IWETHEY v. 0.3.0 | TODO
1,095 registered users | 1 active user | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New I presume . .
. . you did your Klez.H check using a DOS based Klez tool after a fresh boot into Safe Mode. I've cleand Klez.H out of dozens of machines who's owners "Update my antivirus almost every day". By time Klez.H fixes were out, much of the world was infected, and updating your antivirus after the fact is futile - Klez.H nails it instantly - it looks like it's running, but it's just spinning of wheels.

I use the Command Software Klez cleaner (but others should work). I copy the compressed file to the hard disk and immediately reboot into Safe Mode, uncompress and run the cleaner immediately. To be quite frank, since May, I've found only one Windows computer that's used to read email that didn't have Klez.H / Elkern.C. MS Office users average about 84 infections, WordPerfect users 33. Top number 340, lowest 16.

The combo of Klez.H and Magistr is particularly annoying, as they protect each other (probably unplanned). I usually have to clean those from a DOS boot with an up-to-date DOS cleaner - and, presuming they haven't cleaned up their "Temporary Internet Files" for six months, it can take hours (no disk cache).

I have had a few cases where Klez.H was cleaned, and an up-to-date antivirus reinstalled after clean, but Klez.H reoccurred. Fortunately these are quite rare.

I'm not saying your problem is Klez.H, just cautioning that it's a tough one to pin down unless you use exactly the right procedure.

[link|http://www.aaxnet.com|AAx]
New Re: I presume . .
Somehow I've missed it. Why do I always miss the fun? :)
-drl
New What fun?
Nobody seems to get my jokes either, that is what I get for trying to be funny.

[link|http://games.speakeasy.net/data/files/khan.jpg|"Khan!!!" -Kirk]
New Actually you likely didn't miss it
The fun thing about Klez is that it leaves very few telltales for the person with it that they are the one sending out the mail.

Lots of people have it and don't notice. Which is one of the reasons why it hasn't been slacking off.

cheers,
Ben
"Career politicians are inherently untrustworthy; if it spends its life buzzing around the outhouse, it\ufffds probably a fly."
- [link|http://www.nationalinterest.org/issues/58/Mead.html|Walter Mead]
Expand Edited by ben_tilly Sept. 30, 2002, 07:56:48 AM EDT
New Re: Actually you likely didn't miss it
I run that Symantec safe-mode tool from time to time and have never had a report of it. I have no virus protection, because it is useless.
-drl
New Re: I presume . .
I used the Symantec tool, apparently it was the Windows version and ran a GUI interface window as it processed the files on the hard drive. If there is a DOS version of it, please kindly point me to it. Anything to get rid of whatever is causing this thing.

You know, you pay like $70USD for the Norton AntiVirus 2003 Pro software and you'd think that it would come with a DOS based scanner that can scan before the GUI of the OS loads. Why I remember way way back when that was the case. Perhaps I missed a configuration option?

BTW any Open Sourced Virus scanners that don't charge you money for a year's worth of AntiVirus data file updates? Nothing like getting soaked for virus protection and updates when the newer ones start getting out.

[link|http://games.speakeasy.net/data/files/khan.jpg|"Khan!!!" -Kirk]
New Stop using windows
It's the only way to be sure you're not going to get that stuff.

It's not like alternative systems don't have good software... they do, and there are several viable choices you can make.
--
-------------------------------------------------------------------
* Jack Troughton jake at consultron.ca *
* [link|http://consultron.ca |[link|http://consultron.ca|http://consultron.ca] ] irc.ecomstation.ca *
* Laval Qu\ufffdbec Canada [link|news://news.consultron.ca|news://news.consultron.ca] *
-------------------------------------------------------------------
New I know
but Windows is my bread and butter right now, it gets me a job. Linux, OS/2, DR-DOS, etc just don't seem to get me hired.

[link|http://games.speakeasy.net/data/files/khan.jpg|"Khan!!!" -Kirk]
New We use Command antivirus . .
. . $24/year download. Once installed on a machine, it can make a set of three floppies runable from DOS. I just copy them all to a directory on the Service CD-ROM I carry, and run it from there, or copy it to the subject hard disk and run it from there. Of course, you have to have a DOS 7 boot floppy.

