Bill;
I think I may be able to shed some light on this subject, as I have spent a
lot of time dealing with the problem and investigating outbreaks that have
affected vp-mail users.
Bill Velek wrote:
Unless the abilities of new viruses has increased yet again, it appears
to me that you were very likely deliberately targeted with that virus.
I doubt this has happened. In no case that I have investigated has this
occurred. I know it's possible, but my guess is that these days, the chances
are about 1 in a 1,000.
What I mean about 'abilities' is that, once a computer is infected,
viruses can currently mail copies of infected files to addresses listed
in the infected computer's address book without the knowledge of the
owner, and the viruses also have the ability to add seemingly innocent
subject lines ... even varying them to some degree. But I've never
heard of a virus that could, for instance, analyze your mail-folders and
then create a fictitious message that would have content of a similar
nature to your folders in order to give it the appearance of a bona fide
message and otherwise make it seem interesting enough to cause you to
open the attachment That's a very scary prospect
There are a nmber of viruses that do exactly this. As a matter of fact it's
getting to be the norm. Here's what a typical modern virus can do, once it's
infected your computer.
It can scan documents on your computer for titles and text can use that title
for the attachment and/or subject.
It can scan your mail folders for addresses, subjects and text.
It will use the addresses it finds to spoof the From and To fields in the
message header. I have been able to examine the Return-Path field in the
past to find the actual sending computer, but I think that field may be
spoofed also by the newer viruses. Sometimes the virus will just make these
addresses (other than the To: address) up. That makes it harder to trace.
The virus may or may not spoof the IP address of the sender.
The body of the note may contain text from notes the virus has scanned or
from the documents it read.
All of this helps create the impression that a friend or acquaintance has
sent you an email with a document attached that is about a subject you are
familar with. This is great from the virus writer's perspective as it all
makes it more likely that an attachment may be opened. But it also has helped
me track down the source computer when one of vp-mail's members has been
infected:
When several people from the group start getting virus emails of a similar
type from different people, it becomes obvious that a member is infected. The
email addresses, the subject and attachment titles all are clues to the
sending computer. Often some of the sending addresses generated are not group
members, so that alone can narrow down the infectee, since only someone who
has that address in their mail folders or address book would be the infectee.
The same is true for the titles. By asking people if they have any documents
with those titles on their computers, I have been able to pin down a couple
of these. The combination of the titles and non-group email addresses can
quickly pinpoint the infected computer.
The nice thing about this is that even if someone is too embarrased to admit
their computer got infected, they can be alerted (through the group) and
disinfect their computer quietly and on their own.
But assuming that they still can't do that, there are two
possibilities: first, and the easiest and most likely, is that someone
deliberately targeted you (and possibly other folks, as well);
As I have noted, this is not only not the most likely, it is highly
unlikely. In all the years I have been hosting vp-mail I have never run
across a verifiable instance of this. It could happen, of course. Just not
very likely.
the
second is that it was a legitimate message which just happened to
contain a virus
While I guess this could also happen, I don't know of a case of it happening
either. Virus messages are almost always (my guess is 99.99% of the time)
Worms sent from the infected computer by the virus itself. This is the most
efficient way for viruses to work.
Here are some basic rules of thumb about modern worm type viruses:
- The sending computer is usually not (and more recently almost never) the
one in the "From:" field. It may or may not be the address in the
"return-Path" field.
- The sending computer is one that has your address in it somewhere, either
in the address book or (more likely these days) in your mail folders.
- The person whose computer sent you the virus does not know that it happed,
did not send you any emails personally and probably has no idea that their
computer is infected.
- You should never open an attachment unless you know EXACTLY what it is. If
you aren't sure you should contact the sender.
- Anyone who is on the Internet or uses email should have and use antivirus
software. This is just part of being a good "Netizen".
-One other item. Here is the single worst piece of advice well-meaning (but
ignorant) TV commentators offer about viruses - Never open an attachment from
someone you don't know. Well, yes, that is good advice but also very
misleading. Most of the virus infections happen by opening an attachment
"from" someone you know. Or think you know.
There are some links for info about viruses and hoaxes at
http://www.vphomepage.com/handystuff.html#VIRUS
Thanks,
Skip
www.vphomepage.com