vu sur www.antivirus.com
Solution:
Automatic Removal Instructions
Please download and run the fix_worm_klez_4.04.zip fix tool. If you have a MD5 signature checker, the MD5 hash of this tool is 10F4EB881138D7485D95A00EE93F20B4.
Trend Micro requests that all users also download and read the readme_worm_klez_4.04.txt text before using this tool.
Manual Removal Instructions
For Windows 95 systems:
Restart your computer.
Press the F8 key when you see the message, "Starting Windows 95."
For Windows 98/Me systems:
Restart your computer.
Press the Ctrl key until your Windows 98 startup menu appears.
Choose the Safe Mode option then hit the Enter key.
For Windows XP systems:
Restart your computer.
When prompted, press the F8 key. If Windows XP Professional starts without the ?Press select operating system to start? menu, restart your computer.
Press F8 again after the Power-On Self Test is done.
Choose the Safe Mode option from the Windows Advanced Options Menu.
For Windows 2000 systems:
Restart your computer.
Press the F8 key, when you see the Starting Windows bar at the bottom of the screen.
Choose the Safe Mode option from the Windows 2000 Advanced Options Menu.
Scan your system with Trend Micro antivirus and write down the filenames of all files detected as WORM_KLEZ.H. These infected files may be WINK*.EXE files. * is a random number of characters.
Click Start>Run, type Regedit then hit the Enter key.
In the left panel, double click the following:
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows
>CurrentVersion>Run
In the right panel, look for and then delete these registry values. * is any random characters:
?Wink*? = ?%System%\Wink*.exe?
?WQK? = ?%System%\Wqk.exe?
In the left panel, double click the following:
HKEY_LOCAL_MACHINE>System>CurrentControl Set>Services
Under the Services key, look for and then delete this subkey:
Wink*
Close the Registry Editor.
Restart the system.
Scan your system with Trend Micro antivirus and delete all files detected as WORM_KLEZ.H. To do this, Trend Micro customers must download the latest pattern file and scan their system. Other email users may use HouseCall, Trend Micro's free online virus scanner.
Since this worm uses a vulnerability in HTTP-based email clients like Microsoft Outlook and Outlook Express, please apply the latest patches as follows:
Update to Internet Explorer 5.01 SP2
Update to IE 5.5 SP2
Update to IE 6.0