
X-Banned_Bob
Imported Account
Feb 20, 2003, 1:56 PM
Post #5 of 7
(1867 views)
Shortcut
|
|
Re: Faked addresses are a signature of Klez
[In reply to]
|
Can't Post
|
|
B.A. wrote: : Faked addresses ... Yes, I know there are actually several forged addresses in a KLEZ email header. However, there is a way to find out for sure which IP address the email originated at. And in many cases, you can compare that address with other emails you've received to pinpoint the person who has unknowingly sent it. I've been able to help several people identify and clean the virus from their computer this way. Unfortunately, unless you get the police involved, most service providers are not going to outright give you any information on a particular user that was sending mail from a particular IP address at particular time, even though they all have complete logs of all that information (something about privacy policies). I did not find any other email on my system that matched the domain the virus has been sent from -- it may have been deleted, but I just can't find it. To make it clear ... there is no way that a virus can be spread in a forum like this from simply reading the messages -- it has to be from email, or from clicking on a link to a virus file. Fortunately, my real-time virus checkers have always caught the viruses in my email and on the web (since my last bout a couple years ago -- when I finally left F-Prot on full time), so I've been spared their ravages. The way I know it came from a user here, is that this is the only place I'm using this particular email address, except for Carroll Lam, and I'm pretty sure he keeps a check on viruses in his system. So it has to be someone here that at some time has clicked on my name for the address to get into their email program. The good news is that within a few days of posting this message, the virus emails have stopped (I hope) ... so whoever had it has probably caught and disinfected the virus, or it has totally shut down their computer. And I really don't expect anyone to post a note saying, "Yup ... I did it!!" ;-) Thanks!!!!!!
|