The Bugbear virus is a real pain in the patootie...it's been all over for the past few weeks and at least two people who belong to my 150-member email group have had it. And, of course, distributed it all over the place. Since I'm in most of their address books, I've had an average of 1 a day from someone or other.
The Bugbear virus "spoofs" the sender's address - it snitches an address from the victim's address book. So, if I'm in Fred's email address book, and Fred gets the virus, then it could send copies of itself out to everyone in Fred's address book UNDER MY NAME. However, the IP address won't match my IP address. If you look at the headers (source) usually there are some oddities in there, like "untrusted sender".
I had one guy who emailed me and said he'd had the virus and thought he had it all cleaned up - last Saturday. Yesterday, I got another copy of the virus, allegedly from someone with the same last name (brother?) and on checking the IP addresses found that the sender was indeed the same - the victim who thought he had it all cleaned up.
The other thing the Bugbear virus does is grab any file off the victims computer and sends it as the body of the email. I've had orchestra meeting notices from February 2003, an email I sent (that was quite strange!) in December 2002...whatever. It's quite random. The nasty bit is the attachment - usually a file that appears to have TWO extensions - "filename.doc.exe".
Unlike some of the other viruses that spoof email addresses, this one does not reveal the actual sender in the headers - in fact the headers are usually quite incomplete. The emails I've received have usually had info added by the mail server, like "Sending client does not conform to RFC822 minimum requirements" as well as the afore-mentionned "untrusted sender". The only way to identify the actual sender is from the IP address - and most of us use ISPs who use DHCP, so this isn't always that useful, unless you have two recent emails (one legit, one virus) to compare IPs, as I did yesterday.
I usually send the confused to:
http://securityresponse.symantec.com/avcen...gbear.b@mm.html or
http://vil.mcafee.com/dispVirus.asp?virus_k=100358Both McAfee and Symantec have removal tools available for download.
Remember - this one is PC-only and won't do a thing to your Mac except fill up your trash can.