//flex table opened by JP

Click to See Complete Forum and Search --> : The Boomerang virus---Klez.h that keeps coming back!


2penguins
05-14-2003, 12:44 AM
Somehow I've gotten onto the Klez.h mailing list.


I've gotten the worm from several different addresses(none who would have my address in their contact list) over the past few days. It's becoming a real pain in the **** because AVG doesn't seem to plugin to Opera 7. So that means running the virus scanner everytime the **** thing hits.


I've also been getting a popup warning me that I worm/Klez.h has infected C:\System Volume information\ restore_{2d7f664c-6298-4ef0-b07e-oe3ded8ab630}\rp22\a0003833.bat

It only happens when WIN XP(pro sp-1) goes into standby and goes back to the logon screen. I thought it may just be a bug in AVG 6.0, however I wasn't running AVG before I got the first infected mail so there's no way for me to tell if it's a bug or a real infection.

When I get the message I run the scanner and it finds nothing.
I've even run Symantec's Fixklez.exe with no luck.


Anyone know a fix?

Rocketmech
05-14-2003, 06:51 AM
You need to disable System Restore before the fix . Otherwise , XP restores the virus after each reboot.

bushmaster
05-14-2003, 07:57 AM
Bingo. Personally I've turned off restore completely. For me it just eats up space and resources that could be better used elsewhere. But you do need to do a cleansing with the system restore turned off. Otherwise it's like night of the living dead and keeps coming back to haunt you.

2penguins
05-14-2003, 08:15 AM
Thanks, but I found the fix in Google groups.

You disable Restore, then reboot
then you enable restore and reboot.

You lose all of your restore points, but it gets rid of the worm.