[CW] W32.Klez.e@MM virus

David J Ring Jr [email protected]
Mon, 22 Apr 2002 22:41:22 -0400


Here is NORTON's removal tool - they tell you to use this first.
http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.removal.tool.
html

You are getting the Postmaster's response because your domain, knows who you 
are (even without your email address) because you are logged into their internet 
address.  They can send you bounce messages even though you are logging in 
with someone else's computer, but using your own email settings in a program.

Without knowing your email address, the postmaster on the domain through 
which you are sending mail, and send a message directly to the computer that 
sent a message.  (In other words YOU and YOUR computer!!!)

Example.. You come to my house, and set up Eudora Mail with your email 
address at verizon.net - you configure your sending mail settings to my 
capeonramp.net settings.

Because you are on an internet address from capeonramp, the Mail Exchanger at 
capeonramp will take your email with a return address of verizon.net as a 
courtisey.

But should one of those messages bounce, the Postmaster program, knowing the 
Internet address of the sender (your computer) can send a message directly back 
to your program.  I've done this.

Short story - get the Norton Tool and run it.  Then if it doesn't find the virus, follow 
the detailed instructions.
http://securityresponse.symantec.com/avcenter/venc/data/[email protected]

Prevent this email (or stuff like it from going OUT) - get Zone Alarm.

73

David Ring