Note: This is an archived topic. It is read-only.
  ProwlerOnline, Plymouth/Chrysler Prowler Discussion Forum
  Off Topic
  klenz32 (Page 2)

UBBFriend: Email This Page to Someone!

profile | register | preferences | faq | search


This topic is 2 pages long:   1  2 
This topic was originally posted in this forum: Tires, Rims Discusssion
Author Topic:   klenz32
Key Man
Prowler Junkie

Posts: 255
From: Canada
Registered: MAR 2002

posted 05-22-2003 10:50 PM     Click Here to See the Profile for Key Man     
I opened an email that said "2002 Silver Prowler see my beautiful girlfriend" didn't notice my virus protect didn't open, every body on my contact list got an email within 10 minutes which was returned to me as a failed delivery notice. This is the second time this has happened to me using this site. What's up with this.


ed monahan
Prowler Junkie

Posts: 33595
From: Cincinnati, OH
Registered: JUL 2000

posted 05-22-2003 10:58 PM     Click Here to See the Profile for ed monahan     
Sounds like you need to update your Norton anti-virus. If no one else's computer accepted it, yours must be faulty. The Klez virus has been around for about a year. I still get a few a week but not 10 a day like I had been getting. Hope your computer is okay.


Key Man
Prowler Junkie

Posts: 255
From: Canada
Registered: MAR 2002

posted 05-23-2003 12:32 AM     Click Here to See the Profile for Key Man     
Ed
I bought the o3 version of Norton & couldn't load it, after I reset my comp to 2000 default settings, they could do nothing for me and still billed me aprox $70 for their time so I BLEW $140.I tried Safeworld, & that got kicked out when this vitrus took over again I'm still infected,(Safeworld Suks) I am so sorry for people that get my unintentional e-mails. I can only hope your Anti virus is curent.
PS. I know of one person that no longer acesses this site because of viruses.
Alan
(very p*ssed with a lot of people that I don't even know!


CTProwler
Prowler Junkie

Posts: 3915
From: Sherman CT USA
Registered: NOV 2002

posted 05-23-2003 06:55 AM     Click Here to See the Profile for CTProwler     
Don't open emails unless you know who it is. email them back and ask if not sure. Happens alot. People use POA or Prowler in their emails to trick you . Be careful


ed monahan
Prowler Junkie

Posts: 33595
From: Cincinnati, OH
Registered: JUL 2000

posted 05-23-2003 09:02 AM     Click Here to See the Profile for ed monahan     
Alan, I do not know enough about computers to help you but I am sure someone on POA can help you out. Sorry to hear about all of that. The KLEZ is very tricky. I had a huge problem last year but finally got it figured out.


Black Tie 161
Prowler Junkie

Posts: 3563
From: MD, USA
Registered: JUL 2002

posted 05-23-2003 09:15 AM     Click Here to See the Profile for Black Tie 161     
The Klez virus actually PREVENTS anti-virus software from loading!

Since I joind this board, I have gotten some crazy messages from members with the "Klez virus" attached. This is a virus that goes into your email address book, and SELF GENERATES email to others and makes it look like someone else sent it. This is a very vicious virus, and ALL of you should download an anti-virus software program, since this virus is very destructive and self-perpetuating. Home computers are much more vulnerable since there are less firewalls...
Below is some info to help you....I strongly suggest you look into it if you have been getting wierd emails and God forbid if you had opened the attachments!
Any of you using MS Explorer have a vulnerability that is exploited by this virus. If you EVER got any funny emails with shady attachments......even from people you know, you may have the virus. It is a vicious virus that infects your email and sends itself to people in your address book without your knowledge. I got a virus protection package from www.Mcafee.com that killed it....But I had to manually disable the virus through a series of emailed instructions because the virus actually prevents anti-virus software from being loaded!

There are also free patches for Explorer at www.msn.com to close the virus loophole.

If any of you got wierd emails, this may help explain.....

I hope this helped awareness of this virus.....it is nasty!

