Email virus going around?!?
Moderator: Wiz Feinberg
-
Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
Email virus going around?!?
For the last few days, I've been getting empty emails from various Forum members with subjects such as "Specialty Web Network", "Hi,sos!", "A powful tool", etc. I've also received emails from members saying that I have sent similar empty emails.
Complete virus scans on my computer and at least one other member's computer show no viruses, and my Sent folder doesn't show that I have sent any of these emails.
Is anyone else having this problem or has anyone heard of this virus and what we can do to stop it?
Complete virus scans on my computer and at least one other member's computer show no viruses, and my Sent folder doesn't show that I have sent any of these emails.
Is anyone else having this problem or has anyone heard of this virus and what we can do to stop it?
-
Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
Jim,
This is the W32.klez.h@MM virus. I just spent 2 days at a company removing this virus from 30 machines. It is a real bear if the payload is executed. The most common side effect of this virus is it renames your .exe program files. For example at this company I went to, it renamed the .exe files for Norton Anti-Virus to a random named file, and also renamed their QuickBooks.exe file to a random name.
If the virus is on your machine, more than likely you will not be able to open your virus scan, but that is not always the case.
First and foremost...Download the latest virus definition file for your virus scanner. If you don't know how to do this please email me off the forum and I can walk you through it.
Then do a scan and it should pick the virus. If you can't open your virus scan application, please view the following link for instructions on how to manually remove this virus.
http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html
WARNING* The manual removal of this virus is a little tricky and I would only recommend it if you are comfortable with the Operating System and have edited the Registry before. 
If anyone is having problems with this virus you can contact me via email and I will set something up to help you out, be it a phone call or a email.
Thanks,
Mark
This is the W32.klez.h@MM virus. I just spent 2 days at a company removing this virus from 30 machines. It is a real bear if the payload is executed. The most common side effect of this virus is it renames your .exe program files. For example at this company I went to, it renamed the .exe files for Norton Anti-Virus to a random named file, and also renamed their QuickBooks.exe file to a random name.
If the virus is on your machine, more than likely you will not be able to open your virus scan, but that is not always the case.
First and foremost...Download the latest virus definition file for your virus scanner. If you don't know how to do this please email me off the forum and I can walk you through it.
Then do a scan and it should pick the virus. If you can't open your virus scan application, please view the following link for instructions on how to manually remove this virus.
http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html
WARNING* The manual removal of this virus is a little tricky and I would only recommend it if you are comfortable with the Operating System and have edited the Registry before. 
If anyone is having problems with this virus you can contact me via email and I will set something up to help you out, be it a phone call or a email.
Thanks,
Mark
-
Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
Thanks Mark.
Luckily my virus definitions are up to date and the full system scan I performed this morning shows nothing. I don't have any of the registry values or renamed files that your link describes either.
Hopefully this will be a wakeup call to all Forum members to update their virus definitions and run a full system scan. At a minimum, they should run the detection tool provided at your link.
Luckily my virus definitions are up to date and the full system scan I performed this morning shows nothing. I don't have any of the registry values or renamed files that your link describes either.Hopefully this will be a wakeup call to all Forum members to update their virus definitions and run a full system scan. At a minimum, they should run the detection tool provided at your link.
-
Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
-
Joe Delaronde
- Posts: 1037
- Joined: 4 Aug 1998 11:00 pm
- Location: Selkirk, Manitoba, Canada
-
Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
-
Gene Jones
- Posts: 6870
- Joined: 27 Nov 2000 1:01 am
- Location: Oklahoma City, OK USA, (deceased)
-
Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
-
Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
-
Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
-
Bobby Boggs
- Posts: 6467
- Joined: 2 Dec 1999 1:01 am
- Location: Upstate SC.
-
Bobby Boggs
- Posts: 6467
- Joined: 2 Dec 1999 1:01 am
- Location: Upstate SC.
-
Joe Delaronde
- Posts: 1037
- Joined: 4 Aug 1998 11:00 pm
- Location: Selkirk, Manitoba, Canada
-
erik
- Posts: 2018
- Joined: 7 Mar 2000 1:01 am
-
Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
Hey guys,
Sorry, when @home went under I got a new email address and forgot to change my profile on the forum.
Send all emails to markardito@attbi.com
Thanks!

Mark
Sorry, when @home went under I got a new email address and forgot to change my profile on the forum.

Send all emails to markardito@attbi.com
Thanks!

