Arg. 'klez' worm.

MerkabaMerkaba Digital Harmony Join Date: 2002-01-24 Member: 22Members, Retired Developer, NS1 Playtester
Some ###### has sent me a Klez Worm via E-Mail and now I can't get rid of the affected file, 'Winkgz.exe' in WINNT/System32/. Windows prevents me from touching it, and the task manager says its always in operation (And I can't end the process either.)

I have a trojan cleaner, 'The Cleaner 3.5', but that does jack ####. It SAYS it cleans the file but it really can't touch the thing. I can't do anything about this file whilst windows is operating, it seems...yet it's the only OS I have.

How did I get this worm you ask? Bloody Outlook Express took it apon itself to download and run ####### attached .txt files, and I can't find an option anywhere to tell it NOT to...I'm guessing this is a fault in this Outlook version, and I should check for windows updates. (Thus meaning having to set aside 8 hours of time so that it can download the updates on my crappy connection.)

This is really bugging me. The only noticable change so far is that it seemed to delete my trillian.exe, and now Trillian won't even run at all, even after reinstalling it.

Am I doomed?

Comments

  • MerkabaMerkaba Digital Harmony Join Date: 2002-01-24 Member: 22Members, Retired Developer, NS1 Playtester
    Update: Managed to delete the file by loading windows in Safe Mode with Command Prompt. Bleh, I'm still ###### that I got this thing in the first place.

    Any idea why Outlook Express would do that? It's never done it to me before, and I've had plenty of trojan mails before - I've just never downloaded them. Suddenly Outlook Express seems to do it automatically.

    Also, if there any way to see how much damage the worm might have caused? Or shall I just have to find out the hard way?
  • def_onedef_one Join Date: 2002-05-21 Member: 641Members, Retired Developer, NS1 Playtester, Contributor
    run the windows update thing and download any updated to ie and outlook express.  thats an extremely exploitable bug in outlook that was fixed with one of the security updates.
  • MonsieurEvilMonsieurEvil Join Date: 2002-01-22 Member: 4Members, Retired Developer, NS1 Playtester, Contributor
    Stop stop stop. Go here and follow these steps, using this utility. I've already been through this with several thousand workstations, as well as Jeff P's mother <!--emo&:)--><img src="http://www.natural-selection.org/iB_html/non-cgi/emoticons/smile.gif" border="0" valign="absmiddle" alt=':)'><!--endemo-->

    <a href="http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.removal.tool.html" target="_blank">Klez Removal</a>

    Download the util, follow the steps they outline to make sure you are really getting all traces removed. Once cleaned, you may need to reinstall some things, but we'll use the klez log to determine what.



    <!--EDIT|MonsieurEvil|Oct. 14 2002,11:33-->
  • CollateralDamageCollateralDamage Join Date: 2002-07-15 Member: 949Members
    You should also stop using Outlook as email client. It's the main cause of virus infections. Any other client like Eudora or Pegasus offers the same (if not more) functions, and you have to worry about a little less M$ incompetence.
  • MoleculorMoleculor Namer-of-Bob Join Date: 2002-01-24 Member: 9Members
    Yeah... That hole was not only famous, but famously fixed like... ages ago. What are you running, OE5? (And ever since that bug was fixed, no, Outlook Express has NOT been the source of most viral infections... that's a stigma that lasted from that single security hole. The only way it's a source for virii now is if people don't -update-.)
  • MonsieurEvilMonsieurEvil Join Date: 2002-01-22 Member: 4Members, Retired Developer, NS1 Playtester, Contributor
    <!--QuoteBegin--CollateralDamage+Oct. 14 2002,17:17--></span><table border="0" align="center" width="95%" cellpadding="3" cellspacing="1"><tr><td><b>Quote</b> (CollateralDamage @ Oct. 14 2002,17:17)</td></tr><tr><td id="QUOTE"><!--QuoteEBegin-->You should also stop using Outlook as email client. It's the main cause of virus infections. Any other client like Eudora or Pegasus offers the same (if not more) functions, and you have to worry about a little less M$ incompetence.<!--QuoteEnd--></td></tr></table><span id='postcolor'><!--QuoteEEnd-->
    Learn to fix the problem, not just throw up your hands and surrender.

    Guy 1: 'Hey, my car's muffler has a leak.'
    Guy 2: 'D0000ddd, mufflers always leak and suck and break. They never work right. You should get a hang glider!!!'
  • DOOManiacDOOManiac Worst. Critic. Ever. Join Date: 2002-04-17 Member: 462Members, NS1 Playtester
    Turn off the preview pane first of all, that thing is the devil. View->Layout...

    Then if you have IE6 (and hence Outlook Express 6), go to Tools->Options...->Security Tab and check "Do not allow attatchments to be saved or open that could potentially be a virus." This makes it so IE will not open attatchments with most extensions (including .zip). When you are expecting an attatchment then just come back here and uncheck it to let Outlook let you have it. Also you prolly wanna make sure the Zone is set to Restricted while you are on this tab.

    Also, and this is just something that I do, unless I am expecting an attatchment from someone, every time I get an email with a paperclip icon (that means it has an attatchment) I right click on the message and go to Properties->Details tab and click "Message Source..." this brings up a notepad-like window where you view the raw ascii of the email, headers and all. most of it is garbage that won't mean a thing to you but you can read the contents of the mail without any worry of a virus, and more importantly, you can scroll down to where the attatchment starts and you can see the filename of the attatchment without ever opening the thing. If it looks suspicious, delete the message w/o ever opening it. Better to err on the side of precaution I say...

    Good luck to you in ridding your computer of the hax0rs. And if worse comes to worse, don't forget, almost nobody programs viruses anymore that a good old FDISK won't cure :P



    <!--EDIT|DOOManiac|Oct. 14 2002,20:13-->
  • DruBoDruBo Back In Beige Join Date: 2002-02-06 Member: 172Members, NS1 Playtester
    <!--QuoteBegin--DOOManiac+Oct. 14 2002,20:12--></span><table border="0" align="center" width="95%" cellpadding="3" cellspacing="1"><tr><td><b>Quote</b> (DOOManiac @ Oct. 14 2002,20:12)</td></tr><tr><td id="QUOTE"><!--QuoteEBegin-->...almost nobody programs viruses anymore that a good old FDISK won't cure <!--emo&:p--><img src="http://www.natural-selection.org/iB_html/non-cgi/emoticons/tounge.gif" border="0" valign="absmiddle" alt=':p'><!--endemo--><!--QuoteEnd--></td></tr></table><span id='postcolor'><!--QuoteEEnd-->
    ...Mostly. We've had a Nimda breakout here, at least that's what Norton identifies it as before all of its VXDs get nuked or deleted and the virus inserts itself into the BIOS. Whee, fun. It gets on the bootdisks that we use to kill it, too, so we have to throw them out after using them. It's a monster, and while we can handle it, we're going to throw out a lot of floppy disks.

    Apparently, the virus came from a Dell GX110 Faculty Desktop that had it festering on its drive for a year, with the power on but not connected to any network. I guess this kind of behaviour is in the original Nimda code, just under some sort of time-lock.... anyway, if this little bugger shows up around your neck of the woods, unplug your computer's internet connection and you'll save yourself a lot of trouble.

    Or use Linux. Nimda doesn't affect Linux.
  • TychoCelchuuuTychoCelchuuu Anememone Join Date: 2002-03-23 Member: 345Members
    <!--QuoteBegin--MonsieurEvil+Oct. 14 2002,15:05--></span><table border="0" align="center" width="95%" cellpadding="3" cellspacing="1"><tr><td><b>Quote</b> (MonsieurEvil @ Oct. 14 2002,15:05)</td></tr><tr><td id="QUOTE"><!--QuoteEBegin-->Guy 2: 'D0000ddd, mufflers always leak and suck and break. They never work right. You should get a hang glider!!!'<!--QuoteEnd--></td></tr></table><span id='postcolor'><!--QuoteEEnd-->
    Seconded. Get a new comp.


    J/k
  • VyvnVyvn Join Date: 2002-08-24 Member: 1226Members
    *Mental image of ns_hera.rmf going up in flames*

    Aaah!

    Oh, just a dream...*whew*
  • CollateralDamageCollateralDamage Join Date: 2002-07-15 Member: 949Members
    <!--QuoteBegin--></span><table border="0" align="center" width="95%" cellpadding="3" cellspacing="1"><tr><td><b>Quote</b> </td></tr><tr><td id="QUOTE"><!--QuoteEBegin-->Learn to fix the problem, not just throw up your hands and surrender.<!--QuoteEnd--></td></tr></table><span id='postcolor'><!--QuoteEEnd-->
    Nonsense, nobody is surrendering. Why should I waste my time with a crappy program from a company that just doesn't get how to do things right when superior programs are available for free? I didn't have to "update" my email client with "security fixes" even once because SOME programmers actually think about security issues BEFORE they release a program.
  • VenmochVenmoch Join Date: 2002-08-07 Member: 1093Members
    This won't tell you how to cure a viral problem, (stop sniggering in the back) but it'll give you some info on how the dammed things work!

    <a href="http://www.howstuffworks.com/virus1.htm" target="_blank">How Viruses Work!</a>
  • MerkabaMerkaba Digital Harmony Join Date: 2002-01-24 Member: 22Members, Retired Developer, NS1 Playtester
    I recently reformatted my hard drive and reinstalled windows, which is why my Outlook Express is outdated. My university net connection sucks and its difficult for me to update it.
  • GobyWanGobyWan Join Date: 2002-02-22 Member: 234Members
    <a href="http://www.penny-arcade.com/images/2002/20020722l.gif" target="_blank">This</a> is all I have for CollateralDamage.

    And I'm considering ditching my fairly old and oft-broken computer in favour of a small scientific non-programmable Pokémon calculator watch, rather than fixing the machine again. If someone can help me decide between Pikachu and Squirtle, it would be much appreciated.
  • JedisarJedisar Join Date: 2002-03-03 Member: 264Awaiting Authorization
    Merky is hiding Klez in his offical map and it shall devour the NS source Code on Flayra's computer and remove all traces of the game from all the PT's! HACKS!
  • loofboteloofbote Join Date: 2002-07-15 Member: 948Members
    <span style='color:red'>** Nuked ** Watch the language - no more warnings</span>



    <!--EDIT|MonsieurEvil|Oct. 17 2002,11:07-->
  • DruBoDruBo Back In Beige Join Date: 2002-02-06 Member: 172Members, NS1 Playtester
Sign In or Register to comment.