»
 

Go Back   ResellerRatings Store Ratings > ResellerRatings Forums > Tech Support

Reply
 
LinkBack Thread Tools Display Modes
Old 01-30-2004, 04:20 AM   #1 (permalink)
Registered User
 
Join Date: Jan 2004
Posts: 1
memoe is on a distinguished road
virus or what?

i do tech support and i occationally come across this issue:

someone will call in and tell us they are getting email bounced back to them for invalid address. they say they are not sending the email and they do not even know who the recipient is. I usually tell them that may be related to virus and to do an online scan to bypass av prog. i am not sure if that is what is causing that issue and would like to know what is.

any help with this would be grateful
Thank you,
memoe

memoe is offline   Reply With Quote
Old 01-30-2004, 06:04 AM   #2 (permalink)
Registered User
 
JohnE.'s Avatar
 
Join Date: Oct 2001
Location: Vancouver, BC Canada
Posts: 850
JohnE. is on a distinguished road
Send a message via ICQ to JohnE.
After they do an anti-virus scan are any viruses detected? If no, then the problem lies elsewhere and if yes, then there's your answer.

Welcome to TechIMO!
__________________
Nudge, nudge. Wink, wink. Know what I mean? Say no more.
JohnE. is offline   Reply With Quote
Old 01-30-2004, 06:08 AM   #3 (permalink)
Registered User
 
nomaxim's Avatar
 
Join Date: May 2002
Location: Stow, Ohio, Sol III
Posts: 2,211
nomaxim is on a distinguished road
Many mass mailer type worms (MyDoom is the latest) will spoof the 'From' Field in the e-mails they send.

What happens is the virus will pick two e-mail addy's at random out of the infected systems address book. The virus will then send itself to one address and list the sender as the other address.

The person who owns the infected system rarely has their own address listed in their address book, so that addy won't be used.

Since the ISP's send the e-mail back to the addy in the 'from' field, well someone else gets it. In these cases some of the addy's are no longer valid.

I once got an infected e-mail back that had my addy as both the sender and reciept.

I'll say you are right on track with the answer your giving. It never hurts for them to do a scan just to be sure.

__________________
Well, if crime fighters fight crime and fire fighters fight fire, what do freedom fighters fight? They never mention that part to us, do they?
-George Carlin

Last edited by nomaxim; 01-30-2004 at 06:12 AM.
nomaxim is offline   Reply With Quote
Old 01-30-2004, 06:37 AM   #4 (permalink)
Registered User
 
Join Date: Apr 2002
Location: Albany, Ga.
Posts: 1,063
no1_vern is on a distinguished road
Welcome memoe,

To Techimo!

The very first thing I think of is that someone is using their Email to spam people. Unless the Email is brand new it is virtually guaranteed to be on someones list, and most likely has been sold to a spam monger who hides his email by using the victims email to spam other people. My guess depends on how long the email addy has been in existence, which service they are using, and if they use the email address to list themselves for "free services", get info, enter in contests, etc...

It could be as you suggested-a virus that replicates itself and mails itself to others in an attempt to spread.

Good luck in finding what ever it is.
no1_vern is offline   Reply With Quote
Reply




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Most Active Discussions

Recent Discussions

All times are GMT -6. The time now is 01:27 PM.