[meteorite-list] WARNING VIRUS ALERT - more info
From: John Gwilliam <jkg_at_meteoritecentral.com>
Date: Thu Apr 22 10:04:49 2004 Message-ID: <4.2.0.58.20020515083402.009b8810_at_mail.theriver.com> --=====================_2655794==_ Content-Type: multipart/related; type="multipart/alternative"; boundary="=====================_2655795==_.REL" --=====================_2655795==_.REL Content-Type: multipart/alternative; boundary="=====================_2655807==_.ALT" --=====================_2655807==_.ALT Content-Type: text/plain; charset="us-ascii"; format=flowed Morning Jim and list, I know it is list policy to not send info about viruses, but this is a very sneaky virus that you need to be warned about. I received four different copies of it with different subject titles. Norton anti-virus (updated 5/6/02) didn't detect one of them. The attachment was named <<<<warn.txt>>>>. I even scanned it in Windows explorer and Norton said it was clean. Later in the day, I received a 4th copy of it that Norton did catch on the way in. Following are the four different subject lines in came under: Worm Klez.E immunity Rights Reserved A very new game Tickets It has the ability to put whatever address it wants in the "From" line while the original infected email address is listed as "Sender". I use Eudora Pro. Don't open or preview ANY attachments and update your anti-virus program every few days for a while. Best, John Gwilliam At 02:19 AM 5/15/04 -0700, you wrote: >Hello All, > > After becoming infected 2 days ago from a list member & losing 6 > months of e-mails & other assorted data now I have received the same > virus from the following address > <mailto:meteorite-list_at_meteoritecentral.com>mailto:meteorite-list@meteorit > ecentral.com > >Below is the name of the virus & the name of the file. The strange thing >is that I received it from the list address on an e-mail address that has >never been used on the list. > >Jim >James Hartman > > >Date: 5/13/04, Time: 22:28:58, >Virus scanning completed. >Items scanned: C:-D: >Date: 5/14/04, Time: 8:12:54, >Virus scanning completed. >Items scanned: C:-D: >Date: 5/15/04, Time: 2:01:24, >The file >C:\WINDOWS\SYSTEM\Winkpj.exe >is infected with the W32.Klez.H_at_mm virus. >Unable to repair this file. >Date: 5/15/04, Time: 2:01:32, >The file >C:\WINDOWS\SYSTEM\Winkpj.exe >was infected with the W32.Klez.H_at_mm virus. >The file was quarantined. >____________________________________________________ ><http://www.incredimail.com/redir.asp?ad_id=309&lang=9>[meteorite-list] >WARNING VIRUS IncrediMail - Email has finally evolved - ><http://www.incredimail.com/redir.asp?ad_id=309&lang=9>Click Here --=====================_2655807==_.ALT Content-Type: text/html; charset="us-ascii" <html> Morning Jim and list,<br> I know it is list policy to not send info about viruses, but this is a very sneaky virus that you need to be warned about. I received four different copies of it with different subject titles. Norton anti-virus (updated 5/6/02) didn't detect one of them. The attachment was named <<<<warn.txt>>>>. I even scanned it in Windows explorer and Norton said it was clean. Later in the day, I received a 4th copy of it that Norton did catch on the way in.