This is something I decided to put up after dealing with tons of virus related phone calls when I worked at an IT helpdesk. If you don't understand how SMTP
or e-mail sending viruses work, maybe this will explain it for you
|
|
Why is someone sending messages using my email address?
This page is in NO WAY affiliated with the University of Maryland Medical school and the views expressed on this website do not represent that of the University or it's employees.
My name is Pete Lesko, I work for the University of Maryland Medical School IS support helpdesk. I have created this webpage to clarify some misconceptions about virus generated emails.
Why is someone sending messages using my email address?
No one has hijacked your email, this process is best explained through as follows:
When a modern virus infects a PC, it actively looks through files on the computer, as well as the address book in outlook, for any email addresses that it can find.
Once it finds email addresses, it starts to send copies of itself to those email addresses. In the "FROM:" field of this email, it places another random email address.
This is done so that when a person receives an email that contains a virus, they cannot notify the original sender because the "FROM:" field has been spoofed with another random email address.
Why do I keep getting email from people I don't know?
Please refer to the previous heading for the answer to this question.
Is there any way to stop these messages from coming to me?
This is a tricky question. If the virus infected computer is on the University's network, more than likely the network technicians will see that it is sending out emails and clean the PC up.
If the virus infected host is NOT on our network, a home computer for example, then it is much more difficult to stop this PC from sending out messages, and it is very difficult, if at all possible, to notify the person or person(s) responsible for maintaining this computer.
What are these attachments called DELETED0.TXT?
If you have a university of maryland email (IE --- it ends in wertyuio.com or some derivative there of like moose.wertyuio.com) then your email is passed through a sophisticated virus filter that scans the messages for viruses. If it finds a virus attached to the email, it deletes the virus and replaces it with a text file explaining what virus was found in the attachment.
So, what should I do with these messages? Should I forward them to the helpdesk?
The best thing to do is simply delete these messages, as they are of no use to you or the IS department. We cannot simply block hosts out from the internet that send viruses because they may be legitimate PCs that need to get to our network. Please do not forward messages containing viruses or deleted viruses to the helpdesk as there is nothing that we can do with the messages themselves.
If you have any questions that you feel have not been addressed by this document, please feel free to email *email address removed* Thanks
-Pete Lesko x6-3998
comments
|
|
|