Hu Ryde said:
Here is the cure to stopping the majority of viruses from spreading.
DON'T KEEP YOUR CONTACT LIST IN THE SAME PROGRAM AS YOU CHECK YOUR E-MAIL WITH!!!!!!
Plain and simple, keep them apart. I have gotten like 10 of thesealready and am tire of it.
That doesn't necessarily do anything. It searches for files on your hard drive. It even searches through cached web pages. If you have your email addresses stored in some strange format that the virus doesn't recognize, it obviously won't find them. However, if it's something common, it will search your hard drive and find it.
You can find out exactly where the email came from. View all the headers for the email - I think it's Ctrl+F3 in Outlook Express, it's Ctrl+U in Mozilla, and there's probably some option somewhere in whatever webmail site you use. Near the beginning you should find a line that starts with
Received: from. After that will be an IP address in brackets and the HELO command. The IP address should be the PC sending the mails, and the HELO command should return the domain of the spoofed sender address as I stated above. For example, the first email in the screenshot would have something like
Received: from [1.2.3.4] (helo=aol.com). Note that the HELO command is spoofed so that it will always match the From address, even if that's not really your mail server. 1.2.3.4 is the PC sending the email in this case - it's the one with the virus.
http://www.invisibill.net/ipcheck.php will show your IP address. It doesn't do anything to your computer, the webserver just spits out the IP address that requested the page. Here are the IP addresses I've received MyDoom emails from personally:
209.7.198.2 (user-2.museum.state.il.us)
216.237.20.226 (216-237-20-226.orange.nextweb.net)
69.9.12.20 (appears to be a broadband user of dakotacom.net, downstream from broadband01-fe0-0.tus.dakotacom.net)
67.167.18.184 (c-67-167-18-184.client.comcast.net)
68.65.56.34 (va-staff-u1-c4a-a-34.frbgva.adelphia.net)
If one of these is you, you have the virus.