Virus Help! How do I know if this really happened

LemonHead

Golden Member
Oct 28, 1999
1,041
0
76
OK, I'm trying to understand how this works. I keep getting sent e-mails from god knows who that have the Netsky virus. Mcaffee catches it during the download and I tell it to delete. All seems good after that. I've scanned my system many, many times and used the Stinger.exe util as well as checked for spyware with addaware, spybot, and have immunized with spywareblaster. All this to say, my machine is as clean as the pure virgian Montana snow!

But now I get this e-mail:


We have found the following virus(es) or prohibited attachment(s):
scr attachment

in your email to: amy@motherschoice.com

The email has been deleted. Please check your system for viruses and forward this email to your system administrator or postmaster.

For your reference, below are the headers of the email:

------- Begin Headers -------
Message-ID: Date: Wed, 14 Jul 2004 11:00:42 -0600
From: [myemailaddress]@verizon.net
To: amy@motherschoice.com
Subject: info
------- End Headers -------
___________________________________________________________________
This notification has been generated automatically by Mobigator's Anti Malware Gateway, the industry's most advanced gateway designed specifically for protecting computers against malware, spyware, viruses and spam.
For more information, please visit http://www.mobigator.com, or contact us at info@mobigator.com.
--------------------------------------


Yes, I know the sight is some asian pregnancy thing. No, I have never been there so stop with the jokes already! :|

;)

Seriously, it had my actual e-mail address in the Begin Headers section. So first off, I've never sent anything to this person and or this company, etc. I know that someone who has my e-mail is hosed with the Netsky virus, so that's why I keep getting them. I just want to know if I have been infected and/or what this means.

Sorry if this seems simple to some, just want to have some light shown on this mistery.

Thanks.
 

deadseasquirrel

Golden Member
Nov 20, 2001
1,736
0
0
just address spoofing. you most likely have no virus. be sure not to open the attachment, if it came with one.
 

LemonHead

Golden Member
Oct 28, 1999
1,041
0
76
Originally posted by: deadseasquirrel
just address spoofing. you most likely have no virus. be sure not to open the attachment, if it came with one.

Ah, ok. No I never open them of course. I let Mcaffee nuke em and then I trash the e-mail. How's it spoofing? Meaning, where is it getting my address and is it sending it as me?
 

deadseasquirrel

Golden Member
Nov 20, 2001
1,736
0
0
if you have ever typed in your email addy into a form, or put it on a website, used it to register on a website, handed it out to anybody, or replied back to a spammer (ya know, one of those "remove me from your list" things)... then someone has your email addy to spoof.
 

LemonHead

Golden Member
Oct 28, 1999
1,041
0
76
Originally posted by: deadseasquirrel
if you have ever typed in your email addy into a form, or put it on a website, used it to register on a website, handed it out to anybody, or replied back to a spammer (ya know, one of those "remove me from your list" things)... then someone has your email addy to spoof.

Hmmm...ok, I'll buy that. Been real carful with this account. I guess it is just bound to happen sometime. Thanks.
 

Calin

Diamond Member
Apr 9, 2001
3,112
0
0
Well, you could just act like a mail server: connect to the "receiver" mail server (let's say aservecom.com) and say you are user billgates@microsoft.com, and you want to send this message to user user@aservecom.com. The receiving server will happily receive your message, without checking that you really are server microsoft.com, or a user billgates@microsoft.com exists.
So, someone is sending mail and recommends itself as you (whatever your email address is).

How do they know your email address?
There were some viruses lately that searched the entire address book and used the info to propagate them. This means that if even one of the people that had your address was infected, your address might be captured by the virus, and used. Do you receive or send "chain emails"? (I mean forward emails received?) Your name is there for everyone that is reading it. I know I received emails containing around 30+ email addresses, in different domains (like 10+ domains). It's easy for the email addresses to propagate thru such means, and they end up in address book ready to be collected

Calin