W32/Sobig.F virus header
Rabellino Sergio
rabellino at DI.UNITO.IT
Thu Aug 21 14:34:10 IST 2003
Spicer, Kevin wrote:
> Rabellino Sergio wrote:
>
>> these are lines from the NAI website
>>
>>
>>>The attachment must be run manually to infect the local
>>
>>system. Additionally, messages sent by the virus contain the
>>following fields
>>
>>> * X-MailScanner: Found to be clean
>>> * X-Mailer: Microsoft Outlook Express 6.00.2600.0000
>>>
>
>
> Seriously, have any NAI customers on the list asked them to amend this statement to make it clear that these headers also appear in genuine mail, as people [who should know better] seem to be getting confused.
>
done, i'll post the response from nai (if any).
--
Dott. Sergio Rabellino
Technical Staff
Department of Computer Science
University of Torino (Italy)
Member of the Internet Society
http://www.di.unito.it/~rabser
Tel. +39-0116706701
Fax. +39-011751603
More information about the MailScanner
mailing list