Mark
-
Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
-
erik
- Posts: 2018
- Joined: 7 Mar 2000 1:01 am
-
Wayne Brown
- Posts: 2310
- Joined: 3 Apr 2002 1:01 am
- Location: Bassano, Alberta, Canada
TO LATE i got hit and hard....anybody from the forum i now have a different email for me as i went down hard ...still repairing...if anybody got a virus from me ...i'm sorry ....joe...keep the addy you got that is my private one now i'm updated and fixed but still installing
thanks
wayne brown
c/o out west pac-seats<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Wayne Brown on 25 April 2002 at 04:01 PM.]</p></FONT>
thanks
wayne brown
c/o out west pac-seats<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Wayne Brown on 25 April 2002 at 04:01 PM.]</p></FONT>
-
Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
I got this in my work email today:
Klez worm rating upgraded as spread continues
The W32.Klez worm and its variants are still loose in the wild more than a week after the latest variant was discovered, moving antivirus software vendor Symantec Corp. to upgrade it to a "level 4 virus threat" on its danger scale of five.
http://computerworld.com/nlt/1%2C3590%2CNAV47_STO70574_NLTAM%2C00.html <FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Jim Smith on 26 April 2002 at 09:55 AM.]</p></FONT>
Klez worm rating upgraded as spread continues
The W32.Klez worm and its variants are still loose in the wild more than a week after the latest variant was discovered, moving antivirus software vendor Symantec Corp. to upgrade it to a "level 4 virus threat" on its danger scale of five.
http://computerworld.com/nlt/1%2C3590%2CNAV47_STO70574_NLTAM%2C00.html <FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Jim Smith on 26 April 2002 at 09:55 AM.]</p></FONT>
-
Janice Brooks
- Posts: 3115
- Joined: 7 Mar 1999 1:01 am
- Location: Pleasant Gap Pa
Message received through Joey Ace with subject Languages
Return-Path: <joeyace@verizon.net>
Received: from rly-xd05.mx.aol.com (rly-xd05.mail.aol.com [172.20.105.170]) by air-xd03.mail.aol.com (v84.16) with ESMTP id MAILINXD34-0426124108; Fri, 26 Apr 2002 12:41:08 -0400
Received: from out016.verizon.net (out016pub.verizon.net [206.46.170.92]) by rly-xd05.mx.aol.com (v84.10) with ESMTP id MAILRELAYINXD57-0426124037; Fri, 26 Apr 2002 12:40:37 -0400
Received: from Vsosofue ([24.55.174.97]) by out016.verizon.net
(InterMail vM.5.01.04.05 201-253-122-122-105-20011231) with SMTP
id <20020426164023.IYXZ8115.out016.verizon.net@Vsosofue>
for <busgal58jb@aol.com>; Fri, 26 Apr 2002 11:40:23 -0500
From: joeyace <joeyace@sympatico.ca>
To: busgal58jb@aol.com
Subject: Language
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=Zi0B1iyX9O1u
Message-Id: <20020426164023.IYXZ8115.out016.verizon.net@Vsosofue>
Date: Fri, 26 Apr 2002 11:40:32 -0500
------------------
Janice "Busgal" Brooks
ICQ 44729047
Return-Path: <joeyace@verizon.net>
Received: from rly-xd05.mx.aol.com (rly-xd05.mail.aol.com [172.20.105.170]) by air-xd03.mail.aol.com (v84.16) with ESMTP id MAILINXD34-0426124108; Fri, 26 Apr 2002 12:41:08 -0400
Received: from out016.verizon.net (out016pub.verizon.net [206.46.170.92]) by rly-xd05.mx.aol.com (v84.10) with ESMTP id MAILRELAYINXD57-0426124037; Fri, 26 Apr 2002 12:40:37 -0400
Received: from Vsosofue ([24.55.174.97]) by out016.verizon.net
(InterMail vM.5.01.04.05 201-253-122-122-105-20011231) with SMTP
id <20020426164023.IYXZ8115.out016.verizon.net@Vsosofue>
for <busgal58jb@aol.com>; Fri, 26 Apr 2002 11:40:23 -0500
From: joeyace <joeyace@sympatico.ca>
To: busgal58jb@aol.com
Subject: Language
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=Zi0B1iyX9O1u
Message-Id: <20020426164023.IYXZ8115.out016.verizon.net@Vsosofue>
Date: Fri, 26 Apr 2002 11:40:32 -0500
------------------
Janice "Busgal" Brooks
ICQ 44729047
-
Joey Ace
- Posts: 9791
- Joined: 11 Feb 2001 1:01 am
- Location: Hamilton, Ontario, Canada
My computer did not send you that message, Janice. I suspect my email address was "spoofed".
That means someone else had my name and email address in their Addr Book. They got infected and it sent emails out with my name.
There's a free removal tool for this virus at Symantec http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.removal.tool.html
I keep protected with Norton AV and DO NOT open attachments.
Just to be sure, I downloaded and ran the tool in the above link. After about 30 min of examining my system it reported I had no infected files. Per their instructions, I ran it again. Still OK.
I suggest you do the same.
I regularly get attachments from suspicious addresses.
The best advice is
Do Not Open Any Attachments.
Hope you're OK.
-j0ey-<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Joey Ace on 26 April 2002 at 05:47 PM.]</p></FONT>
That means someone else had my name and email address in their Addr Book. They got infected and it sent emails out with my name.
There's a free removal tool for this virus at Symantec http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.removal.tool.html
I keep protected with Norton AV and DO NOT open attachments.
Just to be sure, I downloaded and ran the tool in the above link. After about 30 min of examining my system it reported I had no infected files. Per their instructions, I ran it again. Still OK.
I suggest you do the same.
I regularly get attachments from suspicious addresses.
The best advice is
Do Not Open Any Attachments.
Hope you're OK.
-j0ey-<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Joey Ace on 26 April 2002 at 05:47 PM.]</p></FONT>
-
Colin Goss
- Posts: 338
- Joined: 4 Aug 1998 11:00 pm
- Location: St.Brelade, Island of Jersey, Channel Islands, UK
I recommend that you consider using Zonealarm, a free firewall program that automatically renames all attachments before giving you the option of whether to run them or not. This prevents the nasties getting through.
Then use AVG virus checker from Grisoft - also free,
Finally use Mailwasher (mailwasher.net) also free to get rid of spam.
Then use AVG virus checker from Grisoft - also free,
Finally use Mailwasher (mailwasher.net) also free to get rid of spam.
-
Joey Ace
- Posts: 9791
- Joined: 11 Feb 2001 1:01 am
- Location: Hamilton, Ontario, Canada
-
Kenny Forbess
- Posts: 802
- Joined: 28 Dec 1999 1:01 am
- Location: peckerwood point, w. tn.
<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Jim Smith on 23 April 2002 at 02:11 PM.]</p></FONT>