Web Hosting Talk







View Full Version : Do I have a virus or is someone using my box as a relay??


pgowder
05-28-2002, 11:38 AM
I recieved a messages from my email to my email. It had three attachments:

text.htm
audio.x-wav
appliation.octet-stream

Here are the headers:


Return-Path: <xuanxuan@21cn.com>
Received: from rly-ip01.mx.aol.com (rly-ip01.mx.aol.com [205.188.156.49])
by www.powwows.com (8.10.2/8.10.2) with ESMTP id g4SEZQH28572
for <webmaster@powwows.com>; Tue, 28 May 2002 10:35:26 -0400
Received: from logs-mtc-tg.proxy.aol.com (logs-mtc-tg.proxy.aol.com [64.12.102.135]) by rly-ip01.mx.aol.com (v83.35) with ESMTP id RELAYIN2-0528102456; Tue, 28 May 2002 10:24:56 2000
Received: from Yajay (ACA8AC46.ipt.aol.com [172.168.172.70])
by logs-mtc-tg.proxy.aol.com (8.10.0/8.10.0) with SMTP id g4SDwiV319579
for <webmaster@powwows.com>; Tue, 28 May 2002 09:58:44 -0400 (EDT)
Date: Tue, 28 May 2002 09:58:44 -0400 (EDT)
Message-Id: <200205281358.g4SDwiV319579@logs-mtc-tg.proxy.aol.com>
From: webmaster <webmaster@powwows.com>
To: webmaster@powwows.com
Subject: Indian Friendship Society
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=AyRkIiN6tq6
X-Apparently-From: Dred82@aol.com
X-UIDL: 0!a!!?O;"!HHM"!p&&!!


Does this look familar to anyone??

Thanks

horoscopes2000
05-28-2002, 03:04 PM
Could it be that klez32 virus? It sends out emails to an address book using the replyto taken from an email on the infected computer.

so if you know someone who has it, they are probably sending out klez32 generated copies of the virus using you as a return address.

This has happened to me quite a few times in the last few weeks.

It's just a suggestion, as I'm not too good at reading headers, but this did seem a little familiar.