Email virus going around?!?
Moderator: Wiz Feinberg
- Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
Email virus going around?!?
For the last few days, I've been getting empty emails from various Forum members with subjects such as "Specialty Web Network", "Hi,sos!", "A powful tool", etc. I've also received emails from members saying that I have sent similar empty emails.
Complete virus scans on my computer and at least one other member's computer show no viruses, and my Sent folder doesn't show that I have sent any of these emails.
Is anyone else having this problem or has anyone heard of this virus and what we can do to stop it?
Complete virus scans on my computer and at least one other member's computer show no viruses, and my Sent folder doesn't show that I have sent any of these emails.
Is anyone else having this problem or has anyone heard of this virus and what we can do to stop it?
- Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
Jim,
This is the W32.klez.h@MM virus. I just spent 2 days at a company removing this virus from 30 machines. It is a real bear if the payload is executed. The most common side effect of this virus is it renames your .exe program files. For example at this company I went to, it renamed the .exe files for Norton Anti-Virus to a random named file, and also renamed their QuickBooks.exe file to a random name.
If the virus is on your machine, more than likely you will not be able to open your virus scan, but that is not always the case.
First and foremost...Download the latest virus definition file for your virus scanner. If you don't know how to do this please email me off the forum and I can walk you through it.
Then do a scan and it should pick the virus. If you can't open your virus scan application, please view the following link for instructions on how to manually remove this virus.
http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html
WARNING* The manual removal of this virus is a little tricky and I would only recommend it if you are comfortable with the Operating System and have edited the Registry before. 
If anyone is having problems with this virus you can contact me via email and I will set something up to help you out, be it a phone call or a email.
Thanks,
Mark
This is the W32.klez.h@MM virus. I just spent 2 days at a company removing this virus from 30 machines. It is a real bear if the payload is executed. The most common side effect of this virus is it renames your .exe program files. For example at this company I went to, it renamed the .exe files for Norton Anti-Virus to a random named file, and also renamed their QuickBooks.exe file to a random name.
If the virus is on your machine, more than likely you will not be able to open your virus scan, but that is not always the case.
First and foremost...Download the latest virus definition file for your virus scanner. If you don't know how to do this please email me off the forum and I can walk you through it.
Then do a scan and it should pick the virus. If you can't open your virus scan application, please view the following link for instructions on how to manually remove this virus.
http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html


If anyone is having problems with this virus you can contact me via email and I will set something up to help you out, be it a phone call or a email.
Thanks,
Mark
- Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
Thanks Mark.
Luckily my virus definitions are up to date and the full system scan I performed this morning shows nothing. I don't have any of the registry values or renamed files that your link describes either.
Hopefully this will be a wakeup call to all Forum members to update their virus definitions and run a full system scan. At a minimum, they should run the detection tool provided at your link.

Hopefully this will be a wakeup call to all Forum members to update their virus definitions and run a full system scan. At a minimum, they should run the detection tool provided at your link.
-
- Posts: 1037
- Joined: 4 Aug 1998 11:00 pm
- Location: Selkirk, Manitoba, Canada
- Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
-
- Posts: 6870
- Joined: 27 Nov 2000 1:01 am
- Location: Oklahoma City, OK USA, (deceased)
- Contact:
- Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
- Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
- Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
-
- Posts: 6463
- Joined: 2 Dec 1999 1:01 am
- Location: Upstate SC.
-
- Posts: 6463
- Joined: 2 Dec 1999 1:01 am
- Location: Upstate SC.
-
- Posts: 1037
- Joined: 4 Aug 1998 11:00 pm
- Location: Selkirk, Manitoba, Canada
- Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
Hey guys,
Sorry, when @home went under I got a new email address and forgot to change my profile on the forum.
Send all emails to markardito@attbi.com
Thanks!

Mark
Sorry, when @home went under I got a new email address and forgot to change my profile on the forum.

Send all emails to markardito@attbi.com
Thanks!

