content-type: multipart/report;
boundary="Boundary_(ID_8FyIwj06Z1/zMBaOFzUleg)"; report-type=delivery-status
--Boundary_(ID_8FyIwj06Z1/zMBaOFzUleg)
Content-type: text/plain; charset=us-ascii
Content-language: en-US
Content-transfer-encoding: 7BIT
This report relates to a message you sent with the following header fields:
Message-id: <029488958.78148726402512@free.fr>
Date: Tue, 19 Feb 2008 00:59:53 -0500
From: Kimberle Keith <s.billard@free.fr>
To: clinic@aus.edu
Subject: [Real SPAM] The Shortest Way to Your Happy Love Life
Your message cannot be delivered to the following recipients:
Recipient address: clinic@aus.edu
Reason: You are not allow to send.$--------------------------------$AUS Network Section.: clinic@aus.edu
--Boundary_(ID_8FyIwj06Z1/zMBaOFzUleg)
Content-type: message/delivery-status
Reporting-MTA: dns;mailclust.aus.edu (reprocess-daemon)
Original-recipient: rfc822;clinic@aus.edu
Final-recipient: rfc822;clinic@aus.edu
Action: failed
Status: 5.7.1
(You are not allow to send.$--------------------------------$AUS Network
Section.: clinic@aus.edu)
--Boundary_(ID_8FyIwj06Z1/zMBaOFzUleg)
Content-type: message/rfc822
Return-path: <s.billard@free.fr>
Received: from reprocess-daemon.mailclust.aus.edu by mailclust.aus.edu
(Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
id <0JWH00HR41X9WK00@mailclust.aus.edu>; Tue, 19 Feb 2008 09:58:21 +0400 (GST)
Received: from AUS ([195.229.156.190])
by mailclust.aus.edu (Sun Java System Messaging Server 6.2-8.04 (built Feb 28
2007)) with ESMTP id <0JWH00IPO1X30680@mailclust.aus.edu> for clinic@aus.edu;
Tue, 19 Feb 2008 09:58:15 +0400 (GST)
Received: from [190.67.131.52] by mail1.aus.edu
(Sun Java System Messaging Server 6.2-8.04 (built Feb 28 2007))
with ESMTP id <0JWH00LU91WIJD60@mail1.aus.edu>; Tue,
19 Feb 2008 09:58:15 +0400 (GST)
Received: from [190.67.131.52] by mx1.free.fr; Tue, 19 Feb 2008 00:59:53 -0500
Date: Tue, 19 Feb 2008 00:59:53 -0500
From: Kimberle Keith <s.billard@free.fr>
Subject: [Real SPAM] The Shortest Way to Your Happy Love Life
To: clinic@aus.edu
Reply-to: s.billard@free.fr
Message-id: <029488958.78148726402512@free.fr>
MIME-version: 1.0
X-Mailer: The Bat! (v3.71.04) Educational
Content-type: multipart/alternative;
boundary="Boundary_(ID_XQEA+cjMOy/Fk2GVOiM1pQ)"
X-Priority: 3 (Normal)
--Boundary_(ID_XQEA+cjMOy/Fk2GVOiM1pQ)
Content-type: text/plain; charset=Windows-1252
Content-transfer-encoding: 7BIT
It is an absolutely safe enlargement method that gives incredible results incomparable to the results of any other male medical methods. Order our VPXL now.http://geocities.com/sharpe_emerson/
--Boundary_(ID_XQEA+cjMOy/Fk2GVOiM1pQ)
Content-type: text/html; charset=Windows-1252
Content-transfer-encoding: 7BIT
<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<HTML><HEAD><TITLE></TITLE>
</HEAD>
<BODY>
<html>
<body bgcolor="#FFFFFF" link="#AE0B0B">
<p><font face="Verdana" size="2"><font color="0066FF"><b>It is an absolutely safe enlargement method that gives incredible results incomparable to the results of any other male medical methods. </b></font></font></p>
<p><font face="Verdana" size="2"><b>Order our VPXL now.</font></p>
<p><font face="Verdana" size="2"><b><a href="http://geocities.com/sharpe_emerson/">http://geocities.com/sharpe_emerson/</a> </font></p>
</body>
</html>
</BODY></HTML>
--Boundary_(ID_XQEA+cjMOy/Fk2GVOiM1pQ)--
--Boundary_(ID_8FyIwj06Z1/zMBaOFzUleg)--




Haut














