Thread Links Date Links
Thread Prev Thread Next Thread Index Date Prev Date Next Date Index

RE: [802SEC] FW: REGS/ Virus Alert


It looks like the ieee reflector took care of the virus 
just fine. Normally when I get this kind of message, I also
get the virus email with a notice that the attachment was 
stripped because of the virus.

Note that the particular virus in this message is one 
that searches files as well as the mail folders on the 
infected computer for addresses and sends emails using 
addresses it has found in the to and from fields. 
Therefore, anyone active on reflectors may get emails
sent directly to them from infected computers of people 
that participate in or observe the reflector. IEEE reflector
filters can't protect you against those ones.

What you can do is the regular virus protection routine:
Keep your own virus checker up to date
Check the extension before you open the file.

This particular virus chooses random message titles and
at least some of the ones it uses don't sound obviously 
like a virus email title. Some emails from it look like
a bounce from your own postmaster. The upside is that 
the virus seems to be caught by a lot of email servers.

Maybe the IEEE reflectors could be programed to drop 
virus emails (perhaps with notice to the reflector 
owner) rather than sending out the stripped file
and virus alert to the whole group. Whatever you do,
do not blame or take any action against the from addressee 
for the email as that will not be the infected computer
for this virus.


-----Original Message-----
From: Tony Jeffree []
Sent: Wednesday, May 01, 2002 9:36 AM
To: Stevenson, Carl R (Carl)
Cc: IEEE 802 SEC reflector (E-mail)
Subject: Re: [802SEC] FW: REGS/ Virus Alert

Disallow attachments altogether?

At 10:44 01/05/2002 -0400, Stevenson, Carl R (Carl) wrote:

>Seems we still hve virus problems coming into
>the reflectors ...
>This one came through the regs reflector ...
>What do we do?
> > -----Original Message-----
> > From: []
> > Sent: Wednesday, May 01, 2002 10:31 AM
> > To:
> > Subject: REGS/ Virus Alert
> >
> >
> >
> > InterScan has detected a virus WORM_KLEZ.H in the file (by)
> > in the mail traffic sent to you by
> > _______________________________________
> > This message has been sent to you through the Regulatory
> > mailing-list of IEEE 802. If you want to be removed from the
> > list, send a message to , with the
> > following line in the body of the message:
> > unsubscribe stds-802-regs your_e-mail_address
> > If you want to change your e-mail address, write one line
> > with unsubscribe your old address and one line with subscribe
> > with your new address
> >