RE: [802SEC] FW: REGS/ Virus Alert
It looks like the ieee reflector took care of the virus
just fine. Normally when I get this kind of message, I also
get the virus email with a notice that the attachment was
stripped because of the virus.
Note that the particular virus in this message is one
that searches files as well as the mail folders on the
infected computer for addresses and sends emails using
addresses it has found in the to and from fields.
Therefore, anyone active on reflectors may get emails
sent directly to them from infected computers of people
that participate in or observe the reflector. IEEE reflector
filters can't protect you against those ones.
What you can do is the regular virus protection routine:
Keep your own virus checker up to date
Check the extension before you open the file.
This particular virus chooses random message titles and
at least some of the ones it uses don't sound obviously
like a virus email title. Some emails from it look like
a bounce from your own postmaster. The upside is that
the virus seems to be caught by a lot of email servers.
Maybe the IEEE reflectors could be programed to drop
virus emails (perhaps with notice to the reflector
owner) rather than sending out the stripped file
and virus alert to the whole group. Whatever you do,
do not blame or take any action against the from addressee
for the email as that will not be the infected computer
for this virus.
From: Tony Jeffree [mailto:firstname.lastname@example.org]
Sent: Wednesday, May 01, 2002 9:36 AM
To: Stevenson, Carl R (Carl)
Cc: IEEE 802 SEC reflector (E-mail)
Subject: Re: [802SEC] FW: REGS/ Virus Alert
Disallow attachments altogether?
At 10:44 01/05/2002 -0400, Stevenson, Carl R (Carl) wrote:
>Seems we still hve virus problems coming into
>the reflectors ...
>This one came through the regs reflector ...
>What do we do?
> > -----Original Message-----
> > From: email@example.com [mailto:firstname.lastname@example.org]
> > Sent: Wednesday, May 01, 2002 10:31 AM
> > To: email@example.com
> > Subject: REGS/ Virus Alert
> > InterScan has detected a virus WORM_KLEZ.H in the file (by)
> > in the mail traffic sent to you by firstname.lastname@example.org
> > _______________________________________
> > This message has been sent to you through the Regulatory
> > mailing-list of IEEE 802. If you want to be removed from the
> > list, send a message to email@example.com , with the
> > following line in the body of the message:
> > unsubscribe stds-802-regs your_e-mail_address
> > If you want to change your e-mail address, write one line
> > with unsubscribe your old address and one line with subscribe
> > with your new address