We are currently on a network and have a virus.. (w32.klez) i know that we received it through an email. Is there any way to trace which employee opened that email. We are just running outlook express on the workstations.
If you have emails that were generated from the infection, then you can view the headers to see who the actual sender was. I believe in Outlook express you can right click on an e-mail and select properties then select the details tab to view the headers. The actual sender of a klez virus will be listed in the return path.
Electricity is actually made up of extremely tiny particles called electrons, that you cannot see with the naked eye unless you have been drinking.
Quote taken from Dave Barry
i can't find any emails that actually generated this virus.. i am assuming that it was received from an email and the person deleted the file as soon as he opened it. So the messages would not have been forwarded to anyone else. I have a pretty good idea who it is but i want to make sure and have proof and then explain to him why it is important not open unknown executables.
If someone got infected by Klez it would be vary rare for them not to have generated any e-mails after they were infected. The few infections that I've seen have generated around 50 e-mails every 12 minutes. These e-mails would not be in the users outbox either. You could check with your mail provider and have them review their logs for signs of any mass mailings from your network. I'm not sure whether the original victim "Owns" the infected files in network shares but you could check.
Electricity is actually made up of extremely tiny particles called electrons, that you cannot see with the naked eye unless you have been drinking.
Quote taken from Dave Barry
It seems a little unfair to give some unfortunate person a telling off when the lack of anti-virus is the real culprit. Besides which you don't always have to open the attachemnt yourself to execute the virus code.
Sorry to pile on gman but
OE + old or no AV + novice user = Guaranteed Virus Infection
I have not had the "pleasure" of having a Klez infection. But, Klez is supposed to have it's own SMTP engine. I would guess that means you will not see any sent mails from OE, ie the sent mailbox in OE won't contain the e-mails the Virus sent.
Without the original infected e-mail it might be pretty hard to track down.
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.