What's new

Email from Bobbi of NGEmu??

Allnatural

New member
Moderator
Now this is damn peculiar. I received this email supposedly from Bobbi at NGEmu:

Klez.E is the most common world-wide spreading worm.It's very dangerous by corrupting your files.
Because of its very smart stealth and anti-anti-virus technic,most common AV software can't detect or clean it.
We developed this free immunity tool to defeat the malicious virus.
You only need to run this tool once,and then Klez will never come into your PC.
NOTE: Because this tool acts as a fake Klez to fool the real worm,some AV monitor maybe cry when you run it.
If so,Ignore the warning,and select 'continue'.
If you have any question,please mail to me.
The "mail to me" is an email link to [email protected]

Now I know this is fake of some sort, and Bobbi certainly didn't send it to me. Attached to the email were two files, an html file which I only opened in notepad, and what appeared to be a screensaver called "width.scr." The text within the html file read this:
Temporarily unable to complete registration
Registration services are temporarily unavailable. To complete the registration process, wait a few minutes and click Redial. If you receive this error a second time, contact your computer manufacturer.
To continue without registering your computer, click Skip.
The .scr is some sort of dummy file. It has no size (0 bytes) and it reveals a blank page when opened in notepad.

I've been getting other weird emails like this one lately, and though they all appear to be from different people, I believe they're from the same source.

Anyone else get stuff like this lately? I don't think I've made any enemies recently.;) I've attached a text file with the header information of this email hoping someone can gleen something from it. I'll be honest it's all Greek to me.:innocent:
 

Trotterwatch

Active member
The odd part is the mailto link is actually a valid one, I can only assume this is another function of Klez (which again is extremely clever). The thing with Klez is that it can send out emails under someone elses name, so afaik it is impossible to track down who actually has the virus, and who doesn't.

The files it sends with it, are simply ones that the virus touches, these can be considered safe.

Before Klez I only ever received one Virus through email in the whole of the time I have used the net, and newsgroups... I've had the Klez email upwards of 20 times though!
 

Eagle

aka Alshain
Moderator
Yes, Klez is an annoyance, I had to delete an email account completely because I kept getting over 100 viruses a day from Jabo, Zilmar, Smiff, Martin, Redah, and others as well.
 

Top