Capetonian
3rd Feb 2010, 15:16
Let me start by saying I hate Facebook ..... and even more so after this experience. I was talked into opening a Facebook account by SWMBO, so that I could keep in touch with her family .... stupid I know but we do these things.
This morning I got this email :
HEADERS
Delivered-To: [email protected]
Received: by 10.216.165.204 with SMTP id e54cs1147wel;
Tue, 2 Feb 2010 18:48:27 -0800 (PST)
Received: by 10.140.57.5 with SMTP id f5mr4773777rva.132.1265165306717;
Tue, 02 Feb 2010 18:48:26 -0800 (PST)
Return-Path: <[email protected]>
Received: from mx-out.facebook.com (outmail012.snc1.tfbnw.net [69.63.178.171])
by mx.google.com with ESMTP id 6si25168259pzk.103.2010.02.02.18.48.25;
Tue, 02 Feb 2010 18:48:25 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] designates 69.63.178.171 as permitted sender) client-ip=69.63.178.171;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of [email protected] designates 69.63.178.171 as permitted sender) [email protected]; dkim=pass [email protected]
Return-Path: <[email protected]>
DKIM-Signature: v=1; a=rsa-sha1; d=facebookmail.com; s=q1-2009b; c=relaxed/relaxed;
q=dns/txt; [email protected]; t=1265165289;
h=From:Subject:Date:To:MIME-Version:Content-Type;
bh=cY+0KXrYQ9RmRUL89KDLcelTBXo=;
b=XZsdHb+6e+t/FZeBWJpoZyh91O4M7SDHEu8t6nHOqQ4vUIC8gPJBc9mo8gFzf/4v
PwrHJygKUmBttMW97EWZPw==;
Received: from [10.18.255.130] ([10.18.255.130:54395])
by mta309.snc1.facebook.com (envelope-from <[email protected]>)
(ecelerity 3.0.19.34928 r(34928)) with ECSTREAM
id 54/4F-29886-9E3E86B4; Tue, 02 Feb 2010 18:48:09 -0800
X-Facebook: from zuckmail ([NzQuNTAuMTA4LjE2NQ==])
by m.facebook.com with HTTP (ZuckMail);
Date: Tue, 2 Feb 2010 18:48:09 -0800
To: xxxxxx Cape Town <[email protected]>
From: Facebook <[email protected]>
Reply-to: noreply <[email protected]>
Subject: Carme xxxxxxx sent you a message on Facebook...
Message-ID: <[email protected]>
X-Priority: 3
X-Mailer: ZuckMail [version 1.00]
X-Facebook-Notify: msg; from=1623486772; t=1086001167528; mailid=1d2e117G29f2ab85G57a37f0G0
Errors-To: [email protected]
X-FACEBOOK-PRIORITY: 0
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="UTF-8"
Carme sent you a message.
Subject: tua foto
"es esta su foto?! Leaving Facebook... | Facebook (http://www.facebook.com/l/a85d7;readinfo99995791974886.media-paradise.net/id735rp/)
Con amor!!!"
To reply to this message, follow the link below:
http://www.facebook.com/n/?inbox%2Freadmessage.php&t=1086001167528&mid=1d2e117G29f2ab85G57a37f0G0
___
Find people from your Gmail address book on Facebook! Go to: Find Your Friends on Facebook | Facebook (http://www.facebook.com/find-friends/?ref=email)
This message was intended for [email protected]. Want to control which emails you receive from Facebook? Go to:
Login | Facebook (http://www.facebook.com/editaccount.php?notifications=1&md=bXNnO2Zyb209MTYyMzQ4Njc3Mjt0PTEwODYwMDExNjc1Mjg7dG89NzAzN zY5NDc3)
Facebook's offices are located at 1601 S. California Ave., Palo Alto, CA 94304.
The sender (Carme) is a close and trusted family member and as the links started with Welcome to Facebook | Facebook (http://www.facebook.com) I clicked on one and it took me to the Facebook Sign in page - at least it looked genuine. I signed in and then got a pop up saying I needed to download a new version of Adobe, but there was a grammatical error in that which made me suspicious, so I didn't click on that link or go any further.
Carme has subsequently confirmed that she did not send that message.
Next I got a warning message saying that my Firewall was turned off, this has happened before for no apparent reason, so I wouldn't have been unduly concerned were it not for the preceding situation. I turned the firewall back on (XP) and a few minutes later got this popup, which recurs from time to time :
http://img693.imageshack.us/img693/7873/newpicture2d.png (http://img693.imageshack.us/i/newpicture2d.png/)
Have I got a Trojan/Virus or am I being paranoid? I have done a full AVG scan and it comes up clean.
Would really appreciate any advice on this. Thanks.
