Main      Site Guide    
Message Forum
Klez (was "Help! Is this for real?")
Posted By: Lucky Wizard, on host 4.65.253.80
Date: Wednesday, July 31, 2002, at 17:03:11
In Reply To: Help! Is this for real? posted by Howard on Wednesday, July 31, 2002, at 16:31:28:

> My computer is all messed up. Then I get the same email from both my sister in Massachusettes and my nephew in California. Neither is likely to be taken in by a hoax. Could this be the problem? I don't open any attachments that are the least bit questionable, but this computer has lost two thirds of its functions. The sentence stucture sounds like some of those cons that come out Asia or Africa.
>
> Trendmicro give you the W32.Klez.E removal tools
> W32.Klez.E is a dangerous virus that spread through email.
>
> For more information,please visit http://www.Trendmicro.com
>
> Help!
> Howard

It sounds like you have a virus called W32.Klez.H (different from W32.Klez.E). I've linked to a page about it. It's worth noting that Klez.H sometimes disguises itself as a Klez.E immunity tool, and that Trendmicro sometimes gets mentioned in Klez.H-infected emails. (Also, the email you quote is as badly written as the one Symantec quotes.)

The other thing that is worth noting is that the virus, in all likelihood, was never on your sister's computer or your nephew's computer. Klez.H spoofs email addresses (for more information, please scroll down to the "Email spoofing" section in the page I linked -- "Email spoofing" is under "technical details").

Lucky "I know about Klez from personal experience -- I kept recieving Klez-infected emails with addresses of people on my mother's side of the family as the From line. The emails stopped after a while but I have no idea whose computer was infected with Klez in the first place." Wizard


Link: W32.Klez.H information

Post a Reply

RinkChat Username:
Password:
Email: (optional)
Subject:
Message:
Link URL: (optional)
Link Title: (optional)

Make sure you read our message forum policy before posting.