Computing.Net > Forums > Security and Virus > W32Klez Virus !

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

W32Klez Virus !

Reply to Message Icon

Name: Nick R (by Nick Ritchie)
Date: May 22, 2002 at 06:44:45 Pacific
Comment:

I have been recieving the Klez virus on a daily basis for over 3 weeks now .It arrives in at least one or more email with an attachment. My Norton Anti-Virus Protection is catching the virus and keeping my system from becoming infected. Because I have Windows Me , I have to disable the System Restore Utility to purge the virus from the Restore/Temp folder . Then I run a full hard drive scan to make sure the virus is not still on my PC ! The virus scan takes about a 1/2 hour to perform. Its a major pain in the neck! Is anyone else recieving this virus on such a steady basis. I use Outlook Express & Hotmail . All of the emails with the virus attachment have been coming to me in Outlook. I have the pre-veiw pane removed, and my virus protection is up to date. Could someone actually be targetting me to continually keep recieving this virus . I do go to some politicial web sites and post my opinions which some others most probably disagree with. Any input welcomed !Thanks to All! Nick



Sponsored Link
Ads by Google

Response Number 1
Name: Tank863
Date: May 22, 2002 at 07:19:23 Pacific
Reply:

Nick,

I also receive this virus on a dailt basis.
However, Norton is catching the virus and allowing me to quarantine the virus so that it does not infect my system.

Follow my game plan for Viruses, Worms, and Trojans outloined below and you will be safe.

1) update you antivirus software and run a full scan of your system.
if you do not have a antivirus program... go to http://www.grisoft.com/html/us_index.htm and download this very good free anti virus program.

100% detection rate of AVG Anti-Virus System is continuously certified by independent ICSA laboratories

2) use a software firewall... if you don't have one.. download the free version of Zonealarm from:
http://www.zonelabs.com/

The award-winning personal firewall automatically blocks dangerous Internet threats - known and unknown - guarding your PC from hackers and data thieves. ZoneAlarm provides the basic protection individuals need to secure their PC and keep their valuable information private.

this will prevent anyone from accessing your computer.

3) go to http://www.majorgeek.com/index2.html or http://www.lsfileserv.com/ and download their free program called ad-aware 5.81.
this will remove any spy-ware that is on your system.

Ad-aware is a free multi spyware removal utility that scans your memory, registry and hard drives for known spyware and scumware components and lets you remove them safely. It is updated frequently.


4) go to: http://www.finjan.com/
and down load SurfinGuard® Pro 5.7 - Beta.
SurfinGuard® Pro protects PC users from new, unknown Internet threats by monitoring and containing the behavior of downloaded progams and active content. SurfinGuard Pro runs active content (e.g., executables, ActiveX, scripts, Windows scripting files and Java) in a protected "sandbox" called the Safe Zone that automatically blocks potentially hostile actions.

5) go to http://lockdowncorp.com/bots/downloadswatit.html
download a program called Swat-it. It will remove trojans and bots.

Swat It is a Completely FREE program that scans your files for Trojans, Worms, Bots and other Hacker programs. Swat It can detect and remove over 3000 different Trojan programs plus variants.

6) go to: http://www.diamondcs.com.au/ download TDS Ver 3.21. It is a trial for a Trojan finder and removal tool.

The worlds most comprehensive anti-trojan system just got even better!
There are several anti-trojan systems in existance, but none can even be compared to TDS.

Tank863

If anyone has other programs that they have tested and work better than the programs listed, please email me at tank863@hotmail.com or post here.

Thanks.


0

Response Number 2
Name: Dan
Date: May 22, 2002 at 08:29:57 Pacific
Reply:

I too receive it almost 1-2 times/day. It's
amazing how this thing spreads!

Many thanks to Tank863 for your 'plan', it
was very usefull to me!


0

Response Number 3
Name: Jennifer
Date: May 22, 2002 at 09:49:12 Pacific
Reply:

If you're situation is the same as mine, the e-mails are coming from the same machine on the same domain.

I just set a rule in Outlook to delete them permanently, and then I don't have to mess with them.

Look at the header information and check out the Received From: line. It's not the same as the e-mail address that appears in the Sender field. It's about three lines from the bottom of the header. That's what you want to block. Either that particular machine or the entire domain.


0

Response Number 4
Name: Regale
Date: May 22, 2002 at 17:02:39 Pacific
Reply:

Since you use OE, you could download a free program called Mailwasher. If you have it on and minimized it will alert you when you have mail and you can check on it what it is and where its from before it is downloaded onto your computer. You have the option to bounce (which is good for spam because they think it is not a working address) or you can delete it or both. You also have the option to view what is in it and/or view the headers in a safe mode. I really like it.


0

Response Number 5
Name: Regale
Date: May 22, 2002 at 17:06:07 Pacific
Reply:

I have never posted here so I did it wrong.LOL The url for my homepage is the url for the Mailwasher program. I don't have a url. If you want to check on the program, go to that url at the top of my first post.


0

Related Posts

See More



Response Number 6
Name: Peter Jansen
Date: May 24, 2002 at 14:13:11 Pacific
Reply:

To remove the virus Win32.Magistr do the following;
Go to start
Click on Find - files or folders
Type in - sulfnbk.exe
If this shows up
Highlight by clicking on it only ONCE
(DO NOT OPEN IT)
Delete it
Empty the recycle bin.


0

Response Number 7
Name: Peter Jansen
Date: May 24, 2002 at 14:15:29 Pacific
Reply:

I too received the virus W32Klez. I have removed it from my computer but I have 17 infected files. All the infected files are in Windows. How can I fix them?


0

Response Number 8
Name: Buster
Date: July 4, 2002 at 05:18:17 Pacific
Reply:

One thing that these email viruses don't do is sign the name of the person whose PC mailed it. So if it is too hard not to open every email attachment, look for a signature. Also Sulfnbk.exe is not a virus it is a "Long File Name Backup utility" for Windows. However, some e-mail worms might sometimes send an infected SULFNBK.exe in an e-mail attachment.
If you get SULFNBK.exe in an e-mail attachment, it's probably a virus. If you find it from your Windows directory, it's probably not. W32Klez is scary; it zapped my notepad.exe just because I opened a .txt file in an AV folder and did it in less than 3 seconds. Anyone who's PC has it shouldn’t wait around, go to Symantec and get the fix then be careful opening attachments.
Thanks, Buster


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: W32Klez Virus !

W32Klez Virus ! www.computing.net/answers/security/w32klez-virus-/564.html

w32Klez.H@mm virus affected www.computing.net/answers/security/w32klezhmm-virus-affected/2714.html

Klez Viruses and Outlook Express www.computing.net/answers/security/klez-viruses-and-outlook-express/992.html