Computing.Net > Forums > Security and Virus > klez virus

Computing.Net: Over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to sign up now, it's free!

klez virus

Reply to Message Icon

Original Message
Name: warren
Date: January 14, 2003 at 07:19:01 Pacific
Subject: klez virus
OS: winxp
CPU/Ram: pent 4, 256 mb
Comment:

Every once in a while I get the following pop up:
"Virus identified I-Worm/Klez.H is found in the C:\System Volume Information\_restore{1134CBB0-31B0-483C-A4FE-D6E9E8C18928}\RP157\A0032143.exe

To remove this virus please run AVG for windows."

I have scanned with AVG and Norton and found no virus's after updating the virus definitions. Anyone have any suggestions? Thanks.


Report Offensive Message For Removal


Response Number 1
Name: Imp
Date: January 14, 2003 at 09:12:53 Pacific
Reply:

Hello Warren,
Klez Virus is a trojan virus very well known, particularity is to be able to hide itself from the program Norton from Symantec.
Here is what is saying "Trojan Remover" program about it: "This worm drops a virus (W95/Elkern.cav).Ensure you scan your system with a standard anti-virus program after Trojan Remover has disabled the Worm."
I suggest you download the program Trojan Remover at the address: http://www.simplysup.com/tremover/details.html
This program is a freeware for one month. Scan your computer as soon as possible with it...


Report Offensive Follow Up For Removal

Response Number 2
Name: Palival
Date: January 14, 2003 at 09:22:37 Pacific
Reply:

Hello,

You need to disable system restore to viruses in _RESTORE folder. For instructions visit www.srnmicro.com/customers/resdisable.htm

Have a nice day


Report Offensive Follow Up For Removal

Response Number 3
Name: warren
Date: January 14, 2003 at 09:23:06 Pacific
Reply:

Thanks Imp. I have that program and it scans every time I start my computer and I still get this. Any other help? Thanks.


Report Offensive Follow Up For Removal

Response Number 4
Name: JackG
Date: January 14, 2003 at 09:48:01 Pacific
Reply:

You, not a program, must disable System Restore to clear the _Restore files of any and all traces of the Klez virus. All the Klez virus removal tool INSTRUCTIONS include this required manual step for XP.


Report Offensive Follow Up For Removal

Response Number 5
Name: Nick R (by Nick Ritchie)
Date: January 15, 2003 at 05:25:39 Pacific
Reply:

Listen to JackG , he is correct that you must disable the system restore utility in order to purge the virus from your system .Even though I dont have WindowsXP, Iam running Windows Me , which also has system restore. My Anti-Virus caught the Klez virus a quarantined it , I then deleted it , however a scan would show the virus still in the system restore folder ! Since I did not want to delete the folder , I went to sysmantec's web site where they had instructions posted for removing the virus from system restore by disabling it !


Report Offensive Follow Up For Removal


Response Number 6
Name: Norbert Heinisch
Date: January 15, 2003 at 13:46:56 Pacific
Reply:

As I am having klez removal troubles myself
and wanted to load the fiel I found that the correct link is:
http://members.aol.com/simplysup/tremover/download.html

I will see if I get rid of the klez bug now.
Work on it since days.
Norbert Heinisch


Report Offensive Follow Up For Removal

Response Number 7
Name: Imp
Date: January 16, 2003 at 05:11:45 Pacific
Reply:

Hello Warren,
I come back to this post again to explain how is working Trojan Remover:

"When Trojan Remover detects a trojan or worm, it attempts (if requested) to rename the file, and remove the calling reference. Where the malware detected is known to carry out other actions (create new registry keys, drop new files, alter system files etc) these changes are sought and, if necessary, corrected (again, the user would be prompted about the changes and asked by Trojan Remover if they wish to fix them).

Trojan Remover does not halt any running processes as this can be problematic. Instead, if Trojan Remover finds that it cannot take action on a file because it has a running process, Trojan Remover states it needs to reboot the system and offers to do this automatically. Once rebooted, and before Windows restarts, Trojan Remover then completes any operations it was not able to carry out before the reboot.

During a normal scan files are RENAMED by Trojan Remover rather than being deleted outright (this is to protect against the rare possibility of action being taken as a result of a False Positive - by renaming a malicious file, the file is completely deactivated, but can still be recovered if need be). Such renamed files can be manually deleted when it is confirmed they are malicious, or Trojan Remover can be set to locate these during a Drive/Directory scan (see the "Options > Files To Scan" option on the Drive/Directory scanning window for the option "Include files already renamed by Trojan Remover", which is selected by default).

Nigel."


Report Offensive Follow Up For Removal






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home



Results for: klez virus

Klez viruses
    Summary: I desperately need help. I have had klez viruses on my computer for some time now, in quaranteen. When AVG just scanned my computer right now it says there are 120 infected files. When I go into No...
www.computing.net/answers/security/klez-viruses/5313.html

Klez virus in Server
    Summary: Hi, My NAV console detected a klez virus in 1 of our server. I disable the File System Realtime Protection and ran the removal tools but the result is neither any virus was found on the server. What...
www.computing.net/answers/security/klez-virus-in-server/2952.html

Klez Virus !
    Summary: I was recieving the Klez virus daily for a good 3 weeks . I have my Norton Anti Virus up to date and enabled. I also am aware that after you recieve this virus (using Outlook Express) in Windows Me ...
www.computing.net/answers/security/klez-virus-/1783.html








Which MP3 player do you have?

iPod/iPhone
Zune
Something Else
None


View Results

Poll Finishes Today.
Discuss in The Lounge
Poll History






Data Recovery Software