Tom's Guide | Tom's Hardware | Tom's Games
![]() |
![]() |
![]() |
windows xp pro
700celeron
320 ram
80gig hd
my computer has e-mailed a virus to itself from my account to my wifes adress. i have gone to norton and tried the fix and nothing was found. i tried housecall and nothing was found. ive done scans religeously and nothing is found. i am at my wits end
PLEASE HELP
thanks
wojo

Email spoofing
This worm often uses a technique known as "spoofing." When it performs its email routine. it can use a randomly chosen address that it finds on an infected computer as the "From:" address, numerous cases have been reported in which users of uninfected computers received complaints that they sent an infected message to someone else.For example, Linda Anderson is using a computer that is infected with W32.Klez.H@mm. Linda is not using a antivirus program or does not have current virus definitions. When W32.Klez.H@mm performs its emailing routine, it finds the email address of Harold Logan. It inserts Harold's email address into the "From:" portion of an infected message that it then sends to Janet Bishop. Janet then contacts Harold and complains that he sent her an infected message, but when Harold scans his computer, Norton AntiVirus does not find anything--as would be expected--because his computer is not infected.
If you are using a current version of Norton AntiVirus and have the most recent virus definitions, and a full system scan with Norton AntiVirus set to scan all files does not find anything, you can be confident that your computer is not infected with this worm.
There have been several reports that, in some cases, if you receive a message that the virus has sent using its own SMTP engine, the message appears to be a "postmaster bounce message" from your own domain. For example, if your email address is jsmith@anyplace.com, you could receive a message that appears to be from postmaster@anyplace.com, indicating that you attempted to send email and the attempt failed. If this is the false message that is sent by the virus, the attachment includes the virus itself. Of course, such attachments should not be opened.
The message may be disguised as an immunity tool. One version of this false message is as follows:

thank you MR WIZARD!!!!!!
I have been going mad chasing something that isnt there.
your senario was mine exactly
over the past few months ive had the infected e-mails from my computer.
ive also had the postmaster state i tried to send a virus but actually had sent nothing.
this was the 4th time i did a full scan by 2 different anti-virus fix tools. and also full scans with the anti-virus. i always keep the virus defs up to date and scan weekly.
thanks again for letting me sleep again at nightwojo

I am still getting mail that says I have the Win32.Klez Virus (after a WEEK of this!) It is also not allowing me to reinstall my McAfee 6.0 because it says I have to uninstall v.4.5.0, but it won't allow me to UNinstall because it repeats that I have to have all applications closed (which I do) and can't continue. I also can no longer find V.4.50 anywhere on my computer (no virus shield icon! but listed as a program)
HELP!!!!

You will have to get rid of KLEZ Christine before trying to reinstall your AV software. If you don't Klez will just keep disabling it. Find the instructions for removing the virus, like @ Trendmicro.com or Symantec.com. Once you have Klez removed, then load you AV software from the CD or Disk.
Underdog
V-Peace-V

I am having a problem with email spoofing just as described in Mr Wizards response. I do not have the virus I have scanned my system and do live updates every few days. Although I do not have the virus it is very frustrating to keep getting all the supposedly returned email with the virus attached. Norton keeps catching it but... I just had to delete 36 emails that were quarantined by norton in the last few days, both the returned from postmaster type and seemingly directly sent emails with a virus attachment.
Is there any way to stop this email?

![]() |
![]() |
![]() |

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.
| Ads by Google |