Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Weird attachements lately

Status
Not open for further replies.

Dean2002

IS-IT--Management
Mar 10, 2002
10
0
0
CA
Good day all. I have been bombarded with phone calls about attchments received in emails. The emails are from mostly from people they don't know and they are batch files. Some of the emails are blank. While others with the BAT file, there is a JPG of a kid with pencils in his ears :) Other people must be having this same issue.

I currently run Mcafee w/sp4.5.0.534 with scan engine version 4.1.60 and dat 4203 and when I scan these files it reports that NO infections were found.

Can ANYONE please shed alittle light for me??

Thanks SOOOOO MUCH!!!
 
Send a copy to NAI's research labs (virus_research@nai.com) so they can verify the file.

AVChap
 
sounds like KLEZ to me js error; 67 on line; 36 of signature.class
 
let me clarify..

Klez, when it infects a system, looks into all text on the system for email addresses, this includes the address book.
It compiles this list and encodes it within itself and carries it with itself. It will then start sending mail out to the peoples email addresses. It will also LIE about the sender of the email taking another email address it finds and spoofing the sender info in the header. Also it will grab a file off the harddrive, sorta at random, usually jpg or html... and not infect the file, but also attach this file to the mail. this makes for some strange emails. Groupshield will detect and remove the klez, so your left with some old lady sipping a starbucs cappucino or something. either way the users will call you becuase they are going to wonder whats up...

Klez the HMMM!! virus..

FatesWebb

if you do what I suggested it is not my fault...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top