> I am not very good at tracking down spammers. Does any of the
> information contained in this header help track them down?
> It looks to me like they are on UUNET directly and none of the
> other information is real?
>
> I just received a virus with the below listed header. This makes
> the 3rd time someone has tried to send me the same virus.
This is a new type of virus, that infects the winsock .DLL. Among other things, it
will disguise the address it is coming from (making spread more easily, since you
can't easily notify the sender).
>Received: from doug [63.126.60.224] by noveltymail.com
> (SMTPD32-6.05) id A5AB7A013C; Fri, 05 Jan 2001 13:51:07 -0600
It came from a computer that calls itself "doug" (technically a violation of the RFCs,
but everyone does it). The IP address 63.126.60.224 is owned by UUNet and leased to
Jetta International.
>From: Hahaha <[EMAIL PROTECTED]>
>Subject: Snowhite and the Seven Dwarfs - The REAL story!
These two lines identify the virus -- and show how nasty the thing is.
This is a good reason to get virus protection on the mail server. <G>
--
-Scott
Declude: Anti-virus and Anti-spam solutions for IMail. http://www.declude.com
--
Please visit http://www.ipswitch.com/support/mailing-lists.html
to be removed from this list.
An Archive of this list is available at:
http://www.mail-archive.com/imail_forum%40list.ipswitch.com/