Fink, Thanks for your reply. I feel better now, as I was not sure if it had done any damage or not, but Norton VS quarantined it before I even looked at the message so I believe that you are correct.
Marvin
Printable View
Fink, Thanks for your reply. I feel better now, as I was not sure if it had done any damage or not, but Norton VS quarantined it before I even looked at the message so I believe that you are correct.
Marvin
I agree with IMM...looks like Klez. Download the FixKlez tool from the link he left and I'll bet it finds it and removes it.
papac
Sorry it took me this long to reply, been working some long hours the past few days.
I got the removeal program and ran it. It says I am clean. Boy what a relief. I did however get another email from postmaster again today :
Received: from prserv.net ([32.97.166.34]) by albs2kmail.webdomain.com with Microsoft SMTPSVC(5.0.2195.4453);
Thu, 5 Sep 2002 09:34:16 -0500
Date: Thu, 5 Sep 2002 14:32:35 +0000 (GMT)
X-Comment: Sending client does not conform to RFC822 minimum requirements
X-Comment: Date has been added by Maillennium.
Received: from Obk (slip-12-64-216-103.mis.prserv.net[12.64.216.103])
by prserv.net (out4) with SMTP
id <20020905143208204010rcqee>; Thu, 5 Sep 2002 14:32:13 +0000
From: postmaster <[email protected]>
To: [email protected]
Subject: Returned mail--"additional details, see the"
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=Y314k0f5gk9K5U1g77As229di765ORt
Return-Path: [email protected]
Message-ID: <[email protected]>
X-OriginalArrivalTime: 05 Sep 2002 14:34:16.0412 (UTC) FILETIME=[4FE201C0:01C254E9]
I don't reconize the "albs2kmail.webdomain.com " at the beginning but as I sain the anaweb part is my friends server in Ill.
Also I found the msconfig but it won't let me cut and paste. Boy this is turning out to be a lot of trouble for everyone. sorry
:(
Hi.. well I'd say you're safe at this point.. all the scans and the fix tool all say that there's no klez on your PC so set up whatever kill filters you need to and hopefully you won't be bothered much any more. You should send a link to this thread to your friend who runs that domain so he can check out where the infection may be coming from.
As far as being a bother.. you aren't.. we like to help. :)
Hi sscsr1,
For sure don't ever feel like a bother. We've all been in jams here ;) We all help each other out.
Just a note on msconfig. If you want to share what's listed at Startup in msconfig, you won't be able to use cut and paste, as you mentioned earlier. If you want to save the trouble of writing it all down and typing it here, you can do a screenshot, upload it to the web and other members can view it that way.
If you want to do that now, or for future reference, here's how I do it. Others may have a more simplified method:
- Get to the screen you want (in this case Startup in msconfig).
- Press Alt + PrintScrn. That will put the screenshot into your clipboard.
- Then open a program such as MS Paint and choose Edit>Paste.
- You should then see your screenshot.
- If the screenshot image is really large, you can reduce it in Paint by going to Image>Attributes and reduce it there (for more on resizing go to Paint's Help>Index and type in 'resizing'
- Next do File>Save As, name it and save it in .bmp or .gif format. Save to an easy to get to location on your Hard Drive.
- Sometimes the info is too large to capture in one screen shot, so you might have to break it up into multiple screenshots by scrolling down and repeating the above steps in increments, until all the info has been captured
You can do one of two things next: either upload the screenshot to the web, and insert the link in your post -or- insert it as an image. My personal preference is inserting the link. Inserting the image takes more time for the page to load (for those of us still on 56k ;) )
To upload to the web: if you already have a site that lets you store photos free, you can use that. If not, check out one like Boomspeed.You can also use the IMG command (in vB Code section above Your Reply where you type your post). That will insert the screenshot into your post.
- If using Boomspeed, once you create your account and login, you'll see My Files and Upload section.
- Under Upload section select Browse and navigate to where you stored your screenshot on your hard drive. That will put the path of the screenshot into the Upload box.
- Next select Upload. You will then see your screenshot listed at the top section under My Files.
- Click on it and it will take you to the URL of your screenshot.
- Then simply Copy and Paste the URL into your post, and members here will be able to click on the link and view your screenshot.
Hope that helps. -Kat
Thanks for the replys and the kind words everyone. I think since I am not infected that I will leave well enough alone and just filter these emails out and be done with them. As for posting my MSCONFIG, thanks for all the info kat. I will save it and probably create an account at boomspeed. I checked it out and it looked pretty easy. But I will probably start a new thread in a more aproprit (sp?) forum since it would be mostly to ask advice on what is junk and what is not. I really shouldn't do that here. But thanks for the detailed info on how to do it.