FYI: I just recieved one too... see here.., but off course it didn't get through !
Our Stealth Virus Checker v1.26a caught the : W32/Magistr.28672@mm virus in EXITWIN.EXE from [EMAIL PROTECTED] to: [EMAIL PROTECTED] Date: 10/16/2001 05:36:16 Subject: Green Spool File: D29be0d8.SMD webmaster -----Original Message----- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Bill Beach Sent: Tuesday, October 16, 2001 8:59 AM To: [EMAIL PROTECTED] Subject: [Declude.Virus] Magistr Has anyone else received W32/Magistr.28672@mm recently? Declude/F-Prot catches it just fine but it appears as though it sends itself from a different mail server than the one the infected user has (should have?) configured. A couple of messages IMail received with this came from gull.mail.pas.earthlink.net, while another came from albatross.prod.itd.earthlink.net, and one received today was from robin.mail.pas.earthlink.net, all of which are valid Earthstink hosts. I'm fairly certain the user(s) that sent the message doesn't use Earthstink as their mail is hosted by Hi-Speed Hosting, an ISP in Hoboken, NJ. Also, a couple of the return messages that Declude sends to the sender, sender.eml, are being returned to my postmaster due to the user not being valid on the mail server. While I know it's simple to do in Outlook does this worm actually spoof the return address? -Bill This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com . This E-mail came from the Declude.Virus mailing list. To unsubscribe, just send an E-mail to [EMAIL PROTECTED], and type "unsubscribe Declude.Virus". You can E-mail [EMAIL PROTECTED] for assistance. You can visit our web site at http://www.declude.com .