Mark
- Mark Ardito
- Posts: 899
- Joined: 9 Aug 1999 12:01 am
- Location: Chicago, IL, USA
- Wayne Brown
- Posts: 2259
- Joined: 3 Apr 2002 1:01 am
- Location: Bassano, Alberta, Canada
- Contact:
TO LATE i got hit and hard....anybody from the forum i now have a different email for me as i went down hard ...still repairing...if anybody got a virus from me ...i'm sorry ....joe...keep the addy you got that is my private one now i'm updated and fixed but still installing
thanks
wayne brown
c/o out west pac-seats<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Wayne Brown on 25 April 2002 at 04:01 PM.]</p></FONT>
thanks
wayne brown
c/o out west pac-seats<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Wayne Brown on 25 April 2002 at 04:01 PM.]</p></FONT>
- Wayne Brown
- Posts: 2259
- Joined: 3 Apr 2002 1:01 am
- Location: Bassano, Alberta, Canada
- Contact:
- Jim Smith
- Posts: 7949
- Joined: 4 Aug 1998 11:00 pm
- Location: Midlothian, TX, USA
I got this in my work email today:
Klez worm rating upgraded as spread continues
The W32.Klez worm and its variants are still loose in the wild more than a week after the latest variant was discovered, moving antivirus software vendor Symantec Corp. to upgrade it to a "level 4 virus threat" on its danger scale of five.
http://computerworld.com/nlt/1%2C3590%2CNAV47_STO70574_NLTAM%2C00.html <FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Jim Smith on 26 April 2002 at 09:55 AM.]</p></FONT>
Klez worm rating upgraded as spread continues
The W32.Klez worm and its variants are still loose in the wild more than a week after the latest variant was discovered, moving antivirus software vendor Symantec Corp. to upgrade it to a "level 4 virus threat" on its danger scale of five.
http://computerworld.com/nlt/1%2C3590%2CNAV47_STO70574_NLTAM%2C00.html <FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Jim Smith on 26 April 2002 at 09:55 AM.]</p></FONT>
- Janice Brooks
- Posts: 3115
- Joined: 7 Mar 1999 1:01 am
- Location: Pleasant Gap Pa
- Contact:
Message received through Joey Ace with subject Languages
Return-Path: <joeyace@verizon.net>
Received: from rly-xd05.mx.aol.com (rly-xd05.mail.aol.com [172.20.105.170]) by air-xd03.mail.aol.com (v84.16) with ESMTP id MAILINXD34-0426124108; Fri, 26 Apr 2002 12:41:08 -0400
Received: from out016.verizon.net (out016pub.verizon.net [206.46.170.92]) by rly-xd05.mx.aol.com (v84.10) with ESMTP id MAILRELAYINXD57-0426124037; Fri, 26 Apr 2002 12:40:37 -0400
Received: from Vsosofue ([24.55.174.97]) by out016.verizon.net
(InterMail vM.5.01.04.05 201-253-122-122-105-20011231) with SMTP
id <20020426164023.IYXZ8115.out016.verizon.net@Vsosofue>
for <busgal58jb@aol.com>; Fri, 26 Apr 2002 11:40:23 -0500
From: joeyace <joeyace@sympatico.ca>
To: busgal58jb@aol.com
Subject: Language
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=Zi0B1iyX9O1u
Message-Id: <20020426164023.IYXZ8115.out016.verizon.net@Vsosofue>
Date: Fri, 26 Apr 2002 11:40:32 -0500
------------------
Janice "Busgal" Brooks
ICQ 44729047
Return-Path: <joeyace@verizon.net>
Received: from rly-xd05.mx.aol.com (rly-xd05.mail.aol.com [172.20.105.170]) by air-xd03.mail.aol.com (v84.16) with ESMTP id MAILINXD34-0426124108; Fri, 26 Apr 2002 12:41:08 -0400
Received: from out016.verizon.net (out016pub.verizon.net [206.46.170.92]) by rly-xd05.mx.aol.com (v84.10) with ESMTP id MAILRELAYINXD57-0426124037; Fri, 26 Apr 2002 12:40:37 -0400
Received: from Vsosofue ([24.55.174.97]) by out016.verizon.net
(InterMail vM.5.01.04.05 201-253-122-122-105-20011231) with SMTP
id <20020426164023.IYXZ8115.out016.verizon.net@Vsosofue>
for <busgal58jb@aol.com>; Fri, 26 Apr 2002 11:40:23 -0500
From: joeyace <joeyace@sympatico.ca>
To: busgal58jb@aol.com
Subject: Language
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=Zi0B1iyX9O1u
Message-Id: <20020426164023.IYXZ8115.out016.verizon.net@Vsosofue>
Date: Fri, 26 Apr 2002 11:40:32 -0500
------------------
Janice "Busgal" Brooks
ICQ 44729047
- Joey Ace
- Posts: 9791
- Joined: 11 Feb 2001 1:01 am
- Location: Hamilton, Ontario, Canada
- Contact:
My computer did not send you that message, Janice. I suspect my email address was "spoofed".
That means someone else had my name and email address in their Addr Book. They got infected and it sent emails out with my name.
There's a free removal tool for this virus at Symantec http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.removal.tool.html
I keep protected with Norton AV and DO NOT open attachments.
Just to be sure, I downloaded and ran the tool in the above link. After about 30 min of examining my system it reported I had no infected files. Per their instructions, I ran it again. Still OK.
I suggest you do the same.
I regularly get attachments from suspicious addresses.
The best advice is
Do Not Open Any Attachments.
Hope you're OK.
-j0ey-<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Joey Ace on 26 April 2002 at 05:47 PM.]</p></FONT>
That means someone else had my name and email address in their Addr Book. They got infected and it sent emails out with my name.
There's a free removal tool for this virus at Symantec http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.removal.tool.html
I keep protected with Norton AV and DO NOT open attachments.
Just to be sure, I downloaded and ran the tool in the above link. After about 30 min of examining my system it reported I had no infected files. Per their instructions, I ran it again. Still OK.
I suggest you do the same.
I regularly get attachments from suspicious addresses.
The best advice is
Do Not Open Any Attachments.
Hope you're OK.
-j0ey-<FONT SIZE=1 COLOR="#8e236b"><p align=CENTER>[This message was edited by Joey Ace on 26 April 2002 at 05:47 PM.]</p></FONT>
- Colin Goss
- Posts: 338
- Joined: 4 Aug 1998 11:00 pm
- Location: St.Brelade, Island of Jersey, Channel Islands, UK
I recommend that you consider using Zonealarm, a free firewall program that automatically renames all attachments before giving you the option of whether to run them or not. This prevents the nasties getting through.
Then use AVG virus checker from Grisoft - also free,
Finally use Mailwasher (mailwasher.net) also free to get rid of spam.
Then use AVG virus checker from Grisoft - also free,
Finally use Mailwasher (mailwasher.net) also free to get rid of spam.
- Joey Ace
- Posts: 9791
- Joined: 11 Feb 2001 1:01 am
- Location: Hamilton, Ontario, Canada
- Contact:
-
- Posts: 802
- Joined: 28 Dec 1999 1:01 am
- Location: peckerwood point, w. tn.