-Joe


Virus Profile

Virus Name: Risk Assessment:
W32/Klez.h@MM Medium

Virus Information:
Date Discovered: 4/17/2002
Date Added: 4/17/2002
Origin: Unknown
Length: approx 90kB
Type: Internet Worm
SubType: Win32
DAT Required: 4182

Quick Links:
Virus Characteristics
Indications of Infection
Method of Infection
Removal Instructions
Aliases
Send Virus Info via Email

Update VirusScan
Online


Download the latest
DAT files


Virus Characteristics:

--- Update 4/30/2002 ---
This virus remains at a Medium Risk overall, however AVERT is still seeing many infections reported from Home Users and is informing Home Users that they are STILL at a HIGHER likelyhood of infection than corporate users.
HOME USERS SHOULD UPDATE THEIR DATS AS SOON AS POSSIBLE TO PREVENT INFECTION

--- Update 4/18/2002 ---
AVERT has raised the risk assessment of this threat to Medium after seeing an increase in prevalence over the past 24 hours. Home users are at a greater risk of infection, as they tend to update their DATs less frequently then corporations. As such, the risk of becoming infected in a corporate environment is lower.

This latest W32/Klez variant is already detected as W32/Klez.gen@MM by McAfee products using the 4182 DATs (23 January 2002) or greater.

W32/Klez.h@MM has a number of similarities to previous W32/Klez variants, for example:

W32/Klez.h@MM makes use of Incorrect MIME Header Can Cause IE to Execute E-mail Attachment vulnerability in Microsoft Internet Explorer (ver 5.01 or 5.5 without SP2).
the worm has the ability to spoof the From: field (often set to an address found on the victim machine).
the worm attempts to unload several processes (antivirus programs) from memory. Including those containing the following strings:
_AVP32
_AVPCC
NOD32
NPSSVC
NRESQ32
NSCHED32
NSCHEDNT
NSPLUGIN
NAV
NAVAPSVC
NAVAPW32
NAVLU32
NAVRUNR
NAVW32
_AVPM
ALERTSVC
AMON
AVP32
AVPCC
AVPM
N32SCANW
NAVWNT
ANTIVIR
AVPUPD
AVGCTRL
AVWIN95
SCAN32
VSHWIN32
F-STOPW
F-PROT95
ACKWIN32
VETTRAY
VET95
SWEEP95
PCCWIN98
IOMON98
AVPTC
AVE32
AVCONSOL
FP-WIN
DVP95
F-AGNT95
CLAW95
NVC95
SCAN
VIRUS
LOCKDOWN2000
Norton
Mcafee
Antivir
The worm is able to propagate over the network by copying itself to network shares (assuming sufficient permissions exist). Target filenames are chosen randomly, and can have single or double file extensions. For example:
350.bak.scr
bootlog.jpg
user.xls.exe

The worm may also copy itself into RAR archives, for example:
HREF.mpeg.rar
HREF.txt.rar
lmbtt.pas.rar

The worm mails itself to email addresses in the Windows Address Book, plus addresses extracted from files on the victim machine. It arrives in an email message whose subject and body is composed from a pool of strings carried within the virus (the virus can also add other strings obtained from the local machine). For example:

Subject: A very funny website
or Subject: Undeliverable mail--
or Subject: Returned mail--
or Subject: A WinXP patch
or Subject: A IE 6.0 patch
or Subject: W32.Elkern removal tools
or Subject: W32.Klez.E removal tools

The file attachment name is again generated randomly, and ends with a .exe, .scr, .pif, or .bat extension, for example:
ALIGN.pif
User.bat
line.bat

Thanks to the use of the exploit described above, simply opening or previewing the message in a vulnerable mail client can result in infection of the victim machine.

W32/Klez.h@MM masquerades as a free immunity tool in at least one of the messages used. Below is the message sent by the virus itself.

Subject: Worm Klez.E Immunity
Body: Klez.E is the most common world-wide spreading worm. It's very dangerous by corrupting your files. Because of its very smart stealth and anti-anti-virus technic,most common AV software can't detect or clean it.We developed this free immunity tool to defeat the malicious virus. You only need to run this tool once,and then Klez will never come into your PC.

