Ironworks Gaming Forum

Ironworks Gaming Forum (http://www.ironworksforum.com/forum/index.php)
-   General Conversation Archives (11/2000 - 01/2005) (http://www.ironworksforum.com/forum/forumdisplay.php?f=28)
-   -   Who keeps sending the Klez virus around the place? (http://www.ironworksforum.com/forum/showthread.php?t=74810)

Memnoch 05-04-2002 01:54 PM

It's going to my tgeweb.com address, which means that it's being sent by someone who's visited Ironworks. Some of you guys might be getting sent it as well - I've received it 10 times in the last 2 hours (but my antivirus has killed it each time).

Get updates to your virus definitions, and scan bigtime! This one's annoying... :mad:

Krishach 05-04-2002 01:55 PM

Anti... virus... ?

Talthyr Malkaviel 05-04-2002 01:58 PM

Haven't heard of this one, what does this particular one do??

Campino 05-04-2002 01:58 PM

Thanks for the warning Memnoch.Just started to scan.

And for all those without antivirus:a virus can get to YOUR
computer as well.Get protection!

Ar-Cunin 05-04-2002 01:59 PM

Thanks for the advice - scanning in progress

Although I'm not sure it would get past my firewall

But better safe than soory

Galadria 05-04-2002 02:00 PM

Thanks for the heads-up, Memmy. I always delete anything that I don't expect. What does it show as? (Hmm, who do I know that's been banned lately?)

Krishach 05-04-2002 02:02 PM

Firewalls are annoying, conflict with hosting games too much. Where could I download a free Anti-Virus program?

Memnoch 05-04-2002 02:04 PM

Here...

<font color="silver">
W32.Klez.gen@mm is a mass-mailing worm that searches the Windows address book for email addresses and sends messages to all recipients that it finds. The worm uses its own SMTP engine to send the messages.

The subject and attachment name of incoming emails is randomly chosen. The attachment will have one of the following extensions: .bat, .exe, .pif or .scr.

The worm exploits a vulnerability in Microsoft Outlook and Outlook Express in an attempt to execute itself when you open or even preview the message. Information and a patch for the vulnerability can be found at
http://www.microsoft.com/technet/sec...n/MS01-020.asp
W32.Klez.gen@mm attempts to copy itself to all network shared drives that it finds.

Depending on which variant of the worm, the worm will drop one of the following viruses:

W32.Elkern.3326
W32.Elkern.3587
W32.Elkern.4926

which will then infect the system.

Email spoofing
Some variants of this worm use a technique known as "spoofing." If it does this, it chooses at random an address that it finds on an infected computer as the "From:" address that it uses when it performs its mass-mailing routine. Numerous cases have been reported in which users of uninfected computers receive complaints that they have sent an infected message to someone else.

For example, Linda Anderson is using a computer that is infected with W32.Klez.E@mm; Linda is not using a antivirus program or does not have current virus definitions. When W32.Klez.gen@mm performs its emailing routine, it finds the email address of Harold Logan. It inserts Harold's email address into the "From:" line of an infected email that it then sends to Janet Bishop. Janet then contacts Harold and complains that he sent her infected email, but when Harold scans his computer, Norton AntiVirus does not find anything--as would be expected--because his computer is not infected.

If you are using a current version of Norton AntiVirus, have the most recent virus definitions, and a full system scan with Norton AntiVirus set to scan all files does not find anything, you can be confident that your computer is not infected with this worm.
</font>

(Mem--I removed the '.' at the end of the URL)

[ 05-05-2002, 01:45 AM: Message edited by: Ziroc ]

Campino 05-04-2002 02:06 PM

Go here to get a free demo of Norton.

But seriously consider buying it yourself.could prevent a lot of trouble.

Krishach 05-04-2002 02:12 PM

Buy? Gah, I hate buying stuff.


All times are GMT -4. The time now is 09:46 AM.

Powered by vBulletin® Version 3.8.3
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
©2024 Ironworks Gaming & ©2024 The Great Escape Studios TM - All Rights Reserved