Forum Moderators: phranque
I get about 10 e-mails a day that are infected with this virus. They are all addressed to the e-mail address found on my website and so are automatically forwarded to my home PC. I have two friends that have the same problem with infected e-mails coming from their websites.
Do you know a good forum to post about this?
Is it possible that EVERY domain is receiving so many infected e-mails? (That would be millions of us!) Or in fact could my PC somehow be causing this?
My domain e-mail address is NOT listed in my Outlook Express address list.
Thanks for any direction you can give,
Peter
look up your email's [url=http://www.psychotekk.de/extern/W32.ElKern.4926.htm]signature[/url] (the full header), the return-path is the
address the email actually comes from while 'from' contains a fake address
It gets e-amil addresses from address books and any local files on the infected machine.
It does fake the return address, and often uses the address of an uninfected machine as the return address. When people reply to this address to complain about receiving the virus, often this uninfected machine's owner goes batty trying to find the problem, because his/her machine is not infected!
For reference, I've received about four e-mails infected with W32.Klez.H@mm over the last couple of weeks.
Jim
The Klez.h variant, which appeared in mid-April, infects PCs whose users open the attachment to an infected e-mail. Confusing matters, the e-mail will have a random "from" address, selected from various sources on the original victim's hard drive. And it pairs this bogus sender's address with one of more than 120 different subject lines.
Sneaky Klez worm won't go away [zdnet.com.com]
You can protect yourself some but no one can 100% of the time from these email harverstors by going to [vgernet.net...] and getting some education on the subject.
I did have an email address for an anti spam encrypting machine that I used awhile back...seems to go somewhere else now.
My solution is to change your email address and put a php feedback form on your site where even view source does not show it.
My biggest problems come from forums....these are also harvested. For them I use a temp@ address so I can change it when it becomes too popular. :)
Ann
>>>>
Klez.E is the most common world-wide spreading worm.It's very dangerous by corrupting your files.
Because of its very smart stealth and anti-anti-virus technic,most common AV software can't detect or clean it.
We developed this free immunity tool to defeat the malicious virus.
You only need to run this tool once,and then Klez will never come into your PC.
NOTE: Because this tool acts as a fake Klez to fool the real worm,some AV monitor maybe cry when you run it.
If so,Ignore the warning,and select 'continue'.
If you have any question,please mail to me.
<<<<
Some filter rules are listed here:
[webmasterworld.com...]
If others of you have Norton and have not used this feature, I'd recommend you give it a try and see if it doesn't work for you. I don't use McAfee, but I'm sure they have the same type of feature within their program, too.
I get all the e-mails, but the virus has been deleted. Is this what you mean? Or is there a way to set it up so that you never even know you received the infected e-mail?
Thanks, Peter
Don't get to excited. Yesterday I "previewed" a message from aol.com through mailwasher. NAV poped up and stated that it was infected with the klez virus. Mailwasher froze,I froze and NAV said it deleted/repaired the file. My system started asking for setup disks everytime I went to run a program. NAV probably went overboard :(
But Mailwasher sure will not protect you ;)
I just formated and re-installed W2K.
Mailwasher sure will not protect youdstanovic are you sure it was the MailWasher preview that did that? I've previewed lots of messages that I know are infected on MailWasher and Norton AV never blinked...and I've got my virus definitions updated every day and the heuristics set to the highest level, along with a nightly full system scan.
sounds fishy...
My 2-cents
How paranoid do we have to be about this?
Hitting preview the message causes the NAV to kick in its port 110 checker or something, I guess. NAV is the culprit here, not mailwasher.
I guess I should say I don't have NAV or McAfee on my system because mailwasher does the job for me without the overhead of the scare tactic programs I just mentioned that bloat your system and in general, will NOT always work.
i'm receiving some 15-20 infected emails per day, not including the bounce messages from servers with virus protection or for non-existant mailboxes. but the worst aspect of it is that whoever is infected is probably a client of mine as the emails being sent use my business email addresses.
when bounced emails come back, they often come with the full header information of the original mail. this shows the ISP used when the email was sent. by comparing this with the headers in emails sent by my clients, i've narrowed it down to any of about 100 clients. hopefully, if i email them all with the norton stuff, whoever has the virus should be able to clear it up and everything will be ok again.