This morning I got this email :
HEADERS
Delivered-To: [email protected]
Received: by 10.216.165.204 with SMTP id e54cs1147wel;
Tue, 2 Feb 2010 18:48:27 -0800 (PST)
Received: by 10.140.57.5 with SMTP id f5mr4773777rva.132.1265165306717;
Tue, 02 Feb 2010 18:48:26 -0800 (PST)
Return-Path: <[email protected]>
Received: from mx-out.facebook.com (outmail012.snc1.tfbnw.net [69.63.178.171])
by mx.google.com with ESMTP id 6si25168259pzk.103.2010.02.02.18.48.25;
Tue, 02 Feb 2010 18:48:25 -0800 (PST)
Received-SPF: pass (google.com: domain of [email protected] designates 69.63.178.171 as permitted sender) client-ip=69.63.178.171;
Authentication-Results: mx.google.com; spf=pass (google.com: domain of [email protected] designates 69.63.178.171 as permitted sender) [email protected]; dkim=pass [email protected]
Return-Path: <[email protected]>
DKIM-Signature: v=1; a=rsa-sha1; d=facebookmail.com; s=q1-2009b; c=relaxed/relaxed;
q=dns/txt; [email protected]; t=1265165289;
h=From:Subject:Date:To:MIME-Version:Content-Type;
bh=cY+0KXrYQ9RmRUL89KDLcelTBXo=;
b=XZsdHb+6e+t/FZeBWJpoZyh91O4M7SDHEu8t6nHOqQ4vUIC8gPJBc9mo8gFzf/4v
PwrHJygKUmBttMW97EWZPw==;
Received: from [10.18.255.130] ([10.18.255.130:54395])
by mta309.snc1.facebook.com (envelope-from <[email protected]>)
(ecelerity 3.0.19.34928 r(34928)) with ECSTREAM
id 54/4F-29886-9E3E86B4; Tue, 02 Feb 2010 18:48:09 -0800
X-Facebook: from zuckmail ([NzQuNTAuMTA4LjE2NQ==])
by m.facebook.com with HTTP (ZuckMail);
Date: Tue, 2 Feb 2010 18:48:09 -0800
To: xxxxxx Cape Town <[email protected]>
From: Facebook <[email protected]>
Reply-to: noreply <[email protected]>
Subject: Carme xxxxxxx sent you a message on Facebook...
Message-ID: <[email protected]>
X-Priority: 3
X-Mailer: ZuckMail [version 1.00]
X-Facebook-Notify: msg; from=1623486772; t=1086001167528; mailid=1d2e117G29f2ab85G57a37f0G0
Errors-To: [email protected]
X-FACEBOOK-PRIORITY: 0
MIME-Version: 1.0
Content-Transfer-Encoding: quoted-printable
Content-Type: text/plain; charset="UTF-8"
Carme sent you a message.
Subject: tua foto
"es esta su foto?! Leaving Facebook... | Facebook (http://www.facebook.com/l/a85d7;readinfo99995791974886.media-paradise.net/id735rp/)
Con amor!!!"
To reply to this message, follow the link below:
http://www.facebook.com/n/?inbox%2Freadmessage.php&t=1086001167528&mid=1d2e117G29f2ab85G57a37f0G0
___
Find people from your Gmail address book on Facebook! Go to: Find Your Friends on Facebook | Facebook (http://www.facebook.com/find-friends/?ref=email)
This message was intended for [email protected]. Want to control which emails you receive from Facebook? Go to:
Login | Facebook (http://www.facebook.com/editaccount.php?notifications=1&md=bXNnO2Zyb209MTYyMzQ4Njc3Mjt0PTEwODYwMDExNjc1Mjg7dG89NzAzN zY5NDc3)
Facebook's offices are located at 1601 S. California Ave., Palo Alto, CA 94304.
The sender (Carme) is a close and trusted family member and as the links started with Welcome to Facebook | Facebook (http://www.facebook.com) I clicked on one and it took me to the Facebook Sign in page - at least it looked genuine. I signed in and then got a pop up saying I needed to download a new version of Adobe, but there was a grammatical error in that which made me suspicious, so I didn't click on that link or go any further.
Carme has subsequently confirmed that she did not send that message.
Next I got a warning message saying that my Firewall was turned off, this has happened before for no apparent reason, so I wouldn't have been unduly concerned were it not for the preceding situation. I turned the firewall back on (XP) and a few minutes later got this popup, which recurs from time to time :
http://img693.imageshack.us/img693/7873/newpicture2d.png (http://img693.imageshack.us/i/newpicture2d.png/)
Have I got a Trojan/Virus or am I being paranoid? I have done a full AVG scan and it comes up clean.
Would really appreciate any advice on this. Thanks.