Worm-KLEZ-H Virus running rampent!!!

Tripleshot

Elite Member
Jan 29, 2000
7,218
1
0
I have a PC on my bench that was infected. I did not want to do what most shops recommend----Fdisk/format c: Thats an easy cop out for lazy techies. This insideous virus disables your antivirus software, changes file names, changes extensions, replicates over and over again on your hard drive in hidden files and changes the name on each one of them, the code has in it a dial a porn number that auto dials a 900 number if you have a dial up service, and it attaches to every address in your email address book, outlook, hotmail, whatever. This one is a pistol,folks.

If you have it, or know of someone who has it, isolate it from any and all service and do what you can to begin the cleanup. Leo LaPorte on Screensavers tonight gave a clue as to how to get rid of it, but he did not--I repeat--DID NOT give you all the info you need. And neither will Symantec, my favorite antivirus program. You need to boot to dos and with a dos editor,search for the files that have replicated (hint--in my system on the bench, two files where identified by their duplicate size, repeated more than 46 times) and make that the final thing you do before turning it loose on the public again. follow all the instructions on the Symantec site and use the removal tool, but the problem is, the removal tool will not find all the replicated files because it changes name and extension, but not its size. That is the dead give away.

I do not know where to place this info, but I know OT gets alot of page hits. you all need to be aware and have a reputable, experienced tech remove this from an infected system. If you have what it takes and can do registry edits and use DOS editor tools, then tackle it yourself. If not, find a good shop. But you do not need to loose all your data from some schlock shop too lazy to remove the virus. Many shops just say Fdisk and format. To them -----Eat Sh!t and die--- you are helping the bastard that wrote this virus succeed.

I hope this creep gets busted for life in prison with his pants around his ankles. This is a most malecious virus.

Good luck.:)
 

MacBaine

Banned
Aug 23, 2001
9,999
0
0
There is another (easier?) way to do it. First, boot in safe mode, then open regedit. I am not exactly sure what subfolder it is in, but AVG Anti-virus has a section somewhere on how to do it. Basically you go and delete the Registry key that the virus loads when the system boots. This will allow you to install an anti-virus and run it without the virus deleting it. Good luck!
 

isasir

Diamond Member
Aug 8, 2000
8,609
0
0
NAV has caught 3 e-mails with this virus on my PC, and about 5 e-mails on my sister's PC. I haven't read up much on this, but I'm assuming Norton detecting this file means I'm pretty secure from it? I think it's actually an older virus.
 

vi edit

Elite Member
Super Moderator
Oct 28, 1999
62,484
8,345
126
The virus plugin on my exchange server has been going apesh!t for about 4 days now.
 

Smaulz

Senior member
Jun 20, 2001
938
0
0
yeah, same here... I get one every couple of days or so... NAV keeps catchin' 'em though... :)
 

Hossenfeffer

Diamond Member
Jul 16, 2000
7,462
1
0
Originally posted by: RishiS
NAV has caught 3 e-mails with this virus on my PC, and about 5 e-mails on my sister's PC. I haven't read up much on this, but I'm assuming Norton detecting this file means I'm pretty secure from it? I think it's actually an older virus.
Yes, you're much more secure than by not running AV software. Make sure your def's are updated and practice safe e-mailin'. If you use outlook/outlook express, disable the preview pane.

Also, if using outlook/oe, right-click on the message and click properties to get the address where the thing came from. That way you can get in touch with the infected soul and help em get things squared away.
 

datalink7

Lifer
Jan 23, 2001
16,765
6
81
I think a friend of mine just got this. Some files keep growing larger and larger in size, and his anti virus software stopped working. We decided to reformatt.
 

Tripleshot

Elite Member
Jan 29, 2000
7,218
1
0
datalink7

Sounds like you got it. Yes, I believe a format c: will work to remobe it,along with everything else you had. Sometimes that is unacceptable. But if it is OK with you,then Its OK by me. Except the Virus and the Puke that wrote it got what they wanted. That is demented.