NOTE: Because this tool acts as a fake Klez to fool the real worm,some AV monitor maybe cry when you run it. If so,Ignore the warning,and select 'continue'. If you have any question,please mail to me.

The worm may send a clean document in addition to an infected file. A document found on the hard disk, that contains one of the following extensions, is sent:

.txt
.htm
.html
.wab
.asp
.doc
.rtf
.xls
.jpg
.cpp
.c
.pas
.mpg
.mpeg
.bak
.mp3
.pdf
This payload can result in confidental information being sent to others.


Indications Of Infection:

Randomly/oddly named files on network shares, as described above.
Reference to a WINKxxx.EXE file ("xxx" looks random) in a Registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run

Method Of Infection:

This virus can be considered a blended threat. It mass-mails itself to email addresses found on the local system, exploits a Microsoft vulnerability, spreads via network shares, infects executables on the local system, and drops an additional file infecting virus, W32/Elkern.cav.c.


Removal Instructions:

Use current engine and DAT files for detection.
Once infected, VirusScan may not be able to run as the virus can terminate the process before any scanning/removal is accomplished. The following steps will circumvent this action and allow for proper VirusScan scanning/removal, by using the command-line scanner.

Ensure that you are using the minimum DAT specified or higher.
Close all running applications
Disconnect the system from the network
Go to a command prompt, then change to the VirusScan engine directory:
Win9x/ME - Click START | RUN, type command and hit ENTER.
Type cd \progra~1\common~1\networ~1\viruss~1\40~1.xx and hit ENTER
WinNT/2K/XP - Click START | RUN, type cmd and hit ENTER.
Type cd \progra~1\common~1\networ~1\viruss~1\4.0.xx and hit ENTER
Rename SCAN.EXE to CLEAN.EXE to prevent the virus from terminating the process and deleting files. Type, ren scan.exe clean.exe and hit ENTER
First, scan the system directory
Win9x/ME - Type clean.exe %windir%\system\win*.exe and hit ENTER
WinNT/2K/XP - Type clean.exe %windir%\system32\win*.exe and hit ENTER
Once the scan has completed, Type clean.exe /adl /clean and hit ENTER
Rename scan.exe. Type, ren clean.exe scan.exe and hit ENTER
After scanning and removal is complete, reboot the system
Apply Internet Explorer patch if necessary.

Klez can delete anti-virus software files. It may be necessary to reinstall VirusScan after cleaning a system.

Additional Windows ME/XP removal considerations


Aliases:

W32/Klez.G@mm (Norman), W32/Klez.gen@MM, W32/Klez.I (Panda), W32/Klez.K-mm, WORM_KLEZ.G (Trend)

This message has been edited by Black Tie 161 on 05-23-2003 at 09:18 AM

idive
Prowler Junkie

Posts: 8483
From: Texas USA
Registered: APR 2003

posted 05-23-2003 09:41 AM     Click Here to See the Profile for idive     
I have Norton and that also caught Klez on mine. I also have AVG antivirus that I picked up at work. It is free and can be updated online. If you need a copy of it I can email it to you. (Its a large file.) I know someone that had a virus and runs both Norton and AVG. Norton did not find it but AVG did. There is also a site online that you can go to to scan your system if you don't have an antivirus already. http://housecall.antivirus.com/
Was klenz32 a typo for klez32 or a different virus?

This message has been edited by idive on 05-23-2003 at 11:55 AM

SuperKat
Prowler Junkie

Posts: 2221
From: Atlanta, GA, USA
Registered: NOV 2001

posted 05-23-2003 11:53 AM     Click Here to See the Profile for SuperKat     
I think this virus has Ed figured out. I seem to get emails from him quite often. The last came while he was in Louisville. Actuall got about a half dozen in POA names. I have not seen one wiht a prowler in teh subject, scarry.
Gordon


Dale Beaman
Prowler Junkie

Posts: 2699
From: Lexington, KY, USA
Registered: AUG 2002

posted 05-23-2003 12:39 PM     Click Here to See the Profile for Dale Beaman     
McAfee works great.


ed monahan
Prowler Junkie

Posts: 33595
From: Cincinnati, OH
Registered: JUL 2000

posted 05-23-2003 08:52 PM     Click Here to See the Profile for ed monahan     
Gordon, my computer was actually turned off while I was gone. I usually never turn it off since I am on cable.


