I too have this problem, tonight already I've received 26 e-mails infected
with Swen.
My PC is not infected with Swen, the only thought I have is that someone
with my e-mail in their address book is infected and until their PC is
cleaned I take it the e-mails will continue.
Does anyone have an idea how I find out which of my contacts has been
infected ?
It could be anywhere on the web that has your address.
Some people say that it comes from Usenet, and that might be true.
However, I have not gotten a single one on the address that I have
been using on Usenet for 10 days. Mostly it's munged, but I use it
unmunged on NANAS (news.admin.net-abuse.sightings).
The address that is receiving it here is the one that I only give to
personal acquaintances and family.
According to Norton, it "... searches .html, .asp, .eml, .dbx, .wab,
..mbx files on the hard disk for email addresses."
http://securityresponse.symantec.com/avcenter/venc/data/[email protected]
I looked carefully at more than 30 of the Swen virus attempts. None
of them came from an ISP that I have ever corresponded with. It
included ISP's in Luxembourg, Israel, Poland, the Czech republic,
Hawaii, Canada, and other places.
AFAICT the infected computer (that had your address) sent it secretly
to a central location, which sent it to another infected computer
which in turn sent it to you.