GENMSC-L Archives

Archiver > GENMSC > 2002-05 > 1022558706


From: "Mick Gurling" <>
Subject: Re: WARNING - Dangerous messages from Hertfordshire
Date: Tue, 28 May 2002 04:05:06 GMT
References: <HewI8.1392$2O2.172456@newsfep1-win.server.ntli.net>, <3cf2a28d$0$231$cc9e4d1f@news.dial.pipex.com>, <acutvh$ssebv$2@ID-99845.news.dfncis.de>


So far using the originatin IP in the header and Sam Spade - I've tracked
them and gotten acknowledgements from their ISPs

MickG

(Well in one case I used neotrace to find a contact at the ISP)

"Heather Figueroa" <> wrote in message
news:acutvh$ssebv$2@ID-99845.news.dfncis.de...
>
> "The Roman" <> wrote in message
> news:3cf2a28d$0$231$...
> > If your email address appears in the FROM field of the virus
> messages then
> > it means that someone who has you in their Outlook Express address
> book has
> > been infected. The virus chooses an address from the victim's
> address book
> > when sending itself out. You may be able to establish who the
> sender is by
> > looking at the headers of the virus email (Properties).
>
> Not necessarily........check Klez out at the various antivirus sites.
> Seems it is an elusive one to track down who is infected.
>
> Heather
> >
>
>



This thread: