_Keep_it_Free_ opened this issue on Jun 04, 2002 ยท 25 posts
cooler posted Tue, 04 June 2002 at 9:11 AM
if you run the attachments through a virus scanner you'll find (along with all of them being 125K) that they contain the Klez virus. Here's the NAV logfile from the last one I received... Date: 5/17/02, Time: 4:06:22 AM, cooler on L9A5K6 The file D:EudoraAttachLtf.scr was infected with the W32.Klez.gen@mm virus. One of the pecularities of this virus is that it pulls a random email address & subject from your history file in order to disguise it's true origin. The one above looked like it was sent by a fellow poser modeller & took a bit of digging to find out where it really did come from. DO NOT try to run any of these attachments. If you have & even if it seems like nothing happened you are probably still infected. There is a variant of Klez that is time activated and will lay dormant until the 6th of the month & then activate & destroy all your files with txt, .htm, .html, .wab, .doc, .xls,.jpg, .cpp, .c, .pas, .mpg, .mpeg, .bak, and .mp3. extensions as well as 'seek & destroy' any virus scanning software it finds You can read all abotu it at... http://vil.nai.com/vil/content/v_99367.htm or http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html