This is topic Has anyone received this virus? in forum Film-Yak at Film-Tech Forum ARCHIVE.


To visit this topic, use this URL:
https://ft-forum.com/ft/cgi-bin/ubb/ultimatebb.cgi?ubb=get_topic;f=8;t=000875

Posted by Michael Barry (Member # 237) on 04-30-2002, 08:31 PM:
 
Last night, I received a virus via email attachment. This has never happened to me before, so it's a bit of a novelty!

Fortunately, Norton Antivirus caught it so no harm was done.

It was the W32.Klez.gen@mm virus. It came attached to a file called border.pif

Has anyone else received this? Does anyone know what it does?
 


Posted by Mark Lensenmayer (Member # 134) on 04-30-2002, 09:00 PM:
 
Here is just about everything you would want to know about this virus:
http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.e@mm.html


 


Posted by Jerry Chase (Member # 660) on 04-30-2002, 09:03 PM:
 
Yeah, I got a border.pif in some junk from ? China? Korea? somewhere over there. Agent doesn't open attachments, and I know the routine, so I just deleted it. As for what it does, most viruses make properly running computers run poorly. That means Windows computers should run better.


 


Posted by Scott Norwood (Member # 30) on 04-30-2002, 09:39 PM:
 
Yeah, this one is cute. It sets the From: header to look like someone randomly chosen from the infected computer user's address book (so it looks like it came from someone other than the person who actually propagated the worm) and contains both an executable attachment and a random file from the sender's computer.

It's only really an issue for Windows users who use unpatched versions of the MS Outlook mailer. Users of other mailers and/or platforms should be unaffected.
 


Posted by Paul G. Thompson (Member # 655) on 04-30-2002, 10:40 PM:
 
It seems like Outlook Express is compromised faster than Microsoft can fix it.

Every virus our computers at the radio station I work at came through Outlook Express.

I wish Microsoft would just dump that program and write one that works.


 


Posted by Leo Enticknap (Member # 534) on 05-02-2002, 07:12 AM:
 
I think the reason that Outlook and OE are compromised so often is that, because Outlook is given away with Office and OE is given away with Windows, these are programs that the virus writers specifically target because they've got the highest user base. When anyone asks me for advice on virus prevention, one of my first suggestions is to ditch OE and use another client instead - Eudora, for example, has a 'disallow HTML exectuable content in messages' feature. So with HTML-encoded emails it'll still display graphics, formatting and stuff but will not execute any commands.

As for Klez, I had one every day for about a week from my local art cinema - its email listings computer got infected, and I gather that the network awareness of this virus (I believe the term 'blended threat' is not being used to describe a combination of a worm, virus and network-aware dropper) caused havoc throughout the building. As soon as they'd cleared it off one machine it was reinfected from another on the LAN.

It won't do anything to your computer if you don't run the attachment and either (i) are not on a local network, or (ii) you have a firewall installed and set up correctly.
 






Powered by Infopop Corporation
UBB.classicTM 6.3.1.2