Virus or what?

Top Page
Message as email
+ (text/plain)
Delete this message
Reply to this message
Author: Nathan England
Subject: Virus or what?

In my shop it has been my experience that klez infections can be tracked =
to the person who is sending it out. My shop machine was getting hit abou=
t 30=20
times a day. Viewing the <return-path> in the headers always showed the s=
name, but the From: was different everytime.
Then it all stopped. For a few days we didn't get hit, and assumed the ma=
had been cleaned.=20
That day, while working on a computer with a klez infection, I found that=
reply to: in his outlook setup was the same as the return-path in the mai=
ls I=20
was getting. We had called the ISP but they had ne record of that email=20
address, because it had been misspelled and he wasn't recieving replys fr=
people, which was the reason the machine was in.

I kept track of other return-paths in messages and found all but a couple=
traceable and we got rid of them. A couple more must have been miss spell=

<snip clipping from source of this message>
Return-Path: <>
Received: from localhost (localhost [])
=09by (8.12.4/8.12.4) with ESMTP id

The message I am replying to is from Victor Odhner, but the return path i=

So far its worked for me. And klez seems to be on the rise again.
Atleast in Payson.


On Thursday 21 November 2002 23:22, Victor Odhner wrote:
> Hi, Cliff.
> cliff rogers wrote:
> > The virus software on InterLogic Graphics & Marketing's (ILGM),
> > the server that manages mail for <>
> > has reported that you sent an e-mail to
> > <>, containing the :
> > W32/Klez.H@mm virus in the PCT.exe attachment. The subject of
> > the E-mail was "A very funny website".
> The Klez work looks in the address books of machines it
> has invaded, and randomly selects addresses to use as
> the "From" address of the messages it sends out. This
> is done randomly, and it also varies the subject lines.
> So all you can know is that SOMEBODY who had you in their
> address book got hit by the Klez worm.
> Klez exploits a bug in IE5 whose fix has been available
> for a long time. Of course Klez can't infect a Linux box.
> In fact, I don't think it can hit you if you avoid using
> IE5 for browsing and are not using Microsoft mail clients
> (since these use IE if they receive an HTML e-mail
> message).
> I have gotten a million Klez messages on the Linux system
> where I have one of my e-mail accounts, and of course
> these worms are just data outside the Windows world.
> I think must be filtering out Klez messages
> directed to the address I'm using for mailing lists,
> since I haven't seen any on this account (which I read
> with Mozilla on Win98).
> Vic
>    -- or --

> ---------------------------------------------------
> PLUG-discuss mailing list -
> To subscribe, unsubscribe, or to change you mail settings:

- --=20
Nathan England

plug at
jabber id:

"A free society is one where it is safe to be unpopular."
- --Adlai Stevenson

- -----------------------------------------------------------------

Registered Linux User #189789, Machine #106603

Spam related material will be forwarded to: