PDA

View Full Version : Virus


stefanus
08-17-2002, 09:58 AM
Howzit. Has any Gek come across a virus named WinXzip or something like that or is it mabe another Nigerian message.
Thanks
Stefanus

mjc
08-17-2002, 01:25 PM
Got any more info on it?

Like where did it come from?

Did a virus scanner catch it or is it just a mystery file?

Budfred
08-17-2002, 03:39 PM
The was reference to it in a PCWorld news email I got this week. Apparently it is a Klez mutation. I will try to find and post the link to the info here.

Budfred

EDIT:
Here is the info that I saw with a URL to get a specific tool to remove it. Budfred

F-Secure Antivirus Klez Removal Tool

Klez.E is a new variant of the Klez worm that was first discovered on January 17, 2002. Version 2.0 of the worm installs itself in the Windows System
directory as a Winkxxxx.exe file. Then it overwrites your .exe file and creates a backup file with the same name as the infected file, but with a random
extension and with hidden, system, and read-only attributes.

Price: Free

Download F-Secure Antivirus Klez Removal Tool now at:
http://www.pcworld.com/downloads/file_description/0,fid,22272,tk,hsx,00.asp

stefanus
08-19-2002, 09:19 AM
Thanks for your replies. Budfred, I tried to down load the Klez tool but my PC informs that a problem occured when trying to down load, I tried several times, I have Windows 98 extra and I think Windows2000 etc is required. MJC I am almost sure that the e-mail had a winkxxxxexc address and it was a mystery message. Please I need help, my PC does a scan every time I boot up and I down load Norton Anti Virus Updates weekly :( :confused:

Budfred
08-19-2002, 11:23 AM
I looked at the link I gave you and it indicates that this tool should work with any recent version of Windows, so that is probably not the problem. Given that this Klez variation has been around for a while I suspect that your regular AV program has a fix for it too. If all else fails, there is always the back up crucial records and reformat option.

You might want to update your AV files and then run the deepest AV scan you can get out of Norton. I know they have one scanning option that goes deep enough that it takes several hours to complete. Turn everything else off and run it when you don't need the computer for a long time.

Good luck,
Budfred

stefanus
08-20-2002, 12:14 PM
Thanks I have checked out my Norton av and it recognises W32 Klez and its variations so I will check the whole system someway. Thanks guys