0
skydiverchick

Virus

Recommended Posts

More than likely this was Klez. That particular 'virus' has some interesting stealth habits that might be confusing you.

Klez APPEARS to be sent by someone other than the person who actually is infected. It grabs two names from the victim's mailboxes then sends to one of them from the other.

To track down the true source, you'll have to look at the complete headers of the email. That might or might not have enough info, depending on several factors.


First Class Citizen Twice Over

Share this post


Link to post
Share on other sites
Doubtful if it came from a @dropzone.com address... Unless HH has is setup so you can do POP mail (which I don't think is the case) mail at dz.com is all web based.
More than likely, someone has the KLEZ virus which will send out e-mails using someone in the address book as the sender to cover it's tracks...


DAMMIT LJ!!! YOU BEAT ME!!!! Oh Francis says HI BTW
I promise not to TP Davis under canopy.. I promise not to TP Davis under canopy.. eat sushi, get smoochieTTK#1

Share this post


Link to post
Share on other sites
Quote

I have anti virus stuff but this just creeped on in.



ahhhhhhh, you gotta love a worm that's smart enough to disable older versions of the anti-virus software you're running before it does it's dirty work...

Don't feel like the lone ranger, klez is the most widely spread computer virus ever... I have my mail server at work set up to strip executable attachments, and send me a copy of anything that it's done this to (I'm the postmaster), and I've got one guy here at work that must have klez emailed to him at least a hundred times! I told him he needs smarter friends... :$

BTW - if you look in the message headers for the "X-Return-Path:" line, it will tell you who it REALLY came from...

"If all you ever do is all you ever did, then all you'll ever get is all you ever got."

Share this post


Link to post
Share on other sites
Quote

apparently I do too.



Maybe not, it's really easy to get this thing (I'm a network admin, and it got loose on my network!), but he has the same group of people sending it to him over, and over, and over... :ph34r:

"If all you ever do is all you ever did, then all you'll ever get is all you ever got."

Share this post


Link to post
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

0