TNDemo
(1000+ posts)
Send PM |
Profile |
Ignore
|
Tue Nov-22-05 03:24 PM
Original message |
|
I got this e-mail at my work account. I have no idea who this person is so she is not in my address book and I have had nothing to do with ATLA, which is a trial lawyer association. I could understand if I got a virus and it sent things out from my address book but this is so randon. What is up with this?
*****
Message: This is an automated message from the BorderWare MXtreme Mail Firewall at host mxtreme.atlahq.org.
A mail from you (xxxx@xxx.com) to (xxx@atlahq.org) was stopped and Quarantined because it contains one or more viruses.
Summary of email contents:
Kaspersky AV found virus Email-Worm.Win32.Sober.y /mailtext.zip/File-packed_dataInfo.exe.
|
Crazy Guggenheim
(1000+ posts)
Send PM |
Profile |
Ignore
|
Tue Nov-22-05 03:57 PM
Response to Original message |
| 1. Just delete the email. I would also make sure to run a scan tonight |
seemunkee
(1000+ posts)
Send PM |
Profile |
Ignore
|
Tue Nov-22-05 04:02 PM
Response to Original message |
| 2. Someone you know deals with them |
|
Someone you know and also deals with ATLA has the virus. The virus sent a message to ATLA and spoofed your name. ATLA's email AV isn't smart enough to look at the headers and figure that out. It just bounces back to the apparent sender.
|
Crazy Guggenheim
(1000+ posts)
Send PM |
Profile |
Ignore
|
Tue Nov-22-05 04:04 PM
Response to Reply #2 |
| 3. I was going to say that. Someone got spoofed. |
TNDemo
(1000+ posts)
Send PM |
Profile |
Ignore
|
Tue Nov-22-05 04:11 PM
Response to Reply #3 |
| 4. So they got my name out of their address book? |
|
Wonder who the heck this is.
|
Crazy Guggenheim
(1000+ posts)
Send PM |
Profile |
Ignore
|
Tue Nov-22-05 04:13 PM
Response to Reply #4 |
| 5. They *could* have. I have to step out for a while. Let me think |
|
about this. I'll PM you when I get back.
|
seemunkee
(1000+ posts)
Send PM |
Profile |
Ignore
|
Tue Nov-22-05 05:34 PM
Response to Reply #4 |
| 6. Not necessarily the address book |
|
It could just be an email in their in box, I'm don't know/care how this one works. To track down the source you would need the IP address of the original message that was sent to ATLA. Then do a lookup of the originating domain and hope it gave you the info you needed to know the source. If it came through one of the large providers then your out of luck. Doing a trace route of the IP might help you know what part of the country it came from. Unless you started getting a bunch of them or you started getting mass mailings of the worm I would just delete it and forget about it.
|
DU
AdBot (1000+ posts) |
Wed Feb 25th 2026, 06:47 AM
Response to Original message |