PDA

View Full Version : KLEZ Worm Running Amok



AGD-OfficeGal
06-19-2002, 05:19 PM
Hey guys--

I am receiving emails bearing viruses, especially the KLEZ worm, in masses every day. Others report receiving mails carrying KLEZ appearing to be from Airgun. The KLEZ worm spoofs the sender's address by taking an address from the infected computer's address book.

VIRUS CHECK YOUR SYSTEMS. Most of these emails are undoubtedly coming from paintballers who have put one of our general email addresses into their address books.

For additional information, see http://antivirus.about.com an excellent resource, and also http://www.symantec.com

Marcia

Links were dead. I fixed them.

JRSJKD
06-19-2002, 06:18 PM
oh oh.....if they have Klez its more than likely that their AV has been disabled and wont detect it even when they run a scan.......

Check your systems online here......

http://housecall.antivirus.com/

or try Symantec's removal tool....

http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.removal.tool.html

omni
06-19-2002, 06:19 PM
Here is a Free online scanner


http://housecall.antivirus.com/housecall/start_corp.asp

Edit: Sorry, I posted just after you :D fluke

MikeCouves
06-19-2002, 08:00 PM
I am downloading it now, does it work well though? There alot of free ones out there that JUST PLAIN SUCK! They stopped supporting my version of McAfee! Hmph.

JRSJKD
06-19-2002, 08:57 PM
Mike,
well.....its better than nothing. The online house call should at least detect it. I know the Symantec tool will detect it. Getting rid of Klez is a bit harder. I have a friend who's box I was trying to remove it from. The tool remove the first 50 files, but said it couldnt remove the other 478 files. One big problem is the system restore feature in Win ME and XP. You have to diable that first, boot into safe mode and then run the tool.

If your Mcafee is too old and your looking for something new, I strongly recommend Nod-32. Not real well known, but has an outstanding track record with "real" virus experts(not Cnet, pcworld, etc.). Its only 40 dollars, boasts its 18th Virus Bulletin 100% award, and has never missed a virus in the wild test. Its heuristics are second to none. In addition to that, it is entirely written in machine code...meaning really fast scans. Im usually able to do a FULL system scan in under 4 minutes.


find them here....

http://www.nod32.com/home/home.htm

Happy Hunting!!!

XxSHaRpShOoTaxX
06-19-2002, 09:15 PM
mike same with me so i used that symantec cuz my computer has been turnin off on its self and i have 2 trojans sub7 and backdoor on mine and 101 files were infected =/ mcafee sux!

JRSJKD
06-19-2002, 10:05 PM
Dont wanna bad mouth, but Mcafee isnt a favorite of mine.

Trojans are a different issue. Some AV(anti virus)can detect them, but as a general rule you should run a anti-trojan specific program. Your AV cant do it all alone.

2 sub7's is bad news. You got hacked, who knows what your computer has been used to do!?!?!?

Perhaps the best, steep learning curve, heavy on resources, with newer version on the way...TDS-3 :D

http://tds.diamondcs.com.au/

Outstanding, easier to use, not as big a learning curve....Trojan Hunter

http://www.mischel.dhs.org/trojanhunter.jsp


While I dont think that everyone NEEDs a AT program, to have a computer connected to the internet with a broadband connection without using a software firewall is just reckless.

Free....really popular....Zona Alarm

http://www.zonelabs.com/store/content/home.jsp

My fav....Sygate

http://sygate.com/

Excellent also......gonna try soon...Tiny Personal Firewall

http://www.tinysoftware.com/home/tiny2?la=EN

Riotz
06-19-2002, 10:35 PM
I get 5 of these emails a day...

I suggest Norton Antivirus. It hasn't given me any problems yet and their software is easy to update.


Oh ya, and people. Don't install two virus scanners at once. It causes conflicts, doesn't help to protect any better. ;)

bornl33t
06-19-2002, 10:50 PM
speaking of... I started getting E-mails with files attached etc... I don't open file if I don't know where they are coming from .. but I keep getting more and more of these... always 2 files.. usually one a pics the other a app of sorts .. the e-mails are empty, and the addresses are Hotmail.com usually... I have run MANY virus scanners over my Hd in the last few days and none of them seem to think these apps are infected... anyone know what they are and how to get the ppl that send them out? It's just bothering me right now... but I may end up going on a shooting rampage if it doesn't quit.. I have VERY short nerves!

Riotz
06-19-2002, 10:55 PM
Heat, go here and read more about it http://vil.mcafee.com/dispVirus.asp?virus_k=99455


Even IF the sender is a FRIEND. It may be the virus. As said earlier. This virus SPOOFS (fakes) email addresses. So you may think your friend is sending you something, but's it's just the virus pretending to be them. This virus usually includes two files with it, 1 program file and another document file. Read more at that link.

Becareful. This thing has been going on for two months and it's annoying.

pito189
06-19-2002, 11:55 PM
Just want to reply to this thread, it if full of very useful information. I hope everything works out fine in the end for all of you.

XxSHaRpShOoTaxX
06-20-2002, 12:20 AM
i had blackice firewall and it would give me the ips and everything on who would attack me but i got rid of it cuz nothin serious and now i got a trojan =/

speedballbanks
06-20-2002, 07:43 AM
Originally posted by XxSHaRpShOoTaxX
i had blackice firewall and it would give me the ips and everything on who would attack me but i got rid of it cuz nothin serious and now i got a trojan =/

to get rid of a trojan get like netbus or system 7 and connect to your ip and delete it.

Webmaster
06-20-2002, 09:32 AM
I made this plea about 1 1/2 months ago. I get about 1mb worth of the virus a day in my webmaster account.

Linx
06-20-2002, 02:56 PM
You know what fixes 99% of viruses and worms?

Buying a Mac!


Sorry to make fun of a bad situation, I just had too.

speedballbanks
06-20-2002, 04:12 PM
Originally posted by Linx
You know what fixes 99% of viruses and worms?

Buying a Mac!


Sorry to make fun of a bad situation, I just had too.



you ain't kidding

Vegeta
06-20-2002, 11:01 PM
I refuse to use virus scanning software (cept a year old version of McAfee). My opinion is - i'm on 56K - if a hacker is determined enough to break into MY crapass system to get something.. then so be it.

And If I am stupid enough to download the virus from an attachment, I deserve it. I never download attachements otehr than JPG/GIF and YES i do check for file.jpg.exe crap. I have never gotten a Virus in the 4 years I have been on the web.


Disclaimer: I do not have any @airgun.com adresses in any of my addy books. Wusn't my fualt.