Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | WORM_KLEZ.E Virus?


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > Security & Virus Discussion

WORM_KLEZ.E Virus?
Reply
 
Thread Tools
Old 14-12-2009, 19:11   #1
Keyz333
cf.addict
 
Join Date: Oct 2007
Location: Yateley, Hampshire
Age: 22
Services: Virgin TV & Broadband
Posts: 261
Keyz333 will become famous soon enoughKeyz333 will become famous soon enoughKeyz333 will become famous soon enough
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333 Send a message via Skype™ to Keyz333
WORM_KLEZ.E Virus?

I seem to have this virus now ' WORM_KLEZ.E ' or something similar.

I basically cannot run quite a few applications.

I searched around the web about it, and it has been talked about a bit.

I cannot run Spybot S&D as it stops me.
I cannot System restore, as it also stops me.
I cannot run a few .exe's

I am running Avast! right now to see if it can find anything.

What is also interesting is that in my Task Manager > Processes The user name which is running ALL of my processes, is something in, what looks lines chinese(Will get screenshot if needed, later)

Anyone else had this? and have an idea how to get it of my computer.

I am running Windows 7 RC client, and I don't know if there is a way of reinstalling this either.

Thanks in advance

Quote:
These error messages may be caused by the WORM_KLEZ.E virus, or one of its variations. The executable file name "qbw32[xxx].exe" may vary, where "[xxx].exe" is a randomly generated and false executable name.
Keyz333 is offline   Reply With Quote
Advertisement
Old 14-12-2009, 19:17   #2
zing_deleted
Guest
 
Posts: n/a
Re: WORM_KLEZ.E Virus?

can you download malwarebytes? if its not blocked the download rename it to anythingyouwant.exe hopefully that will allow you to install and run it. What security let it in?
  Reply With Quote
Old 14-12-2009, 19:25   #3
Keyz333
cf.addict
 
Join Date: Oct 2007
Location: Yateley, Hampshire
Age: 22
Services: Virgin TV & Broadband
Posts: 261
Keyz333 will become famous soon enoughKeyz333 will become famous soon enoughKeyz333 will become famous soon enough
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333 Send a message via Skype™ to Keyz333
Re: WORM_KLEZ.E Virus?

It's letting me run MB, I'm just about to start a scan.. I'm looking at Hijackthis too. I have Avast! running all the time, and had it since yesterday I believe. They say it gets transferred through USB, but I haven't really used any USB devices that could have. The process list is really odd though.

EDIT Hijackthis got nothing.

Last edited by Keyz333; 14-12-2009 at 19:29.
Keyz333 is offline   Reply With Quote
Old 14-12-2009, 19:47   #4
Toto
cf.mega poster
 
Join Date: Dec 2004
Posts: 3,366
Toto has a bronzed appealToto has a bronzed appeal
Toto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appeal
Re: WORM_KLEZ.E Virus?

Quote:
Originally Posted by Keyz333 View Post
It's letting me run MB, I'm just about to start a scan.. I'm looking at Hijackthis too. I have Avast! running all the time, and had it since yesterday I believe. They say it gets transferred through USB, but I haven't really used any USB devices that could have. The process list is really odd though.

EDIT Hijackthis got nothing.
Hijack this tends to look at Internet Explorer hooks, that is its strength, not a good AV tool though.

You could try http://vil.nai.com/vil/stinger/, that may well work as it deals with some Klez variants.

Simple program to download and run.
__________________
Toto

http://www.cableforum.co.uk/board/image.php?u=6881&dateline=1172428039&type=sigpic
Toto is offline   Reply With Quote
Old 14-12-2009, 19:59   #5
Keyz333
cf.addict
 
Join Date: Oct 2007
Location: Yateley, Hampshire
Age: 22
Services: Virgin TV & Broadband
Posts: 261
Keyz333 will become famous soon enoughKeyz333 will become famous soon enoughKeyz333 will become famous soon enough
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333 Send a message via Skype™ to Keyz333
Re: WORM_KLEZ.E Virus?

Quote:
Originally Posted by Toto View Post
Hijack this tends to look at Internet Explorer hooks, that is its strength, not a good AV tool though.

You could try http://vil.nai.com/vil/stinger/, that may well work as it deals with some Klez variants.

Simple program to download and run.
I'm just running it now, will get back to you.
Keyz333 is offline   Reply With Quote
Old 14-12-2009, 20:00   #6
Toto
cf.mega poster
 
Join Date: Dec 2004
Posts: 3,366
Toto has a bronzed appealToto has a bronzed appeal
Toto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appeal
Re: WORM_KLEZ.E Virus?

Quote:
Originally Posted by Keyz333 View Post
I'm just running it now, will get back to you.
Good luck.

Handy little program to keep on a USB stick, as long as you have the most up to date version.
__________________
Toto

http://www.cableforum.co.uk/board/image.php?u=6881&dateline=1172428039&type=sigpic
Toto is offline   Reply With Quote
Old 14-12-2009, 22:11   #7
Keyz333
cf.addict
 
Join Date: Oct 2007
Location: Yateley, Hampshire
Age: 22
Services: Virgin TV & Broadband
Posts: 261
Keyz333 will become famous soon enoughKeyz333 will become famous soon enoughKeyz333 will become famous soon enough
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333 Send a message via Skype™ to Keyz333
Re: WORM_KLEZ.E Virus?

It seems I can't change my users in the control panel either... I was going to remove another one of my users, and can't even get to that part of it. I click 'Add or remove Users' and nothing happens.

Malware Bytes has got upto 232,000 files, and none are infected.
Stinger has been going on for ages, and still hasn't found anything that I know of.

EDIT - After running all that stuff for a while, my computer seemed to want to restart on it's own.. and since then it seems ok..

Weirdly enough..

Thankyou for your help, hopefully it will stay this way !

Last edited by Keyz333; 14-12-2009 at 22:53.
Keyz333 is offline   Reply With Quote
Old 15-12-2009, 05:54   #8
Toto
cf.mega poster
 
Join Date: Dec 2004
Posts: 3,366
Toto has a bronzed appealToto has a bronzed appeal
Toto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appealToto has a bronzed appeal
Re: WORM_KLEZ.E Virus?

Quote:
Originally Posted by Keyz333 View Post
It seems I can't change my users in the control panel either... I was going to remove another one of my users, and can't even get to that part of it. I click 'Add or remove Users' and nothing happens.

Malware Bytes has got upto 232,000 files, and none are infected.
Stinger has been going on for ages, and still hasn't found anything that I know of.

EDIT - After running all that stuff for a while, my computer seemed to want to restart on it's own.. and since then it seems ok..

Weirdly enough..

Thankyou for your help, hopefully it will stay this way !
Hmmm, restarted on its own......

There's a rather nasty root kit that forces a PC to restart on its own...

Got to www.prevx.com and download their free scanner program just to be on the safe side. It could well be that you system is OK, but its odd that so far nothing you have tried has identified the worm, and removed it.
__________________
Toto

http://www.cableforum.co.uk/board/image.php?u=6881&dateline=1172428039&type=sigpic
Toto is offline   Reply With Quote
Old 15-12-2009, 09:37   #9
Stuart
Cable Forum Team
 
Stuart's Avatar
 
Join Date: Jun 2003
Location: Sarf east Luhndun.
Services: Virgin for TV and Internet, BT for phone
Posts: 24,243
Stuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered stars
Stuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered stars
Send a message via MSN to Stuart Send a message via Skype™ to Stuart
Re: WORM_KLEZ.E Virus?

I think a good option at this point would be to backup any data you need (not the programs), reformat and reinstall..
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.
Stuart is offline   Reply With Quote
Old 15-12-2009, 09:40   #10
Keyz333
cf.addict
 
Join Date: Oct 2007
Location: Yateley, Hampshire
Age: 22
Services: Virgin TV & Broadband
Posts: 261
Keyz333 will become famous soon enoughKeyz333 will become famous soon enoughKeyz333 will become famous soon enough
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333 Send a message via Skype™ to Keyz333
Re: WORM_KLEZ.E Virus?

How do I reinstall the RC of W7..? I had Vista before, but I do not have a disk, due to it being on there already. I'm not sure if there is a way of reinstalling?
Keyz333 is offline   Reply With Quote
Old 15-12-2009, 10:22   #11
Aragorn
cf.mega poster
 
Aragorn's Avatar
 
Join Date: Apr 2004
Location: Minas Tirith, Gondor
Age: 46
Posts: 3,458
Aragorn has a nice shiny star
Aragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny starAragorn has a nice shiny star
Re: WORM_KLEZ.E Virus?

You know the RC has only got a few months life left anyway? I think from 1 March it will shutdown every two hours.
Are you a full time student still? If you have an ac.uk email address you can get Win 7 Home or Pro for £30.
Aragorn is offline   Reply With Quote
Old 15-12-2009, 11:26   #12
Stuart
Cable Forum Team
 
Stuart's Avatar
 
Join Date: Jun 2003
Location: Sarf east Luhndun.
Services: Virgin for TV and Internet, BT for phone
Posts: 24,243
Stuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered stars
Stuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered starsStuart is seeing silvered stars
Send a message via MSN to Stuart Send a message via Skype™ to Stuart
Re: WORM_KLEZ.E Virus?

If he is a full time student, he may be able to download it for free through the MSDN Academic Alliance.
__________________
Just to make it clear if a post is bold and is from a team member, it's a moderating decision. If it's not bold or not from a team member, it's not.
Stuart is offline   Reply With Quote
Old 15-12-2009, 13:33   #13
Keyz333
cf.addict
 
Join Date: Oct 2007
Location: Yateley, Hampshire
Age: 22
Services: Virgin TV & Broadband
Posts: 261
Keyz333 will become famous soon enoughKeyz333 will become famous soon enoughKeyz333 will become famous soon enough
Send a message via AIM to Keyz333 Send a message via MSN to Keyz333 Send a message via Skype™ to Keyz333
Re: WORM_KLEZ.E Virus?

Nope, no longer a student, I'm at full time employment now.
Keyz333 is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Google Search




All times are GMT +1. The time now is 08:39.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server1.cableforum.co.uk)

SEO by vBSEO 3.3.2