Notices
ScoobyNet General General Subaru Discussion

**Someone on here needs to run this KLEZ Virus removal tool**

Thread Tools
 
Search this Thread
 
Old 07 April 2002 | 04:13 PM
  #1  
MarkCSC's Avatar
MarkCSC
Thread Starter
Scooby Regular
 
Joined: Apr 1999
Posts: 2,464
Likes: 0
From: Surferk
Post

Carl the virus spoofs your e-mail address. Your address is held on somebodies PC (lets call it X). X sends itself an e-mail that looks likes it comes from your e-mail address. The owner of X will probably send an e-mail to you saying you a have sent them a virus. You'll run the check and find no virus.
It's a bit complicated but explained well on the Norton site.

Mark

Bugger too late twice over!

[Edited by Mark Champion - 7/4/2002 3:14:41 PM]
Old 07 April 2002 | 04:13 PM
  #2  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

Don't forget Klez can spoof the "From" Address.

I had a virus warning back from an ISP saying I'd sent an infected message when my PC was OFF and I was 30 miles sat outside enjoying the sunshine.

Our resident AV expert Jack Clark has suffered from this as well.

[Edited by ChrisB - 7/4/2002 3:14:02 PM]
Old 07 April 2002 | 04:51 PM
  #3  
mega_stream's Avatar
mega_stream
Scooby Regular
 
Joined: May 2001
Posts: 4,580
Likes: 0
From: Scotland
Talking

Carl, yup its me, I sent you the email yesterday asking who you were!
Thought what the heck is this guy doing sending me a "good tool"

Gotta hand it to the little shytes that write these damn viruses..

[Edited by mega_stream - 7/4/2002 3:51:30 PM]
Old 07 April 2002 | 04:55 PM
  #4  
DJ Dunk's Avatar
DJ Dunk
Moderator
iTrader: (5)
 
Joined: Nov 2001
Posts: 17,864
Likes: 0
From: Not all those who wander are lost
Post

Mine came from 'scoobiedude@hotmail.com' or something

Never mind, good 'ol Sophos should have licked it anyway
The virus, not the good tool

[Edited by DJ Dunk - 7/4/2002 3:56:15 PM]
Old 04 July 2002 | 03:22 PM
  #5  
mega_stream's Avatar
mega_stream
Scooby Regular
 
Joined: May 2001
Posts: 4,580
Likes: 0
From: Scotland
Exclamation

I got an email yesterday from someone titled "A good tool", didn't know who it was from so I thought I'ld check out the domain where the mail originated....an Impreza owner...emailed him and asked him, turns out he's been getting suspect emails from various people on Scoobynet.

I know this ones probably been done before, but can people check they have AV software on there PC's! (and its up-to-date)

The clean for this particular virus can be found here..

http://antivirus.about.com/gi/dynami...oval.tool.html

Please read the instructions before using this..

Cheers all
Old 04 July 2002 | 03:35 PM
  #6  
DJ Dunk's Avatar
DJ Dunk
Moderator
iTrader: (5)
 
Joined: Nov 2001
Posts: 17,864
Likes: 0
From: Not all those who wander are lost
Post

I got sent this too. The title is pretty suspicsious so I deleted it straight away.

I too got it from an "Impreza owner"
Old 04 July 2002 | 03:44 PM
  #7  
carl's Avatar
carl
Scooby Regular
 
Joined: May 1999
Posts: 7,901
Likes: 0
Post

Ooh, was it from me?

<carl@bogart.org.uk>

I don't think I have a virus -- it virus-checks clean, I don't have either of your e-mail addresses in my address book, and I don't use microsoft mail software. Also the mail allegedly sent from me was at a time when none of my machines were switched on.

Old 04 July 2002 | 04:11 PM
  #8  
carl's Avatar
carl
Scooby Regular
 
Joined: May 1999
Posts: 7,901
Likes: 0
Post

Update -- I read up on the Klez worm and apparently some variants are able to spoof the originator's address. This may explain why I received an e-mail with an attachment specific to MRO Scoobystyling, but the e-mail's originator was not Rob of MRO. It also suggests that someone with one of my e-mail addresses in their address book (who is using Outlook/Outlook Express) has this worm.
Old 04 July 2002 | 04:13 PM
  #9  
NotoriousREV's Avatar
NotoriousREV
Scooby Regular
 
Joined: Jan 2002
Posts: 11,581
Likes: 0
Post

Don't forget, Klez masks it's origination point, so the senders e-mail address is pretty useless. Look at the sending machines host IP, you should be able to track it down to an ISP and then you can say "A **** user needs to run this Klez removal tool"
Old 04 July 2002 | 04:17 PM
  #10  
ChrisB's Avatar
ChrisB
Moderator
 
Joined: Dec 1998
Posts: 23,573
Likes: 0
From: Staffs
Post

Oh, a decent ISP will virus scan your e-mails for you before you even download them (just like Titan...
Old 04 July 2002 | 04:26 PM
  #11  
Little Miss WRX's Avatar
Little Miss WRX
Moderator
 
Joined: Jul 2001
Posts: 19,910
Likes: 0
Wink

LOL@Mr B, no association with them blah, blah etc don't forget

My AV is updated, I have run the Klez check on mine and I am free, yet it has spoofed my email address as if I was the sender.

Worth doing a quick check, doesn't take long

Michelle.
Old 04 July 2002 | 04:53 PM
  #12  
carl's Avatar
carl
Scooby Regular
 
Joined: May 1999
Posts: 7,901
Likes: 0
Post

I assure you I keep my tool under close wraps
Old 04 July 2002 | 05:40 PM
  #13  
mega_stream's Avatar
mega_stream
Scooby Regular
 
Joined: May 2001
Posts: 4,580
Likes: 0
From: Scotland
Post

LOL

I didn't tweek that it was a virus at first (due to my Defcon5 AV setup ), so I actually sent Carl an email saying there was no attachment..

I guess what threw me was my recent post about Dewalt power tools


Old 04 July 2002 | 05:46 PM
  #14  
Markus's Avatar
Markus
Scooby Regular
 
Joined: Mar 1999
Posts: 25,080
Likes: 0
From: The Great White North
Post

yeah, klez seems to be infecting quite a few people. have helped some of my RS friends clean it up.

Nasty ****** it is too!

Why do people write viruses?? WHY???
Old 04 July 2002 | 06:15 PM
  #15  
carl's Avatar
carl
Scooby Regular
 
Joined: May 1999
Posts: 7,901
Likes: 0
Post

...because they're paid to do so by Anti-Virus companies?

[Sorry, JackClark ]
Related Topics
Thread
Thread Starter
Forum
Replies
Last Post
SilverM3
ScoobyNet General
8
24 February 2021 02:03 PM
Tarling
Subaru Parts
10
19 October 2015 08:58 PM
shorty87
Other Marques
0
25 September 2015 09:52 PM
hedgecutter
General Technical
3
25 September 2015 03:35 PM
S600HBY
Subaru Parts
0
25 September 2015 10:46 AM




All times are GMT +1. The time now is 01:16 PM.