Unfortunately, many people, even with AV running, do not have dat files updated in time, and the consequence is desaster. If your AV suddenly stops working, you have the virus. Try Housecall.com to get past that temporarily. it will also get attacked after you run it,making it useless,but it will identify,and quaerentinne some of the files,but you must edit the registry and unhide all files and boot to dos and search for what I said in the first paragraph. This is a bad bad virus folks. I can't over emphasize that enough. I'm happy others here are also helping to advise you. Yes turn off that review window in your email browser,but I do not think that will eliminate it. I do think that if AV is on and running should the Vrus come knocking,it should catch it and kill it. Do not attempt to look at it in GUI. It will begin replication and do its stuff in GUI. In DOS with a DOS editor,I have sen the code. It is BAD! I have re checked this computer many times since I finally got rid of it. It took 3 days to track it down. I think its gone now,and I did lose some data,but I also saved most of it. The virus has not re appeared, so that's all I can offer.

Good Luck. This one is worse than Mellisa and SirCam in my book.:|
 

Hossenfeffer

Diamond Member
Jul 16, 2000
7,462
1
0
Recently did a system repair for a theatre here in town. They had nimda, sircam, and a variant of the Klez worm. That was fun stuff. They offered me two tickets to a show in return for being their savior. Didn't have the heart to tell em I just saved their ass (and the last 6 years of records that they've kept solely on the computer, no hard copies....) and that I want some cash. ;)
 

PsychoAndy

Lifer
Dec 31, 2000
10,735
0
0
over the course of the month, norton quarrantined about 20 cc's or variants of this sucker. i can spot them the second they hit the inbox. weird thing is the subject keeps changing and the flie(s) and filesize stay the same

in OE, whenever i highlight it, Norton kicks in automatically and quarrantines it.
 

Flashram

Diamond Member
Apr 11, 2000
3,968
0
76
The school where my mom works was hit with this virus today. They had to shut down the whole network. Thanks for the tips on getting rid of it. I'll be sure to pass them on to her.
 

BillGates

Diamond Member
Nov 30, 2001
7,388
2
81
I've been hearing a lot of calls lately for that virus - tech support - it hasn't really improved over the past 3-4 weeks, people still use their computers normally, totally oblivious... It's funny when they call up with $2000 PCs that have been reduced to junk - as to why the call their ISP tech support, your guess is as good as mine...

Serves people right for being so clueless - they need to spend less time reading about NASCAR and anal fisting and start reading up on how to protect themselves online....
 

MaxDSP

Lifer
May 15, 2001
10,056
0
71
So is it unanimous(sp?) that Norton is the way to go for AV, or is there something better? I just reformatted and dont have any AV programs installed yet.
 

SinnerWolf

Senior member
Dec 30, 2000
782
0
0
Ive used Symantec's Klez removal tool on several PC's at work. Works like a charm. Might want to reinstall some appz after the removal just to make sure the registry isn't too corrupted, but if you're lazy, you really do not need to reformat/reinstall

Klez Removal Tool From Symantec
 

dakata24

Diamond Member
Aug 7, 2000
6,366
0
76
thanks for the info tripleshot..

finally disabled previewpane.. still getting used to having to double click to see the messages.. but better safe than sorry.. and i find that most of my email is spam anyways. so i hit delete before even viewing..

i dont know if it's a good idea, or whether it helps, but i personally have 2 av programs running, AVG and NAV. both using their resident shield thingy.. i figure it couldnt hurt.. and i dont notice any performance degradation running both at the same time..
 

Lithium381

Lifer
May 12, 2001
12,452
2
0
Scary stuff, my brothers computer is going crazy too, lagging like crazy, he says files pop in and out of his system too....not sure if he's got this or something else, i need to find my install disk for norton....sheesh, and i'm on a network with him! scary scary
 

heat23

Elite Member
Oct 9, 1999
3,998
9
81
www.heatware.com
I am having trouble removing the KLEZ virus...
I did REGEDIT but did not find the keys that the symantec site says the virus puts. Also I didnt find any wink*.exe files on the hard drive......
But everytime I run the removal tool, it finds at least thousand new infections (even without rebootnig the computer)...i cant even run the housecall virus scanner..anyone have any suggestions

haet