w2wlord
06-05-2002, 08:24 PM
Hi ive been getting spam emails
that are biger than 150 kb yet they dont have any attachements
and are competly blank.they come from various email addresees and have
diferent subjects (somettimes none)
can u tell me plz what is this all about does it have anykind of viruses
thanks
Paleo Pete
06-05-2002, 10:24 PM
I'd be willing to bet they carry the Klez virus, that sounds like a perfect description of emails I've gotten that carry it, as well as some that have been described bu other posters recently.
FIrst thing you need to do is make sure you have the Preview Pane turned off, some viruses can be installed by viewing in the Preview Pane. With Outlook Express click View then Layout. Look toward the bottom for a check box for Preview Pane. UNcheck that box.
Then when you get emails, right click on an email in the right hand pane, and click Properties, then the Details tab. On the Details sheet, close to the bottom look for a button that says Message Source.
Message Source lets you see a text vresion of the email, with no graphics, and without actually opening it. If it includes a file either attached or embedded it should be shown there also.
Since you have been receiving emails such as the ones you describe, I would very strongly advise you to make sure you keep the virus definitions updated for your antivirus and use it to run a full system scan any time you receive a questionable email of that type. If you have opened these messages, there is a good chance it has installed itself. If you try to run a scan and it won't work, it's time to worry...
Klez (http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html) Symantec page.
Klez (http://vil.mcafee.com/dispVirus.asp?virus_k=99455) McAffee page.
F-Secure page.
Read some or all of those pages and pay attention, several things about this virus make it well worth familiarizing yourself with it. It can pose as an antivirus tool, it can pose as a game, can send empty messages, uses random subject lines and filenames, and quite often sends itself using a bogus return address picked from the address book or ICQ database of the infected computer.
It has been spread widely in the past few weeks, due mostly to the difficulty in identifying it. Since it uses so many random characteristics, can fake its own return address, as well as use its own SMTP routine, this is not an easy one to keep up with. Get familiar with it and in the future chances are you may be able to recognize it before it can do any damage.
------------------
If your nose runs and your feet smell...
You're built upside down!
Note: Please post your questions on the forums, not in my email.
[url="http://www.dreamwater.com/paleopete/computer.htm"]Computer Information Links (http://www.europe.f-secure.com/v-descs/klez.shtml) has been moved, please update your bookmarks.
vBulletin v3.6.1, Copyright ©2000-2012, Jelsoft Enterprises Ltd.