Go Back  PPRuNe Forums > Misc. Forums > Computer/Internet Issues & Troubleshooting
Reload this Page >

Have I acquired the klez virus?

Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Have I acquired the klez virus?

Thread Tools
 
Search this Thread
 
Old 3rd Sep 2002, 11:34
  #1 (permalink)  
Thread Starter
 
Join Date: Jan 2000
Location: Australia
Posts: 543
Likes: 0
Received 0 Likes on 0 Posts
Have I acquired the klez virus?

I run Win 2000 and OE6. Yesterday I got two emails, both from the same address in Japan, advising me that Lotus Notes had detected that I had sent two individuals emails containing the KLEZ virus. Neither of the two individuals are in my address book, and both are also in Japan.

I run the free version of AVG6 antivirus, and the latest update available for that is 21 Aug. It doesn't find any viruses on my system. I've logged onto Symantec and downloaded both their fixklez tool and done a complete on-line scan - neither found any visuses.

However, if I go Start/Search/Files and Folders and write "klez" in the "containing text" field, every one of my directories in Outlook Express comes up as containing the offending word.

Question: do I have a new version of klez, or it it normal to find this word in every directory of OE?

Thanks in advance.
MTOW is offline  
Old 3rd Sep 2002, 14:02
  #2 (permalink)  
 
Join Date: Feb 2000
Location: [edited by PPRuNe Admin]
Posts: 776
Likes: 0
Received 0 Likes on 0 Posts
This is the text from symantec.com/avcenter

Due to a decreased rate of submissions, Symantec Security Response has downgraded the threat level for W32.Klez.E@mm from Category 3 to Category 2 as of July 23, 2002.

W32.Klez.E@mm is similar to W32.Klez.A@mm. It is a mass-mailing email worm that also attempts to copy itself to network shares. The worm uses random subject lines, message bodies, and attachment file names.

The worm exploits a vulnerability in Microsoft Outlook and Outlook Express in an attempt to execute itself when you open or even preview the message in which it is contained. Information and a patch for the vulnerability are available at http://www.microsoft.com/technet/sec.../MS01-020.asp.

The worm overwrites files and creates hidden copies of the originals. In addition, the worm drops the virus W32.Elkern.3587, which is similar to W32.ElKern.3326.

The worm attempts to disable some common antivirus products and has a payload which fills files with all zeroes.

Removal tool
Symantec has provided a tool to remove infections of all known variants of W32.Klez and W32.ElKern. Click here to obtain the tool.

This is the easiest way to remove these threats and should be tried first.
this is the link
What_does_this_button_do? is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.