<br> <br> Following are the four different subject lines in came under:<br> <br> Worm Klez.E immunity<br> Rights Reserved<br> A very new game<br> Tickets<br> <br> It has the ability to put whatever address it wants in the "From" line while the original infected email address is listed as "Sender".<br> <br> I use Eudora Pro.<br> <br> Don't open or preview ANY attachments and update your anti-virus program every few days for a while.<br> <br> Best,<br> <br> John Gwilliam<br> <br> <br> At 02:19 AM 5/15/04 -0700, you wrote:<br> <blockquote type=cite cite>Hello All,<br> <br> After becoming infected 2 days ago from a list member & losing 6 months of e-mails & other assorted data now I have received the same virus from the following address <a href="mailto:meteorite-list_at_meteoritecentral.com">mailto:meteorite-list@meteoritecentral.com </a><br> <br> Below is the name of the virus & the name of the file. The strange thing is that I received it from the list address on an e-mail address that has never been used on the list.<br> <br> Jim<br> James Hartman<br> <br> <br> Date: 5/13/04, Time: 22:28:58, <br> Virus scanning completed.<br> Items scanned: C:-D: <br> Date: 5/14/04, Time: 8:12:54, <br> Virus scanning completed.<br> Items scanned: C:-D: <br> Date: 5/15/04, Time: 2:01:24, <br> The file<br> C:\WINDOWS\SYSTEM\Winkpj.exe<br> is infected with the W32.Klez.H_at_mm virus.<br> Unable to repair this file.<br> Date: 5/15/04, Time: 2:01:32, <br> The file<br> C:\WINDOWS\SYSTEM\Winkpj.exe<br> was infected with the W32.Klez.H_at_mm virus.<br> The file was quarantined.<br> <font size=2>____________________________________________________<br> </font><a href="http://www.incredimail.com/redir.asp?ad_id=309&lang=9"><img src="cid:.0" width=20 height=15 alt="[meteorite-list] WARNING VIRUS"></a><font face="Comic Sans MS" size=2> <i>IncrediMail</i> - <b>Email has finally evolved</b> - </font><a href="http://www.incredimail.com/redir.asp?ad_id=309&lang=9"><font face="Times New Roman, Times"><b><u>Click Here</a></font></b></u> </blockquote></html> --=====================_2655807==_.ALT-- --=====================_2655795==_.REL Content-Type: application/octet-stream; name="[meteorite-list] WARNING VIRUS " Content-ID: <.0> Content-Transfer-Encoding: base64 Content-Disposition: inline; filename="[meteorite-list] WARNING VIRUS " R0lGODlhFAAPALMIAP9gAM9gAM8vAM9gL/+QL5AvAGAvAP9gL////wAAAAAAAAAAAAAAAAAAAAAA AAAAACH/C05FVFNDQVBFMi4wAwEAAAAh+QQJFAAIACwAAAAAFAAPAAAEVRDJSaudJuudrxlEKI6B URlCUYyjKpgYAKSgOBSCDEuGDKgrAtC3Q/R+hkPJEDgYCjpKr5A8WK9OaPFZwHoPqm3366VKyeRt E30tVVRscMHDqV/u+AgAIfkEBWQACAAsAAAAABQADwAABBIQyUmrvTjrzbv/YCiOZGmeaAQAIfkE CRQACAAsAgABABAADQAABEoQIUOrpXIOwrsPxiQUheeRAgUA49YNhbCqK1kS9grQhXGAhsDBUJgZ AL2Dcqkk7ogFpvRAokSn0p4PO6UIuUsQggSmFjKXdAgRAQAh+QQFCgAIACwAAAAAFAAPAAAEEhDJ Sau9OOvNu/9gKI5kaZ5oBAAh+QQJFAAIACwCAAEAEAANAAAEShAhQ6ulcg7Cuw/GJBSF55ECBQDj 1g2FsKorWRL2CtCFcYCGwMFQmBkAvYNyqSTuiAWm9ECiRKfSng87pQi5SxCCBKYWMpd0CBEBACH5 BAVkAAgALAAAAAAUAA8AAAQSEMlJq7046827/2AojmRpnmgEADs= --=====================_2655795==_.REL-- --=====================_2655794==_ Content-Type: text/plain; charset="us-ascii"; format=flowed John Gwilliam Meteorites PO Box 26854 Tempe AZ 85285 http://www.meteoriteimpact.com --=====================_2655794==_-- Received on Wed 15 May 2002 11:46:41 AM PDT |
StumbleUpon del.icio.us Yahoo MyWeb |