Computing.Net > Forums > Security and Virus > W32.Klez.H@mm

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

W32.Klez.H@mm

Reply to Message Icon

Name: wojo
Date: August 29, 2002 at 16:29:09 Pacific
Comment:

windows xp pro
700celeron
320 ram
80gig hd
my computer has e-mailed a virus to itself from my account to my wifes adress. i have gone to norton and tried the fix and nothing was found. i tried housecall and nothing was found. ive done scans religeously and nothing is found. i am at my wits end
PLEASE HELP
thanks
wojo



Sponsored Link
Ads by Google

Response Number 1
Name: MrWizard
Date: August 29, 2002 at 17:16:55 Pacific
Reply:

Email spoofing
This worm often uses a technique known as "spoofing." When it performs its email routine. it can use a randomly chosen address that it finds on an infected computer as the "From:" address, numerous cases have been reported in which users of uninfected computers received complaints that they sent an infected message to someone else.

For example, Linda Anderson is using a computer that is infected with W32.Klez.H@mm. Linda is not using a antivirus program or does not have current virus definitions. When W32.Klez.H@mm performs its emailing routine, it finds the email address of Harold Logan. It inserts Harold's email address into the "From:" portion of an infected message that it then sends to Janet Bishop. Janet then contacts Harold and complains that he sent her an infected message, but when Harold scans his computer, Norton AntiVirus does not find anything--as would be expected--because his computer is not infected.

If you are using a current version of Norton AntiVirus and have the most recent virus definitions, and a full system scan with Norton AntiVirus set to scan all files does not find anything, you can be confident that your computer is not infected with this worm.

There have been several reports that, in some cases, if you receive a message that the virus has sent using its own SMTP engine, the message appears to be a "postmaster bounce message" from your own domain. For example, if your email address is jsmith@anyplace.com, you could receive a message that appears to be from postmaster@anyplace.com, indicating that you attempted to send email and the attempt failed. If this is the false message that is sent by the virus, the attachment includes the virus itself. Of course, such attachments should not be opened.

The message may be disguised as an immunity tool. One version of this false message is as follows:


0

Response Number 2
Name: wojo
Date: August 29, 2002 at 18:57:13 Pacific
Reply:

thank you MR WIZARD!!!!!!
I have been going mad chasing something that isnt there.
your senario was mine exactly
over the past few months ive had the infected e-mails from my computer.
ive also had the postmaster state i tried to send a virus but actually had sent nothing.
this was the 4th time i did a full scan by 2 different anti-virus fix tools. and also full scans with the anti-virus. i always keep the virus defs up to date and scan weekly.
thanks again for letting me sleep again at night

wojo


0

Response Number 3
Name: Christine
Date: August 31, 2002 at 05:07:10 Pacific
Reply:

I am still getting mail that says I have the Win32.Klez Virus (after a WEEK of this!) It is also not allowing me to reinstall my McAfee 6.0 because it says I have to uninstall v.4.5.0, but it won't allow me to UNinstall because it repeats that I have to have all applications closed (which I do) and can't continue. I also can no longer find V.4.50 anywhere on my computer (no virus shield icon! but listed as a program)
HELP!!!!


0

Response Number 4
Name: Underdog
Date: September 1, 2002 at 07:57:00 Pacific
Reply:

You will have to get rid of KLEZ Christine before trying to reinstall your AV software. If you don't Klez will just keep disabling it. Find the instructions for removing the virus, like @ Trendmicro.com or Symantec.com. Once you have Klez removed, then load you AV software from the CD or Disk.

Underdog
V-Peace-V


0

Response Number 5
Name: Gloria
Date: September 7, 2002 at 06:27:11 Pacific
Reply:

I am having a problem with email spoofing just as described in Mr Wizards response. I do not have the virus I have scanned my system and do live updates every few days. Although I do not have the virus it is very frustrating to keep getting all the supposedly returned email with the virus attached. Norton keeps catching it but... I just had to delete 36 emails that were quarantined by norton in the last few days, both the returned from postmaster type and seemingly directly sent emails with a virus attachment.

Is there any way to stop this email?


0

Related Posts

See More



Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: W32.Klez.H@mm

w32.klez.h@mm www.computing.net/answers/security/w32klezhmm/2488.html

W32.Klez.H@,mm www.computing.net/answers/security/w32klezhmm/1474.html

HELP!! Klez.H@mm Virus Attack!!! www.computing.net/answers/security/help-klezhmm-virus-attack/3419.html