Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations IamaSherpa on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

who did it?

Status
Not open for further replies.

qmann

IS-IT--Management
May 2, 2003
269
CA
We are currently on a network and have a virus.. (w32.klez) i know that we received it through an email. Is there any way to trace which employee opened that email. We are just running outlook express on the workstations.

Q
 
If you have emails that were generated from the infection, then you can view the headers to see who the actual sender was. I believe in Outlook express you can right click on an e-mail and select properties then select the details tab to view the headers. The actual sender of a klez virus will be listed in the return path.

Electricity is actually made up of extremely tiny particles called electrons, that you cannot see with the naked eye unless you have been drinking.
Quote taken from Dave Barry

Bill.
 
i can't find any emails that actually generated this virus.. i am assuming that it was received from an email and the person deleted the file as soon as he opened it. So the messages would not have been forwarded to anyone else. I have a pretty good idea who it is but i want to make sure and have proof and then explain to him why it is important not open unknown executables.

thanks in advance.

Q
 
If someone got infected by Klez it would be vary rare for them not to have generated any e-mails after they were infected. The few infections that I've seen have generated around 50 e-mails every 12 minutes. These e-mails would not be in the users outbox either. You could check with your mail provider and have them review their logs for signs of any mass mailings from your network. I'm not sure whether the original victim "Owns" the infected files in network shares but you could check.

Electricity is actually made up of extremely tiny particles called electrons, that you cannot see with the naked eye unless you have been drinking.
Quote taken from Dave Barry

Bill.
 
Answer:


Get some AV software! Keep it up to date!



Chris.



Indifference will be the downfall of mankind, but who cares?
 
Sorry to pile on gman but
OE + old or no AV + novice user = Guaranteed Virus Infection

I have not had the "pleasure" of having a Klez infection. But, Klez is supposed to have it's own SMTP engine. I would guess that means you will not see any sent mails from OE, ie the sent mailbox in OE won't contain the e-mails the Virus sent.

Without the original infected e-mail it might be pretty hard to track down.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top