mgs
[Top] [All Lists]

Re: Virus found in sent message "Onmouseover"

To: Kenneth Scott <KSCOTT@holycross.edu>, mgs@autox.team.net,
Subject: Re: Virus found in sent message "Onmouseover"
From: S & M Barnes <barnes@mghorizon.com>
Date: Fri, 24 May 2002 16:21:17 -0500
I've had this same message several times too, I'm getting one or two Klez
infected emails per day, I am also getting messages from various corporate
servers saying one of my email addresses had sent them a virus, many of
those were supposedly sent when my computer was switched off!

I can imagine someone's distress at being continually sent a virus (I'm
getting kind of fed up with it) but I do know that the one person who didn't
sent it to me is the person in the reply-to line!

An interesting asside about this virus, along with the infected file it
tends to send a randomly chosen image or html file off the infected
computer. Being nosey I look at all these in the hope they will give me a
hint who is sending me the virus - I've had some very interesting images
sent to me, it's surprising what some people keep on their computers! :-)

MikeB


----- Original Message -----
From: "Kenneth Scott" <KSCOTT@holycross.edu>
To: <mgs@autox.team.net>; <LittleLeroy@outdrs.net>
Sent: Friday, May 24, 2002 3:22 PM
Subject: Re: Virus found in sent message "Onmouseover"


> Robert,
>    I am Ken Scott.  I am sorry that you got this email.  Our system is set
to reject e-mails containing viruses.  This virus infected message was sent
to me at our server by someone who had both your and my email addresses in
their address book.  This particular virus is able to spoof a source address
and yours is the address it used to perform the spoof.  If you wish to
express hostility please direct it at the author of this and other such
viruses.  I hope that this explanation will help.
>
> Ken Scott
>
> >>> "Robert" <LittleLeroy@outdrs.net> 05/24/02 02:34PM >>>
> This is some sort of scam.  I do not know kscott@holycross.edu, did not
send
> him an e-mail, I know NO ONE at Holy Cross .........and I have NAV2002
that
> is updated daily and has quarantined and deleted KLEZ about 50 times!  If
he
> got it, I sent it back in a reply, without opening it.  You'd better check
> HIS computer.
>
> Whenever I get a virus-containing e-mail, I immediately send it back in a
> reply, don't open it, quarantine it, then delete it!  So, if he got one,
he
> sent it to me and then got it back!
>
> Go fool somebody else!
>
> Bob
>
> Robert & Carol Mauk
> Our Gardens
> Southern Maryland
> LittleLeroy@outdrs.net
> The Little Sawdust Factory
> Tired of being knocked offline and jerked
> around?  Try www.outdoorsunlimited.net
>
> THIS E-MAIL CHECKED BY NAV 2002
> BOTH IN AND OUTBOUND!
>
>
> ----- Original Message -----
> From: "System Anti-Virus Administrator" <root@warren.holycross.edu>
> To: <littleleroy@outdrs.net>
> Cc: <root@warren.holycross.edu>
> Sent: Friday, May 24, 2002 2:23 PM
> Subject: Virus found in sent message "Onmouseover"
>
>
> > Attention: littleleroy <littleleroy@outdrs.net>.
> >
> >
> > A Virus was found in an Email message you sent.
> > This Email scanner intercepted it and stopped the entire message
> > reaching it's destination.
> >
> > The Virus was reported to be:
> >
> >  the W32/Klez.h@MM virus !!!
> >
> >
> > Please update your virus scanner or contact your I.T support
> > personnel as soon as possible as you have a virus on your system.
> >
> >
> > Your message was sent with the following envelope:
> >
> > MAIL FROM: littleleroy@outdrs.net
> > RCPT TO:   kscott@holycross.edu
> >
> > ... and with the following headers:
> >
> > From:    littleleroy <littleleroy@outdrs.net>
> > To:      kscott@holycross.edu
> > Subject: Onmouseover
> > Message-ID: <200205241800.g4OI0EE01630@logs-mtc-tb.proxy.aol.com>
> > Date:    Fri, 24 May 2002 14:00:15 -0400 (EDT)
> >
> >
> >
> > The original message is kept in:
> >
> >   warren:/var/spool/qmailscan/quarantine
> >
> > where the System Anti-Virus Administrator can further diagnose it.
> >
> > The Email scanner reported the following when it scanned that message:

///  or try http://www.team.net/cgi-bin/majorcool
///  Archives at http://www.team.net/archive


<Prev in Thread] Current Thread [Next in Thread>