Notices
Computer & Technology Related Post here for help and discussion of computing and related technology. Internet, TVs, phones, consoles, computers, tablets and any other gadgets.

Unbeleivable!

Thread Tools
 
Search this Thread
 
Old Apr 8, 2004 | 09:23 AM
  #1  
NotoriousREV's Avatar
NotoriousREV
Thread Starter
Scooby Regular
 
Joined: Jan 2002
Posts: 11,581
Likes: 0
Default Unbeleivable!

I've been regularly getting viruses sent to me, which thankfully my av software has been managing, but I finally had some time to try and figure out where it was coming from and it was all from the same IP address.

So I do a whois at RIPE and find that the IP address belongs to an IT Consultancy firm. I've just sent a lovely e-mail to their MD
Reply
Old Apr 8, 2004 | 10:13 AM
  #2  
darlodge's Avatar
darlodge
Scooby Regular
 
Joined: Oct 2001
Posts: 3,449
Likes: 0
From: Lovely Lancing in West Sussex
Default

Let me quess. Assetz. We had 1 email every minute for 2 weeks

Darren
Reply
Old Apr 8, 2004 | 10:19 AM
  #3  
GaryK's Avatar
GaryK
Scooby Regular
 
Joined: Sep 1999
Posts: 4,037
Likes: 0
From: Bedfordshire
Default

rev,

how do you that? I get loads of virus emails daily now and its getting a joke. Would like to do a little more, its a pity you cant setup rules at isp level so I dont even receive them.

cheers

Gary
Reply
Old Apr 8, 2004 | 10:32 AM
  #4  
NotoriousREV's Avatar
NotoriousREV
Thread Starter
Scooby Regular
 
Joined: Jan 2002
Posts: 11,581
Likes: 0
Default

Some ISP's do offer AV screening and anti-spam, but you have to make it so that you can opt in or out (what may be spam to you could be useful to someone else).

For Outlook Users:

Right-click on the offending e-mail and select Options off the menu with the left button.

At the bottom of the dialogue box, is a section marked "Internet Headers". This is where to start looking.

You need the line that says "Received: from [123.456.789.123]" the bit in the square brackets is the IP address. Now, your message may have been bounced from mail server to mail server, so check the date stamps to work out the oldest, which is your starting computer and is the one with the problem.

You can then use various tools to see who owns that IP address (if it's a European IP address, go to www.ripe.net, go to the whois db and put the address in there and it gives the ownership details.

99% of the time the IP address belongs to a large ISP, in which case you could try sending an e-mail to abuse@[isp.name] but I wouldn't hold your breath. On this occasion I got lucky and the address belonged to a small-ish company and there was a contact name listed.

I love IT detective work
Reply
Old Apr 10, 2004 | 10:15 AM
  #5  
Nog's Avatar
Nog
Scooby Regular
 
Joined: Jul 2003
Posts: 141
Likes: 0
Smile

MessageLabs - that's the answer. Bl**dy fantastic.

Before anyone asks, no I don't work for them - just been using their service for ~3 yrs now (just after the "I Love You" virus).
Reply
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
HT04
ScoobyNet General
5
Nov 27, 2009 09:50 PM
Potiriadis
General Technical
27
May 28, 2009 09:56 PM
NotoriousREV
Non Scooby Related
1
Feb 16, 2009 04:22 PM




All times are GMT +1. The time now is 08:24 AM.