given the following message:

Declude Virus v1.79 caught the  the W32/[EMAIL PROTECTED] virus in message.scr
from [Forged] to:  [EMAIL PROTECTED]

Date:       06/16/2004 00:36:46
Subject:    Mail Delivery (failure [EMAIL PROTECTED])
Spool File: Ddc53428f00fc4933.SMD
Remote IP:  24.199.28.90

Headers
Received: from ameripride.org [24.199.28.90] by mail.ameripride.org with
ESMTP
  (SMTPD32-8.05) id AC53428F00FC; Wed, 16 Jun 2004 00:36:19 -0500
From: [EMAIL PROTECTED]
To: [EMAIL PROTECTED]
Subject: Mail Delivery (failure [EMAIL PROTECTED])
Date: Tue, 15 Jun 2004 23:58:45 -0700
MIME-Version: 1.0
Content-Type: multipart/related;
type="multipart/alternative";
boundary="----=_NextPart_000_001B_01C0CA80.6B015D10"
X-Priority: 3
X-MSMail-Priority: Normal
Message-Id: <[EMAIL PROTECTED]>

Could I conclude that the Netsky virus was coming from a pc with an internet
ip of 24.199.28.90 or an internet router by the same address?

I pinged the company owning this IP and they stated bluntly "we know we
don't have any viruses". Since I don't know what a relayed email header
looks like, could it be coming from somewhere else?

---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to