October 7, 2002



Mini-dossier: Klez email-based virus - How to remove

 

Klez Virus - General Information, Symptoms and Treatment

W32/Klez.I is a worm designed to propagate via e-mail by sending itself out to all the contacts found in the Address Book. The worm reaches systems as an e-mail attachment with a variable name and extension. This worm has been programmed to end certain processes as well as to delete certain files.

When W32/Klez.I is activated, it creates a file in the Windows/System folder, which turns out to be a copy of the worm. In addition, it creates another file in the Program Files folder. This file turns out to be a virus -detected as W32/Elkern.C- which infects files found in all drives available on infected systems; from A: to Z:. Moreover, the worm can disable some antivirus programs.

The Symantec site says reports the following symptoms description of the W32.Klez.E@mm virus, for example:

"Linda Anderson is using a computer that is infected with W32.Klez.E@mm Linda is not using an antivirus program or does not have current virus definitions. When W32.Klez.E@mm performs its emailing routine, it finds the email address of Harold Logan. It inserts Harold's email address into the "From:" line of an infected email that it then sends to Janet Bishop. Janet then contacts Harold and complains that he sent her infected email, but when Harold scans his computer, Norton AntiVirus does not find anything--as would be expected--because his computer is not infected."

More info at:
http://securityresponse.symantec.com/ avcenter/venc/data/w32.klez.e@mm.html

Aliases: W32/Klez.G@mm, W32/Klez.gen@MM, W32/Klez.K-mm, WORM_KLEZ.G, W32/Klez.H

W32/Klez.I is a mass-mailing worm written in Visual C++ which sends itself out to all of the contacts in the Windows Address Book (WAB). The messages sent can have variable characteristics.

The worm has been programmed to end certain processes on affected computers, as well as to delete files. Some of the files that this worm deletes may correspond to antivirus products.

This worm takes advantage of a Microsoft Internet Explorer vulnerability, already exploited by other worms, which could allow attached files to be run automatically simply by opening the corresponding message or viewing it through Outlook's preview pane.

For further information about this vulnerability and the corresponding patch visit the following Microsoft web page:

http://www.microsoft.com/technet/ security/bulletin/MS01-020.ASP

.........................................
How to Diagnose a Klez Virus Infection

You can find out if your computer is infected by taking the following steps:

Use Pandasoftware free on-line scanning tool, ActiveScan at:
http://www.pandasoftware.com
Click on the right column animated box that says:
"FREE virus check online - Panda Activescan".

For further detailed info about the Klez virus, symptoms, damages, and ways to verify its presence and to eradicate it, please refer to:

http://service.pandasoftware.es/servlet/ panda.pandaInternet.EntradaDatosInternet? operacion=EV2FichaVirus&idVirusFicha= 2646&pestanaFicha=1&idioma=2

.........................................
How to Remove and Disinfect Your Computer From the Klez Virus

Computers not connected to a network, as well as computers connected to small networks (workstations and servers)

If you have received this worm by e-mail and the antivirus detected it, please delete the message you received from the Inbox and the Deleted Items folders.

Follow the steps below to disinfect W32/Klez.I automatically.

Access this URL which is normally protected by a registration form. I am giving the direct link so that you do not have to give in your name/email to access this info:
http://www.pandasecurity.com/utilities/klez-i.htm

Dowload the PQREMOVE.COM file and save it to a directory of your choice.

Click on the file you just downloaded to run the application.
Then, follow the instructions provided. After scanning the system with PQREMOVE, your computer will be disinfected. If you have a computer network, disconnect the network cable from the workstations and servers that comprise it. In this way, you will prevent reinfection of any of these elements during the disinfection process.


NOTE: If PQRemove should not find this virus on your computer, it might be inactive or it just might not exist. If there should be any .VIR files on your computer just delete them.

Also check:
http://www.pandasoftware.es/library/ W32KlezI_en.htm

and
http://www.f-secure.com/v-descs/klez_e.shtml

.........................................
How to Remove the Klez Virus from Microsoft Windows Me systems

On Windows Millennium systems there may be the case that, after eliminating a virus, the antivirus keeps detecting it in the folder _restore over and over again, without deleting it. This situation, caused by a special feature in Windows Millennium, does not pose any dangers. However, it may rise alarm among users not used to working with the _restore folder.

Follow the steps below to remove the virus and solve this problem:

Click on Start.
Go to Configuration.
Click on Control Panel.
Double-click on System.
Click on the Performance tab.
Click on File Systems.
Click on the Troubleshooting tab.
Check the Disable System Restore checkbox.
Click on Apply.
Uncheck the Disable System Restore checkbox.
Click on Apply
Click on Accept.

You will be asked if you wish to restart the computer. Once you restart it, the virus will have been eliminated for good.

Conversation Tags:
Readers' Comments    
Recent Articles


July 2, 2008
The Future And What It Holds: Howard Rheingold Video Interview - Frontiers Of Interaction IV


I shot the video interview that follows for the Frontiers of Interaction conference which took place yesterday in Turin, Italy. Superbly organized by Leandro Agrò and Matteo Penzo, the sold out event brought together high prestige names like sci-fi writer and visionary Bruce Sterling, Elizabeth Churchill... read more




May 24, 2008
Spam Checking Tools And Tips To Avoid Your Newsletter Being Filtered, Blacklisted Or Marked As Spam


Sending out newsletters and having them delivered reliably to your list of subscribers has become a greater challenge than I would have ever thought. Problem is, if you don't devote yourself to it, everything is set for your newsletter to run into trouble. To not run... read more




May 18, 2008
Making Sense Of New Technologies And Media: An Opinionated Digest by George Siemens - May. 18 08


"Media literacy" is increasingly the keyword to which I attribute the greatest importance when it comes to become effective trainers, online communicators as well as effective and successful entrepreneurs of yourselves. Understanding, to the very root, what communication means, how we do it, what reality and... read more




February 19, 2008
Edit And Remove Text Chat Messages In Skype
Did you know that in a live Skype text chat session you can actually remove or even edit messages you have ALREADY SENT to some of your contacts? Don't believe me? Check out how to do it in this short two minute video. Isn't it great? How... read more




January 18, 2008
Virtual Teams: Best Practices When Communicating Electronically


When communicating inside a virtual distributed team, things are not as clear and evident as when you operate in traditional physical environments. Virtual teams are somewhat more sensitive to bad or improper use of communication tools and methods as such teams pivot their key abilities specifically... read more




December 3, 2007
Lifestreaming - Aggregate And Author All Your Social Media Content From One Place: Lifestrea.ms


If you want to aggregate and author all of your social media content from a single service, Lifestrea.ms may very well interest you. Lifestrea.ms offers you a single solution for gathering all of your various online identities and publishing destinations into a single social media space. Given... read more




posted by Robin Good on Monday, October 7 2002, updated on Saturday, January 21 2006


 

 

 

 

Understanding comes from exploration

Home | Subscribe | RSS Feeds | Site map | Syndicate
Consulting | Publications
About | Privacy | Contact

 

Creative Commons License
This work is licensed under a Creative Commons License.





View blog authority

 

617