The following instructions have been created to help you to get rid of "Klez" manually.
Use this guide at your own risk; software should usually be better suited to remove malware, since it is able to look deeper.

If this guide was helpful to you, please consider donating towards this site.

Threat Details:

Categories:
  • worm

Description:
Symantec information: http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html
Sophos information: http://www.sophos.com/virusinfo/analyses/w32klezh.html
McAfee Information: http://vil.mcafee.com/dispVirus.asp?virus_k=99455
Detection finds only main files. If you find one or both Klez entries, make sure you update your antivirus software and use it to remove the worm.
Also, if you've got We-Blocker installed, this may be a false positive, so check with your AV first before removing it!
Supposed Functionality:
Gets installed by opening an infected email. Once installed, it sends itself to all contacts it can gather from your address book, even email addresses found in the web site cache. Subject and contents of these mails change.
Links (be careful!):
Symantec: http://securityresponse.symantec.com/avcenter/venc/data/w32.klez.h@mm.html
Sophos: http://www.sophos.com/virusinfo/analyses/w32klezh.html
McAfee: http://vil.mcafee.com/dispVirus.asp?virus_k=99455
Removal Instructions:

Autorun:

Important: There are more autorun entries that cannot be safely described in simple words. Please use Spybot-S&D to remove them.

Files:

Important: There are more files that cannot be safely described in simple words. Please use Spybot-S&D to remove them.

Final Words:

If neither Spybot-S&D nor self help did resolve the issue or you would prefer one on one help,
  1. Please read these instructions before requesting assistance,
  2. Then start your own thread in the Malware Removal Forum where a volunteer analyst will advise you as soon as available.