Some machines get so badly virus infected you just can't install and/or run an antivirus under Windows.
[link|http://www.aaxnet.com|AAx]
     Sorry for the troubles - (orion) - (97)
         It's not about your whining... err... troubles - (folkert) - (3)
             Well I am confused - (orion) - (2)
                 Did you get your Uncle"s hair???? - (bepatient)
                 Please distinguish... - (folkert)
         Softly softly. - (static) - (5)
             Good advice - (Silverlock) - (4)
                 That's not quite what I meant, but that's okay. :-) -NT - (static) - (2)
                     I know what you meant - (Silverlock) - (1)
                         Troublemaker.. - (Ashton)
                 Muahahaha, great one! :-) - (CRConrad)
         I personally cannot believe it - (tseliot) - (2)
             IT with kids in the house - (jake123) - (1)
                 Now imagine.. - (Ashton)
         You are set up Norm! - (Snitcherooni) - (83)
             Take it elsewhere... - (ChrisR) - (65)
                 Re: Take it elsewhere... - (deSitter) - (64)
                     seconded -NT - (boxley)
                     Doesn't change my response - (bepatient)
                     Doesn't seem like NK's writing to me. - (Another Scott) - (61)
                         Not me, but it disturbs me greatly - (orion)
                         Not me, but it disturbs me greatly - (orion)
                         No, the actual telltale sign.. - (deSitter) - (58)
                             Interesting - (orion) - (57)
                                 Re: Interesting - (deSitter) - (48)
                                     What can I do then? - (orion) - (47)
                                         get a scrip for androgel - (boxley) - (2)
                                             May not be the problem - (orion) - (1)
                                                 Not quite right. - (Another Scott)
                                         Re: What can I do then? - (deSitter) - (43)
                                             Re: What can I do then? - (deSitter) - (42)
                                                 That would've been my suggestion. -NT - (bepatient)
                                                 Apologizing - (orion) - (40)
                                                     No - (deSitter) - (38)
                                                         Apology again - (orion) - (37)
                                                             no prob norm -NT - (boxley)
                                                             Of Course! - (deSitter) - (30)
                                                                 There is a fine line - (orion) - (29)
                                                                     Heh - I'm still looking for the pencil to draw it with... -NT - (imric)
                                                                     Bullshit - (deSitter) - (27)
                                                                         I dunno... - (imric) - (25)
                                                                             Very nice - (Ashton)
                                                                             Stupid request - (ben_tilly) - (23)
                                                                                 Sure... - (imric) - (5)
                                                                                     Re: Sure... - (deSitter) - (4)
                                                                                         Nice to be appreciated - thanks! -NT - (imric) - (3)
                                                                                             Re: Nice to be appreciated - thanks! - (deSitter)
                                                                                             Re: Nice to be appreciated - (deSitter) - (1)
                                                                                                 *blush* -NT - (imric)
                                                                                 Targets & tags -- annoying as hell - (kmself) - (16)
                                                                                     *shrug* Tell you what. Let's vote on it. - (imric) - (15)
                                                                                         What he's talking about - (drewk) - (3)
                                                                                             So - you don't mind targets? 'K.. - (imric) - (1)
                                                                                                 Sure, I see why - (drewk)
                                                                                             What he said - (ben_tilly)
                                                                                         FWIW, I've always disliked targeted links. - (admin) - (2)
                                                                                             Bribes... - (imric) - (1)
                                                                                                 Bah. - (admin)
                                                                                         If I see a link in Imric's post I know a new window will pop - (boxley)
                                                                                         Re: *shrug* Tell you what. Let's vote on it. - (deSitter) - (1)
                                                                                             your target did not link :-) -NT - (boxley)
                                                                                         Can see both sides. - (Another Scott)
                                                                                         How to open in new windows, block target-generated windows - (kmself) - (3)
                                                                                             *smile* OK, then, no problems anymore? Ben, anyone? - (imric) - (2)
                                                                                                 I can't use Karsten's solution - (ben_tilly) - (1)
                                                                                                     Hmmm. - (imric)
                                                                         absolutely true Im quite off brand myself - (boxley)
                                                             *smile* - (imric)
                                                             Sure thing, man. -NT - (bepatient)
                                                             Much better - (ben_tilly)
                                                             De nada. -NT - (Ashton)
                                                             Yes, and Thanks. -NT - (Steve Lowe)
                                                     A tip - (ben_tilly)
                                 What's really interesting... - (admin) - (7)
                                     That address responds to ping - (SpiceWare) - (5)
                                         Re: That address responds to ping - (deSitter) - (4)
                                             Some personal accountability would be nice. - (admin) - (2)
                                                 Any chance of a 3rd person in STL - (boxley) - (1)
                                                     ... - (admin)
                                             ? - (SpiceWare)
                                     Interesting enough - (orion)
             Fsck off bucko! -NT - (bepatient)
             Right. - (pwhysall) - (15)
                 What do I know - (orion) - (14)
                     time to adjust again, working again has changed - (boxley)
                     Forgive me if I don't see a problem... - (bepatient) - (11)
                         Apparently not Klez - (orion) - (10)
                             Klez spoofs sender - (kmself)
                             I presume . . - (Andrew Grygus) - (8)
                                 Re: I presume . . - (deSitter) - (3)
                                     What fun? - (orion)
                                     Actually you likely didn't miss it - (ben_tilly) - (1)
                                         Re: Actually you likely didn't miss it - (deSitter)
                                 Re: I presume . . - (orion) - (3)
                                     Stop using windows - (jake123) - (1)
                                         I know - (orion)
                                     We use Command antivirus . . - (Andrew Grygus)
                     Fair weather friends? - (a6l6e6x)

I made it through almost 20 minutes of this before coming out of my skin and destroying the TV with my mad shrieking.
120 ms