given the following message:

Headers
Received: from ameripride.org [24.199.28.90] by mail.ameripride.org with ESMTP
  (SMTPD32-8.05) id AC53428F00FC; Wed, 16 Jun 2004 00:36:19 -0500
From: [EMAIL PROTECTED]
...

Could I conclude that the Netsky virus was coming from a pc with an internet
ip of 24.199.28.90 or an internet router by the same address?

Yes, it definitely did.

I pinged the company owning this IP and they stated bluntly "we know we
don't have any viruses". Since I don't know what a relayed email header
looks like, could it be coming from somewhere else?

It's amazing how often people know things they don't know. The computer at 24.199.28.90 definitely is almost certainly infected with Netsky.p. Although it is also ARRC's mailserver, Netsky.p sends directly, and there are no other Received: headers, so it did come from 24.199.28.90. They don't have to believe you, though -- but that's exactly how viruses spread, and the attitude that spammers love, and the attitude that people who receive spam hate. Some guy doesn't want to lose his job, but doesn't realize that he is going to have to admit to having a virus eventually (as their E-mail gets blocked because of all the spam coming from their server).


-Scott
---
Declude JunkMail: The advanced anti-spam solution for IMail mailservers since 2000.
Declude Virus: Ultra reliable virus detection and the leader in mailserver vulnerability detection.
Find out what you've been missing: Ask for a free 30-day evaluation.


---
[This E-mail was scanned for viruses by Declude Virus (http://www.declude.com)]

---
This E-mail came from the Declude.Virus mailing list.  To
unsubscribe, just send an E-mail to [EMAIL PROTECTED], and
type "unsubscribe Declude.Virus".    The archives can be found
at http://www.mail-archive.com.

Reply via email to