To clarify this:
I'm 99,99% sure that Caryl is not spreading any internet worm.
You can verify this quite easily, if you analyse the mail headers.
It's much more likely that one member of that mailing lists got infected and now the worm is harvesting that member's address book.
Additionally a warning:
There are variants of the W32/Bagle worms on the loose.
I received an email from
management@mlukfc.com notifying me about my email account utilization.
This is a fake email address and the email is not coming from mlukfc.com.
Code:
Subject: Notify about your e-mail account utilization.
Dear user, the management of Mlukfc.com mailing system wants to let you know that,
Some of our clients complained about the spam (negative e-mail content)
outgoing from your e-mail account. Probably, you have been infected by
a proxy-relay trojan server. In order to keep your computer safe,
follow the instructions.
For details see the attached file.
Cheers,
The Mlukfc.com team http://www.mlukfc.com
Part of the email header:
Code:
Received: from tot-syd-aa01.proxy.aol.com (tot-syd-aa01.proxy.aol.com [202.67.64.151]) by rly-ip04.mx.aol.com (v95.1) with ESMTP id RELAYIN2-340451e33271; Tue, 02 Mar 2004 18:52:20 1900
Received: from toshiba-user ([202.67.122.27])
by tot-syd-aa01.proxy.aol.com (8.12.10/8.12.10) with SMTP id i22Nm8JB019154
for <webmaster@mlukfc.com>; Tue, 2 Mar 2004 23:48:10 GMT
This one was sent from a computer called "toshiba-user" in Australia.
Does that sound familiar to someone?