At 04:07 PM 2/9/2004, you wrote:
Today we received the "W32/[EMAIL PROTECTED]" virus in an email file attachment received from <[EMAIL PROTECTED]>. The file was named text.zip which contained text.scr.

It's possible the return email address was spoofed but be careful of the file attachment.

All the copies of Mydoom I've looked at carefully -- we get maybe twenty or thirty a day -- have been spoofed. And we receive bounces, several per day, coming back to [EMAIL PROTECTED], some of which are actual bounces instead of merely simulated ones. [name] is some common name and sales might be in the list.


By now, most users should know that it does not matter who a piece of mail appears to come from, if you weren't expecting an attachment, open it at your great peril. These viruses can sometimes conceal the fact that a file is executable due to the execrable decision of MS to be "helpful" by hiding file extensions by default. I look at every attachment with a jaundiced eye.

Sometimes if I am curious with something that has a possibility of being legitimate, I'll open up an attachment with Notepad....

Obviously, however, many people are executing the virus code. It only takes a few to keep the viruses going, and until we have systems in place to identify and shut down infected systems promptly, we will only continue to be inundated by every-increasing streams of this dangerous junk.





* * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
* To post a message: mailto:[EMAIL PROTECTED]
*
* To leave this list visit:
* http://www.techservinc.com/protelusers/leave.html
*
* Contact the list manager:
* mailto:[EMAIL PROTECTED]
*
* Forum Guidelines Rules:
* http://www.techservinc.com/protelusers/forumrules.html
*
* Browse or Search previous postings:
* http://www.mail-archive.com/[EMAIL PROTECTED]
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * *

Reply via email to