W32.Klez.gen@mm help!
W32.Klez.gen@mm help!
Guys!
I need your help! I am infected with the W32.Klez.gen@mm virus. I know this because i keep getting messages back from different ISP's saying that _________ person could not be found. Those also come back with the attachment of a virus. Then i get some that say "You have sent __________ a virus, and was not delivered". I am running Norton Antivirus 2002. I went to there website and downloaded the fix, but when its running the fix performs an illegal operation on some files, and it closes. When i go to find them, they dont even exist! Can anyone find manual steps to remove the virus ?
Thanks
I need your help! I am infected with the W32.Klez.gen@mm virus. I know this because i keep getting messages back from different ISP's saying that _________ person could not be found. Those also come back with the attachment of a virus. Then i get some that say "You have sent __________ a virus, and was not delivered". I am running Norton Antivirus 2002. I went to there website and downloaded the fix, but when its running the fix performs an illegal operation on some files, and it closes. When i go to find them, they dont even exist! Can anyone find manual steps to remove the virus ?
Thanks
All the Best
TBob
TBob
try here..... http://securityresponse.symantec.com/av ... en@mm.html .
Here
is the removal tool for this virus. I would suggest to restart computer once it finishes cleaning your hard drive and run it 1 more time.
Good Luck
PS some files might not be repairable and you might loose some data
is the removal tool for this virus. I would suggest to restart computer once it finishes cleaning your hard drive and run it 1 more time.
Good Luck
PS some files might not be repairable and you might loose some data
yah... i ran it again, and it performs an illegal operation. Im running XP, and dont you get those messages where it says "Send error report" / "Dont Send" ... i get that for the klezfix program! Its so annoying! I need to get this virus off my computer as i have a huge address book & it is sending to everyone!Originally posted by -Hitman-
Here
is the removal tool for this virus. I would suggest to restart computer once it finishes cleaning your hard drive and run it 1 more time.
Good Luck
PS some files might not be repairable and you might loose some data
All the Best
TBob
TBob
I hope this helps.
To remove this worm, delete files that are detected as W32.Klez.A@mm, and remove the value that it added to the registry.
To remove the worm:
1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
3. Run a full system scan.
4. Delete all files that are detected as W32.Klez.A@mm.
To edit the registry:
CAUTION: We strongly recommend that you back up the system registry before you make any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure that you modify only the keys that are specified. Please see the document How to back up the Windows registry before you proceed.
1. Click Start, and click Run. The Run dialog box appears.
2. Type regedit and then click OK. The Registry Editor opens.
3. Navigate to the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
4. In the right pane, delete the following value:
krn132 %System%\krn132.exe
5. Click Registry, and click Exit.
To remove this worm, delete files that are detected as W32.Klez.A@mm, and remove the value that it added to the registry.
To remove the worm:
1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
3. Run a full system scan.
4. Delete all files that are detected as W32.Klez.A@mm.
To edit the registry:
CAUTION: We strongly recommend that you back up the system registry before you make any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure that you modify only the keys that are specified. Please see the document How to back up the Windows registry before you proceed.
1. Click Start, and click Run. The Run dialog box appears.
2. Type regedit and then click OK. The Registry Editor opens.
3. Navigate to the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
4. In the right pane, delete the following value:
krn132 %System%\krn132.exe
5. Click Registry, and click Exit.
ok weird, i dont have a krn132.exe file on in my registry, but on the symantec website they say its wink[random characters].exeOriginally posted by -Hitman-
I hope this helps.
To remove this worm, delete files that are detected as W32.Klez.A@mm, and remove the value that it added to the registry.
To remove the worm:
1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
3. Run a full system scan.
4. Delete all files that are detected as W32.Klez.A@mm.
To edit the registry:
CAUTION: We strongly recommend that you back up the system registry before you make any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure that you modify only the keys that are specified. Please see the document How to back up the Windows registry before you proceed.
1. Click Start, and click Run. The Run dialog box appears.
2. Type regedit and then click OK. The Registry Editor opens.
3. Navigate to the following key:
HKEY_LOCAL_MACHINE\Software\Microsoft\
Windows\CurrentVersion\Run
4. In the right pane, delete the following value:
krn132 %System%\krn132.exe
5. Click Registry, and click Exit.
weird...
All the Best
TBob
TBob
- AoDLiQuiD-M3tH
- Posts: 2457
- Joined: Wed Jul 12, 2000 12:00 am
- Location: Connecticut
Most likely is!Originally posted by AoDLiQuiD-M3tH
is this why ive been getting so many mail undeliverable msgs ? but they dont show that the came from me. hmm ill have to run that tool when i get home.
The tool doesn't always work. You may have to remove it manually and that stinks! Here is the link if you need it.
http://www.symantec.com/avcenter/venc/d ... .h@mm.html
Install a decent firewall. I use Zone Alarm . It will alert you to any unauthorized incoming and outgoing data. Good Luck 
Abit NF7, 2500+ o/c'd to 3200+, 1GB 3200 DDR, 9800Pro 128M, DVDrw, 80GB 8M, XPpro
- AoDLiQuiD-M3tH
- Posts: 2457
- Joined: Wed Jul 12, 2000 12:00 am
- Location: Connecticut