TenTec
[Top] [All Lists]

[TenTec] Viruses and the Ten-Tec List

To: <tentec@contesting.com>
Subject: [TenTec] Viruses and the Ten-Tec List
From: n1eu@yahoo.com (N1EU)
Date: Thu, 23 May 2002 14:33:49 -0700 (PDT)
Someone on this list (not me) has an infected computer
and sent out the recent message aliased with my "from
address".  This is characteristic of the Klez virus
(see below).  Since my email is Web-based, not Windows
based, I am immune from the attack.  Also, I am set up
to not receive the list messages directly (I read the
archives on contesting.com), so I am twice protected.

Info on the Klez virus from the Symantec site: 
http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html

This worm searches the Windows address book, the ICQ
database, and local files for email addresses. The
worm sends an email message to these addresses with
itself as an attachment. The worm contains its own
SMTP engine and attempts to guess at available SMTP
servers. For example, if the worm encounters the
address user@abc123.com it will attempt to send email
via the server smtp.abc123.com.

The subject line, message bodies, and attachment file
names are random. The From address is randomly-chosen
from email addresses that the worm finds on the
infected computer.


73,
Barry N1EU


__________________________________________________
Do You Yahoo!?
LAUNCH - Your Yahoo! Music Experience
http://launch.yahoo.com

<Prev in Thread] Current Thread [Next in Thread>
  • [TenTec] Viruses and the Ten-Tec List, N1EU <=