1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

help stopping ???klez??? PLEASE

Discussion in 'Security and Privacy' started by tanya, 2003/02/18.

Thread Status:
Not open for further replies.
  1. 2003/02/18
    tanya

    tanya Inactive Thread Starter

    Joined:
    2002/07/28
    Messages:
    264
    Likes Received:
    0
    hi
    i have had this problem before however when i found the originating domain and sent A message to spamCop's suggested address they stopped
    HOWEVER not this time
    (i use nn 4.77 and save > 50 kb messages on the server so these are not being dLoaded...)
    (it is klezE as one of the message subjects were its removal tools -- lol)
    have submitted the fullHeader info MANY times now to spamCop sent F.O.U.R. requests to their suggested address, had them report it and the only response is an increase (5 per day)
    1. is it ok to post the full header info (only) in this forum b/c i have a question re: ip addresses not correlating (i.e. the lowerMost received lines very first ip address is NOT the domain suggested by spam cop also trace, xwhoIs, Lookup have another domain...)
    2. also is there anything else i should be doing (or can do)?
    3. should i be posting this in the nn forum?
    thank you
     
  2. 2003/02/19
    aleekat

    aleekat Inactive

    Joined:
    2002/01/07
    Messages:
    902
    Likes Received:
    0
    First "received ", your provider.

    In the full header, look at the second "received line ". Look at the IP address within the quotes. That is the offender.

    SamSpade

    GeekTools
     

  3. to hide this advert.

  4. 2003/02/19
    BillyBob Lifetime Subscription

    BillyBob Inactive

    Joined:
    2002/01/07
    Messages:
    6,048
    Likes Received:
    0
    Is it possible that this is where the repeats are coming from ?

    Also I would like to suggest a Program called MailWasher.

    With it you can EXAMINE ONLY e-mail right on the server.

    If anything looks undesireable you can then delete it right off of the server.

    It will also notify you if it does contain possible Virus.

    I would also check with your Friends etc. that have your e-mail address and make sure they have good AV protection.

    Also have then run a reliable on-Line AV check.

    Have them also check to make sure their AV software has not been disable. I believe that the mentioned Virus is one that will do that. And then use that machine and Random address from the Address book to FORWARD the NASTY Virus. And all of this without the owners knowledge.

    BillyBob
     
  5. 2003/02/19
    tanya

    tanya Inactive Thread Starter

    Joined:
    2002/07/28
    Messages:
    264
    Likes Received:
    0
    hello aleekat and BillyBob,
    thank you for replying!
    (sorry cannot see a way to reply to seperate msgs...)
    so...
    aleekat,
    there are no quotes AT ALL in the full header data...
    just for the lowerMost received states from <letters> ([ipAddress]) by anotherDomain...
    Thank you so much for the links! they look excellent!
    **************************************************
    BilyBob,
    By repeats you mean that the same msg is being sent like occasionally spam will do?
    the msgs are different; the forged senders are different; the subjects are different and i deleted all mail from the server yesterday but still getting them today...

    i appreciate your suggestions re: mailWasher; contacts etc... and thank you!

    a major reason i am trying to notify the originating domain is to warn whoever's computer is sending these...

    again, aleekat and BillyBob, i really appreciate your answering; suggestions; links and advice
    sincerely
    Tanya
     
  6. 2003/02/19
    markp62

    markp62 Geek Member Alumni

    Joined:
    2002/05/01
    Messages:
    4,012
    Likes Received:
    16
    tanya
    Your heart is in the right place, but I wouldn't bother trying to warn whoever for this reason. One of klez's email messages is telling someone that they have a virus and here is a tool to fix it. The "tool" to fix it is the virus. See what I mean?
    Another thing is that klez has it's own email program built in, it scans the address book for addresses, puts a fake address as the sender, puts in a stolen address and away the email goes. The only legit thing about it is the sending IP. So, you would have to convince the ISP about what you are doing.
     
  7. 2003/02/20
    tanya

    tanya Inactive Thread Starter

    Joined:
    2002/07/28
    Messages:
    264
    Likes Received:
    0
    hello markp62,
    many thanks for the reply!
    i also got that(helpful / thoughtFul:) message telling me how dangerous klez is with its attached removal tools lol...
    at this moment i have not received any of the daily 5 or so messages so far...
    the last thing i did was write to the ip number at the very start of the bottomMost received abuse@ipNumber
    perhaps this had an effect -- likely not:)
    i appreciate your reply and thank you again!
    sincerely
    Tanya
     
Thread Status:
Not open for further replies.

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.