W32.Klez.gen@mm help!

Discuss anything not covered in another forum (life, the universe etc.)... Please keep it PG-13 and avoid spam.
Post Reply
TBob
Regular Member
Posts: 112
Joined: Sat Nov 10, 2001 2:31 am

W32.Klez.gen@mm help!

Post by TBob »

Guys!

I need your help! I am infected with the W32.Klez.gen@mm virus. I know this because i keep getting messages back from different ISP's saying that _________ person could not be found. Those also come back with the attachment of a virus. Then i get some that say "You have sent __________ a virus, and was not delivered". I am running Norton Antivirus 2002. I went to there website and downloaded the fix, but when its running the fix performs an illegal operation on some files, and it closes. When i go to find them, they dont even exist! Can anyone find manual steps to remove the virus ?

Thanks
All the Best

TBob
User avatar
Faust
Posts: 8730
Joined: Sat Apr 22, 2000 4:34 am
Location: Huntington Beach, CA

Post by Faust »

User avatar
Hitman
Regular Member
Posts: 299
Joined: Sun May 20, 2001 12:00 am
Location: Canada

Post by Hitman »

Here
is the removal tool for this virus. I would suggest to restart computer once it finishes cleaning your hard drive and run it 1 more time.

Good Luck

PS some files might not be repairable and you might loose some data
TBob
Regular Member
Posts: 112
Joined: Sat Nov 10, 2001 2:31 am

Post by TBob »

hey you forgot to make your "click here" a link... thanks
All the Best

TBob
User avatar
Hitman
Regular Member
Posts: 299
Joined: Sun May 20, 2001 12:00 am
Location: Canada

Post by Hitman »

Originally posted by TBob
hey you forgot to make your "click here" a link... thanks
fixed it :)
TBob
Regular Member
Posts: 112
Joined: Sat Nov 10, 2001 2:31 am

Post by TBob »

Originally posted by -Hitman-
Here
is the removal tool for this virus. I would suggest to restart computer once it finishes cleaning your hard drive and run it 1 more time.

Good Luck

PS some files might not be repairable and you might loose some data
yah... i ran it again, and it performs an illegal operation. Im running XP, and dont you get those messages where it says "Send error report" / "Dont Send" ... i get that for the klezfix program! Its so annoying! I need to get this virus off my computer as i have a huge address book & it is sending to everyone!
All the Best

TBob
User avatar
Hitman
Regular Member
Posts: 299
Joined: Sun May 20, 2001 12:00 am
Location: Canada

Post by Hitman »

I hope this helps.




To remove this worm, delete files that are detected as W32.Klez.A@mm, and remove the value that it added to the registry.

To remove the worm:
1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
3. Run a full system scan.
4. Delete all files that are detected as W32.Klez.A@mm.

To edit the registry:

CAUTION: We strongly recommend that you back up the system registry before you make any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure that you modify only the keys that are specified. Please see the document How to back up the Windows registry before you proceed.

1. Click Start, and click Run. The Run dialog box appears.
2. Type regedit and then click OK. The Registry Editor opens.
3. Navigate to the following key:

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run

4. In the right pane, delete the following value:

krn132 %System%\krn132.exe

5. Click Registry, and click Exit.
TBob
Regular Member
Posts: 112
Joined: Sat Nov 10, 2001 2:31 am

Post by TBob »

Originally posted by -Hitman-
I hope this helps.




To remove this worm, delete files that are detected as W32.Klez.A@mm, and remove the value that it added to the registry.

To remove the worm:
1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
3. Run a full system scan.
4. Delete all files that are detected as W32.Klez.A@mm.

To edit the registry:

CAUTION: We strongly recommend that you back up the system registry before you make any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure that you modify only the keys that are specified. Please see the document How to back up the Windows registry before you proceed.

1. Click Start, and click Run. The Run dialog box appears.
2. Type regedit and then click OK. The Registry Editor opens.
3. Navigate to the following key:

HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run

4. In the right pane, delete the following value:

krn132 %System%\krn132.exe

5. Click Registry, and click Exit.
ok weird, i dont have a krn132.exe file on in my registry, but on the symantec website they say its wink[random characters].exe

weird...
All the Best

TBob
User avatar
AoDLiQuiD-M3tH
Posts: 2457
Joined: Wed Jul 12, 2000 12:00 am
Location: Connecticut

Post by AoDLiQuiD-M3tH »

is this why ive been getting so many mail undeliverable msgs ? but they dont show that the came from me. hmm ill have to run that tool when i get home.
-[AoD]-LiQuiD>M3tH-[SA]-
-[AoD]-Clan General

www.Counter-Strike.net
User avatar
blebs
Posts: 12819
Joined: Sat Dec 02, 2000 12:00 am
Location: North Canton, Ohio

Post by blebs »

Originally posted by AoDLiQuiD-M3tH
is this why ive been getting so many mail undeliverable msgs ? but they dont show that the came from me. hmm ill have to run that tool when i get home.
Most likely is!
The tool doesn't always work. You may have to remove it manually and that stinks! Here is the link if you need it.
http://www.symantec.com/avcenter/venc/d ... .h@mm.html
iaus10
Posts: 1419
Joined: Sat Mar 17, 2001 12:00 am
Location: Minneapolis, MN

Post by iaus10 »

Install a decent firewall. I use Zone Alarm . It will alert you to any unauthorized incoming and outgoing data. Good Luck :)
Abit NF7, 2500+ o/c'd to 3200+, 1GB 3200 DDR, 9800Pro 128M, DVDrw, 80GB 8M, XPpro
User avatar
AoDLiQuiD-M3tH
Posts: 2457
Joined: Wed Jul 12, 2000 12:00 am
Location: Connecticut

Post by AoDLiQuiD-M3tH »

hey thanks for the link blebs , ill see what i find when i get home, stupid virus :D
-[AoD]-LiQuiD>M3tH-[SA]-
-[AoD]-Clan General

www.Counter-Strike.net
Post Reply