Email virus going around?!?

The machines we love to hate

Moderator: Wiz Feinberg

Everett Cox
Posts: 497
Joined: 13 Jul 1999 12:01 am
Location: Marengo, OH, USA (deceased)

Post by Everett Cox »

Harry-- A few days ago I was checking the spam that was being filtered/blocked at my ISP and was very disturbed to see 4 different messages FROM MYSELF. Like you, I figured a virus had gotten by PC-Cillin and immediately scanned my machines. Didn't find any bugs. Went back to the ISP site and opened the messages (had not done that earlier) and read that the senders openly stated they had put MY address in BOTH the 'To' AND 'From' fields. There seemed to be more than one actual sender involved. I hope this is not a new trend in spam. BUT, there was no virus, at least. --Everett
User avatar
Jim Smith
Posts: 7949
Joined: 4 Aug 1998 11:00 pm
Location: Midlothian, TX, USA

Post by Jim Smith »

As has been said before, this virus randomly puts names from the infected user's address book as the sender. My PC is clean, but I occasionally get returned email that I supposedly sent (but didn't) that was addressed to people I don't even know and aren't in my address book.
User avatar
Mark Ardito
Posts: 899
Joined: 9 Aug 1999 12:01 am
Location: Chicago, IL, USA

Post by Mark Ardito »

Harry,

If you have run a live update and then scanned the machine, I would say you are clean. The Klez virus does spoof email addresses. Mine gets spoofed all the time.

Mark
User avatar
John Gretzinger
Posts: 427
Joined: 20 Aug 1999 12:01 am
Location: Canoga Park, CA

Post by John Gretzinger »

Boy - this stuff never ends.

Let me recap a lot of the stuff being said here.

#1 - Get a GOOD anti-virus product that updated daily or as needed and use it. **Personal preference PC-cillin or Sophos. Personal dislikes - McAffee. The reasons continue to be valid although they date back to 1985.**

#2 - If you have always on Internet (DSL, Cable, etc.) Get and use a personal firewall. ** Personal preference Zone Alarm - consistantly works on both incoming and outgoing files.**

#3 - Remember that KLEZ takes a look at the infected machine and used the Outlook Address book (contact list, etc.) to find a "From" addressee for the message it sends out to most if not everyone in your address book. Very seldom will it use your real address as the From address. Security professionals know this and don't really expect You to do anything - many of the return messages and "You sent a message containing a virus" from corporate firewalls are system generated and not personal.

#4 - Back up early and often.

#5 - If you don't know computers well, know someone well who does.

Enjoy

jdg

------------------
MSA D-10 w/Nashville 400
'63 Gibson Hummingbird
16/15c Hammered Dulcimer

Post Reply