Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Quick Klez question

Status
Not open for further replies.

walks

Technical User
May 7, 2001
203
CA
Ive recieved now two emails that are kind of like autoresponders saying that my email had sent out a virus and Im almost condifent that Im not infected.

This is what the mail message reads:

&quot;Attention: ann_akerland <ann_akerlaund@address.net>.


A Virus was found in an Email message you sent.
This Email scanner intercepted it and stopped the entire message
reaching it's destination.

The Virus was reported to be:

the W32/Klez.h@MM virus !!!


Please update your virus scanner or contact your I.T support
personnel as soon as possible as you have a virus on your system.


Your message was sent with the following envelope:

MAIL FROM: walks@telusplanet.net
RCPT TO: snakes@newmexicom.com

... and with the following headers:

From: ann_akerlund <ann_akerlund@address.com
To: snakes@newmexicom.com
Subject: Japanese girl VS playboy
Message-ID: <20020724045422.DJUC22374.priv-edtnes11-hme0.telusplanet.net@Obbn>
Date: Tue, 23 Jul 2002 22:58:07 -0600



The original message is kept in:

sleepy.lobo.net:/var/spool/qmailscan/quarantine

where the System Anti-Virus Administrator can further diagnose it.




The question I have is does this mean Im infected? Ive ran the Klez cleaner before and it reported nothing...is it possible its someone elses computer sending the virus that has my email address in there address book? (Thats what I was guessing at but just wanted to be sure. Ive recieved an email like this twice from two different companies.)
 
You are quite right. You should be getting some copies of the virus from the original sender. If you look at the header you will see the ISP it was sent from. All you can do is to send the header text to that ISP's abuse email address.
Don't know if it will do any good though. I've been getting klez for some while from someone on tninet.se . I mailed them, they said they would deal with it and still they come. Peter Meachem
peter@accuflight.com

 
It's a lie.

Don't worry about it. I had someone else e-mail the same message to me. When they sent me a copy of the e-mail that I supposidly infected them with, I found out that someone had infected my computer with Sub7 or a program similar and intercepted the e-mail and added the Klez worm to it. I would check your computer for Servers(Trojans) and see if someone has Sub7(or similar program) running on your computer(It doesn't really run on your computer, but in theory, u know what i mean). Hope this was a help. :)

JabadaJobu
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top