News:

Tekforums.net - The improved home of Tekforums! :D

Main Menu

rescue emails with corrupt headders (probably caused by virus)

Started by knighty, May 31, 2015, 10:40:23 AM

Previous topic - Next topic

0 Members and 2 Guests are viewing this topic.

knighty

friend called me because all his emails had turned to gobbildygook

assumed it was just a daft setting somewhere... but everything looks find, no settings have changed, nothing new installed etc..

he has 6 email accounts, but it's effected every email in one accounts inbox, all the same accounts deleted items, and then randomly effected emails in other saved folders (all other email accounts look fine, but didn't check every single email)

some of the emails are pretty important and they desperaly need them back

I forwarded one email onto my gmail account, and when I received it, it was fixed....

tried it with other emails, but apparently email servers will reject any email with more than 998 characters without a space/break... so the vast majority of the emails won't forward on


any ideas anyone ?

I downloaded 4 different programs which are supposed to fix email headers but non of them worked

widows live mail btw...
(ignore white boxes, business so I removed info about them)
click for big http://i.imgur.com/tKPUPKV.png



dropbox link to a couple of effected emails...
https://www.dropbox.com/s/vi43j9e606xvjfb/ATT01123.eml?dl=0
https://www.dropbox.com/s/ngrorz05hc2f1de/ATT01337%20%281%29.eml?dl=0

soopahfly

Are these pulled in by POP or IMAP?
What do they look like in webmail?
Have you tried to view the emails through telnet?

knighty

pop

and they're all deleted from server on download

it's niges server, is there anything he can do his end ?

was on the phone to him while I was checking the PC but we're both stumped :-(


forgot to say, new emails come through fine

but out of my element here... googled my ass off but can't find anything helpful :-(

Clock'd 0Ne

Its definitely a singular issue with her Live Mail, I've not seen this issue with all the other accounts on my server and I have around 40 of them. I just haven't a clue what has corrupted them! Googling only comes back with suggestions about changing to UTF-8 and such because of garbled emails, but that's a totally different problem.


knighty

oops, I thought the emails were coming through the site

either way it's not a server side problem because new emails are fine, and months old emails are buggered (which were fine before)


I'll get them to try the database reset thingie you linked too and report back

knighty

actually

the email i forwarded to my gmail from their computer fixed itself once it landed in my inbox

but I also sent an email to myself as an attachment

when I open that, and then forward it to myself.,... it doesn't get fixed :-s

Eggtastico

sounds like an issue with the email client.
Looks to me like the encoding/encryption problem or language has been changed.

What if you install a new email client & import the email?

As you can see the emails ok when forwarded, that makes me think its a settings issue.

knighty

tried installing firefox, but it wouldn't import any of the emails

I've no idea why that email I forwarded fixed itself, non of the others will, and I can't find that email again because they're all gibberish :-(

it still looked like gibberish when I clicked to forward it, and was only fixed once it landed in my gmail inbox


sam did some stuff, and is pretty sure the emails are encrypted

Eggtastico

thats why I think it is an issue with the mail client rather than the emails itself.
When forwarded to your Gmail account, then they are decoding/decrypting correctly.

I can only think a setting has been changed & now its not decoding correctly or not decoding at all.

matt5cott

I've seen corruption similar to this after ANTI virus has been installed, AVG has caused issues to what you describe at our place a few times,

http://forums.msexchange.org/randomly_corrupted_messages_%2F_headers/m_1800550446/tm.htm

Clock'd 0Ne

They actually have a virus, the machine is completely shafted now. Its one of them ones that takes over the entire kernal.

knighty

yep :-(

I was surprised it took so long for the ransom not to pop up.... they've been having problems for a week... that was the only reason I thought it might be down to something else

there's tools to save files from the older versions of the virus, but this looks like the most recent version so no tools available for it yet :-(

they're going to upgrade to an SSD, I'm going to do them a fresh install and then they can save the old drive for if any repair tools come out for it

knighty

copied all there old stuff off to an old HD and pulled it out of the machine, so if a tool comes out later on for the new version of the virus they have a chance to rescue their old stuff

set them up with an ssd, a fresh install and paid up version of NOD32


anyone use any off side back up services ?

they want regular, safe backups... but all the companies offering online/off side backup look the same to me... any recommendations ?

Eggtastico