FRISK Software International


Summary of W32/Klez.H@mm
Alias:I-Worm.Klez.H, W32/Klez.H
Infectable objects: PE files
Discovered: 17 Apr 2002
Definition files: 17 Apr 2002
Risk Level: High
Distribution:High
Payload: Drops Elkern.C
 
Jump to:
Brief description

Brief Description

A new variant of the Klez virus has started spreading rapidly. This new variant is called Klez.H@mm and seems to be originating from Asia.

This new variant is spreading much faster than its predecessors and is both a companion virus and a worm. Klez.H@mm also drops a new virus on an infected machine, called Elkern.C.

It sends out e-mail spreading itself with random subjects and randomly named attachment. Klez.H@mm seem to be very similar to its predecessors with the exceptions that a .PDF ending has been added to the list it uses for making double extensions and that Klez.H has no payload routine itself.

Klez.H occasionally uses a social engineering trick that the other variants did not use. It then spreads through an e-mail message disguised as a cleaning tool for Klez.E. The subject line of these messages is 'Worm Klez.E immunity' and the body states that the attachment contains a special tool for defeating Klez.E. It even warns the recipient that some anti-virus products might trigger on the 'tool', but asks users to ignore the warning.

F-Prot Antivirus™ version 3.12 using virus signature files from the 17th of April detects Klez.H@mm.



FRISK Software International's Viruslab Team
 


Stay up to date with important developments via e-mail.
Stay up to date with life cycle policies for F-PROT Antivirus for Windows.
Virus news and information directly to your desktop.
Definitions of common antivirus terminology.
For further virus information, please try our partners' websites:

Authentium

perComp Verlag
(in German)
 

agoat@klaki.net argentina@f-prot.com argentina@frisk.is argentina@complex.is argentina@f-prot.is argentina@frisk-software.com argentina@f-prot.net argentina@f-prot.co.uk brazil@f-prot.com brazil@frisk.is brazil@complex.is brazil@f-prot.is brazil@frisk-software.com brazil@f-prot.net brazil@f-prot.co.uk malta@f-prot.com malta@frisk.is malta@complex.is malta@f-prot.is malta@frisk-software.com malta@f-prot.net malta@f-prot.co.uk a.bjani@f-prot.com a.bjani@frisk.is a.bjani@complex.is a.bjani@f-prot.is a.bjani@f-prot.co.uk a.bjani@frisk-software.com a.bjani@f-prot.net z.fifl@f-prot.com z.fifl@frisk.is z.fifl@complex.is z.fifl@f-prot.is z.fifl@f-prot.co.uk z.fifl@frisk-software.com z.fifl@f-prot.net strumpuri@complex.is strumpure@complex.is strumpuru@complex.is 00a@eircom.net 0maaahonyy@eircom.net 950@eircom.net af@eircom.net am@eircom.net ar@eircom.net as@eircom.net b1@eircom.net boss3@eircom.net ceih@eircom.net cera@eircom.net chxe@eircom.net cs@eircom.net cydw@eircom.net d71@eircom.net dpfy@eircom.net dzuv@eircom.net ehpa@eircom.net epin@eircom.net f1@eircom.net fa@eircom.net fdld@eircom.net fdnv@eircom.net gacg@eircom.net gafj@eircom.net gc@eircom.net gz@eircom.net ha@eircom.net he@eircom.net ia@eircom.net ja@eircom.net k2@eircom.net lleahy6@eircom.net m1@eircom.net no@eircom.net pb@eircom.net qq@eircom.net r6oo@eircom.net ra@eircom.net s2@eircom.net t2@eircom.net ua@eircom.net va@eircom.net vb@eircom.net w2@eircom.net ww2@eircom.net xxxkiss@eircom.net y1@eircom.net ya@eircom.net zz@eircom.net