Notices
ScoobyNet General General Subaru Discussion
Sponsored by:
Sponsored by:

**Someone on here needs to run this KLEZ Virus removal tool**

Thread Tools
 
Search this Thread
 
Old 07 April 2002, 03:13 PM
  #1  
MarkCSC
Scooby Regular
Thread Starter
 
MarkCSC's Avatar
 
Join Date: Apr 1999
Location: Surferk
Posts: 2,464
Likes: 0
Received 0 Likes on 0 Posts
Post

Carl the virus spoofs your e-mail address. Your address is held on somebodies PC (lets call it X). X sends itself an e-mail that looks likes it comes from your e-mail address. The owner of X will probably send an e-mail to you saying you a have sent them a virus. You'll run the check and find no virus.
It's a bit complicated but explained well on the Norton site.

Mark

Bugger too late twice over!

[Edited by Mark Champion - 7/4/2002 3:14:41 PM]
Old 07 April 2002, 03:13 PM
  #2  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

Don't forget Klez can spoof the "From" Address.

I had a virus warning back from an ISP saying I'd sent an infected message when my PC was OFF and I was 30 miles sat outside enjoying the sunshine.

Our resident AV expert Jack Clark has suffered from this as well.

[Edited by ChrisB - 7/4/2002 3:14:02 PM]
Old 07 April 2002, 03:51 PM
  #3  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Talking

Carl, yup its me, I sent you the email yesterday asking who you were!
Thought what the heck is this guy doing sending me a "good tool"

Gotta hand it to the little shytes that write these damn viruses..

[Edited by mega_stream - 7/4/2002 3:51:30 PM]
Old 07 April 2002, 03:55 PM
  #4  
DJ Dunk
Moderator
Support Scoobynet!
iTrader: (5)
 
DJ Dunk's Avatar
 
Join Date: Nov 2001
Location: Not all those who wander are lost
Posts: 17,863
Received 0 Likes on 0 Posts
Post

Mine came from 'scoobiedude@hotmail.com' or something

Never mind, good 'ol Sophos should have licked it anyway
The virus, not the good tool

[Edited by DJ Dunk - 7/4/2002 3:56:15 PM]
Old 04 July 2002, 02:22 PM
  #5  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Exclamation

I got an email yesterday from someone titled "A good tool", didn't know who it was from so I thought I'ld check out the domain where the mail originated....an Impreza owner...emailed him and asked him, turns out he's been getting suspect emails from various people on Scoobynet.

I know this ones probably been done before, but can people check they have AV software on there PC's! (and its up-to-date)

The clean for this particular virus can be found here..

http://antivirus.about.com/gi/dynami...oval.tool.html

Please read the instructions before using this..

Cheers all
Old 04 July 2002, 02:35 PM
  #6  
DJ Dunk
Moderator
Support Scoobynet!
iTrader: (5)
 
DJ Dunk's Avatar
 
Join Date: Nov 2001
Location: Not all those who wander are lost
Posts: 17,863
Received 0 Likes on 0 Posts
Post

I got sent this too. The title is pretty suspicsious so I deleted it straight away.

I too got it from an "Impreza owner"
Old 04 July 2002, 02:44 PM
  #7  
carl
Scooby Regular
 
carl's Avatar
 
Join Date: May 1999
Posts: 7,901
Likes: 0
Received 0 Likes on 0 Posts
Post

Ooh, was it from me?

<carl@bogart.org.uk>

I don't think I have a virus -- it virus-checks clean, I don't have either of your e-mail addresses in my address book, and I don't use microsoft mail software. Also the mail allegedly sent from me was at a time when none of my machines were switched on.

Old 04 July 2002, 03:11 PM
  #8  
carl
Scooby Regular
 
carl's Avatar
 
Join Date: May 1999
Posts: 7,901
Likes: 0
Received 0 Likes on 0 Posts
Post

Update -- I read up on the Klez worm and apparently some variants are able to spoof the originator's address. This may explain why I received an e-mail with an attachment specific to MRO Scoobystyling, but the e-mail's originator was not Rob of MRO. It also suggests that someone with one of my e-mail addresses in their address book (who is using Outlook/Outlook Express) has this worm.
Old 04 July 2002, 03:13 PM
  #9  
NotoriousREV
Scooby Regular
 
NotoriousREV's Avatar
 
Join Date: Jan 2002
Posts: 11,581
Likes: 0
Received 0 Likes on 0 Posts
Post

Don't forget, Klez masks it's origination point, so the senders e-mail address is pretty useless. Look at the sending machines host IP, you should be able to track it down to an ISP and then you can say "A **** user needs to run this Klez removal tool"
Old 04 July 2002, 03:17 PM
  #10  
ChrisB
Moderator
 
ChrisB's Avatar
 
Join Date: Dec 1998
Location: Staffs
Posts: 23,573
Likes: 0
Received 0 Likes on 0 Posts
Post

Oh, a decent ISP will virus scan your e-mails for you before you even download them (just like Titan...
Old 04 July 2002, 03:26 PM
  #11  
Little Miss WRX
Moderator
 
Little Miss WRX's Avatar
 
Join Date: Jul 2001
Posts: 19,910
Likes: 0
Received 0 Likes on 0 Posts
Wink

LOL@Mr B, no association with them blah, blah etc don't forget

My AV is updated, I have run the Klez check on mine and I am free, yet it has spoofed my email address as if I was the sender.

Worth doing a quick check, doesn't take long

Michelle.
Old 04 July 2002, 03:53 PM
  #12  
carl
Scooby Regular
 
carl's Avatar
 
Join Date: May 1999
Posts: 7,901
Likes: 0
Received 0 Likes on 0 Posts
Post

I assure you I keep my tool under close wraps
Old 04 July 2002, 04:40 PM
  #13  
mega_stream
Scooby Regular
 
mega_stream's Avatar
 
Join Date: May 2001
Location: Scotland
Posts: 4,580
Likes: 0
Received 0 Likes on 0 Posts
Post

LOL

I didn't tweek that it was a virus at first (due to my Defcon5 AV setup ), so I actually sent Carl an email saying there was no attachment..

I guess what threw me was my recent post about Dewalt power tools


Old 04 July 2002, 04:46 PM
  #14  
Markus
Scooby Regular
 
Markus's Avatar
 
Join Date: Mar 1999
Location: The Great White North
Posts: 25,080
Likes: 0
Received 0 Likes on 0 Posts
Post

yeah, klez seems to be infecting quite a few people. have helped some of my RS friends clean it up.

Nasty ****** it is too!

Why do people write viruses?? WHY???
Old 04 July 2002, 05:15 PM
  #15  
carl
Scooby Regular
 
carl's Avatar
 
Join Date: May 1999
Posts: 7,901
Likes: 0
Received 0 Likes on 0 Posts
Post

...because they're paid to do so by Anti-Virus companies?

[Sorry, JackClark ]
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
SilverM3
ScoobyNet General
8
24 February 2021 01:03 PM
Tarling
Subaru Parts
10
19 October 2015 07:58 PM
shorty87
Other Marques
0
25 September 2015 08:52 PM
hedgecutter
General Technical
3
25 September 2015 02:35 PM
S600HBY
Subaru Parts
0
25 September 2015 09:46 AM



Quick Reply: **Someone on here needs to run this KLEZ Virus removal tool**



All times are GMT +1. The time now is 06:17 PM.