SuperKat
Prowler Junkie

Posts: 2221
From: Atlanta, GA, USA
Registered: NOV 2001

posted 05-23-2003 10:40 PM     Click Here to See the Profile for SuperKat     
Not to worry Ed, I never suspected you were actually behind this diabolical scheme. I know you have bigger plans. Hope they don't start coming in with prowler related subjects instead of the junk names. Have a good weekend.


Bcoffman Gray Ghost
Prowler Junkie

Posts: 2418
From: Marshall,Mo.65340
Registered: DEC 2002

posted 05-24-2003 11:13 AM     Click Here to See the Profile for Bcoffman Gray Ghost     
One question about the virus getting in my e-mail address book. I have Norton anti-virus 2002. I keep it up-dated every 2-3 days. I use Hot-mail exclusively. It uses McAfee virus scan on all attachments. Now my question. Would the KLEZ virus be able to get in my Hot-Mail address book. The address book isn't on my computer, (I think). It is on Hot-mail's server, isn't it?


YellowFever
unregistered

Posts: 2418
From: Marshall,Mo.65340
Registered: DEC 2002

posted 05-26-2003 05:51 PM           
quote:
Originally posted by Bcoffman Gray Ghost:
One question about the virus getting in my e-mail address book. I have Norton anti-virus 2002. I keep it up-dated every 2-3 days. I use Hot-mail exclusively. It uses McAfee virus scan on all attachments. Now my question. Would the KLEZ virus be able to get in my Hot-Mail address book. The address book isn't on my computer, (I think). It is on Hot-mail's server, isn't it?

It depends.

Hotmail has been around for quite a while but, Microsoft was using Outlook and you had to be a Microsoft customer to use Outlook. Problem was, you couldn't use or access it from anywhere other then the pc you installed it on and had your address book on.

Then Microsoft bought Hotmail and started migrating individual pc (is. MSN) accounts to it.

The good news is that if you cancel your MSN account and go with Roadrunner cable, you still have your hotmail (msn) account (ie. trey@msn.com vs. trey@hotmail.com ). You also have the restrictions (sizewise) of a free account versus a monthly paid one but, the point being, you still have the same email address for friends and such to send you emails.

Sorry for the history lesson but, the point is, that if you started out with an Outlook account and now have their hotmail account (msn account) you still have an address book locally.

We not only use McAfee anti-virus software on all our servers at home but, also use their firewall software too. I would highly recommend a firewall software in addition to any anti-virus software.

Bcoffman Gray Ghost
Prowler Junkie

Posts: 2418
From: Marshall,Mo.65340
Registered: DEC 2002

posted 05-26-2003 08:46 PM     Click Here to See the Profile for Bcoffman Gray Ghost     
Guess I'll be OK then. Never used Outlook. Started with Lycos e-mail and when it went out of business, I went straight to Hotmail. So that makes it sound like my address book is at Hotmail server. Rather than being on my computer. Thanks for the input.


FL Blue Kat
Prowler Junkie

Posts: 471
From: Zellwood, FL
Registered: JAN 2003

posted 05-27-2003 05:53 AM     Click Here to See the Profile for FL Blue Kat     
If you are going to install a fire-wall then look at Zone Alarm. It works great and is totally FREE for private home use.



This topic is 2 pages long:   1  2 

All times are CT (US)

This is an ARCHIVED topic. You may not reply to it!
Hop to:

Contact Us | Prowler Online Homepage

All material contained herein, Copyright 2000 - 2012 ProwlerOnline.com
E-Innovations, LP

POA Terms of Service

Powered by Infopop www.infopop.com © 2000
Ultimate Bulletin Board 5.45c