F-Secure: Be Sure
Main
F-Secure Logo - Be Sure
Select local site


Privacy Policy
Legal Notices
Contact Us

F-Secure Virus Descriptions : Klez.H

[Summary] | [Disinfection] | [Detailed Description] | [Detection]

THIS VIRUS IS RANKED AS LEVEL 2 ALERT UNDER
F-SECURE RADAR.

Radar Alert LEVEL 2

NAME:Klez.H
ALIAS:I-Worm.Klez.H, W32/Klez.H, Klez.K (Messagelabs)
ALIAS:Klez.G (Trend), W95/Klez.H@mm

Summary

The new version of the Klez worm has been found from various parts of Asia on April 17th, 2002. A week after its discovery Klez.H is still globally spread. This worm, like its previous versions sends e-mail messages with randomly named attachments and subject fields.

The Klez.H variant it quite close to Klez.E, F and G worm variants. The descripions of Klez.E, F and G variants can be found here:

http://www.europe.f-secure.com/v-descs/klez.shtml

Here is a screenshot showing what Klez messages could look like:

Disinfection

Disinfection tool

Disinfection of Klez.H worm can be performed with the special tool that is available on our ftp site:

ftp://ftp.europe.f-secure.com/anti-virus/tools/kleztool.zip

Please read the KLEZTOOL.TXT file included in the ZIP archive before using the tool.

Removal help with Video

We have produced an online video showing step-by-step how to get rid of the Klez worm.

View the video (Real) from here: http://www.f-secure.com/virus-info/video/klez.ram

You can download RealPlayer from here:

http://www.real.com/player/index.html?lang=en

For feedback on the video or further questions, contact support@f-secure.com

Back to the Top


Detailed Description

F-Secure Virus Research Team found the following differences in Klez.H variant comparing to its previous versions:

1. There's no payload routine.

2. The .PDF extension was added to the list of extensions that the worm uses to make a double-extension name for its file.

3. The worm sometimes uses social engineering approach in its spreading and sends the following message with its own file attached:

Subject:

 Worm Klez.E immunity

Body:

 Klez.E is the most common world-wide spreading worm.It's very
 dangerous by corrupting your files.
 Because of its very smart stealth and anti-anti-virus
 technic,most common AV software can't detect or clean it.
 We developed this free immunity tool to defeat the malicious
 virus.
 You only need to run this tool once,and then Klez will never
 come into your PC.
 NOTE: Because this tool acts as a fake Klez to fool the real
 worm,some AV monitor maybe cry when you run it.
 If so,Ignore the warning,and select 'continue'.
 If you have any question,please mail to me.

The 'mail to me' is represented as a link to the sender's e-mail address. Note that this address is not always the real sender's address.

4. The worm contains a new text message from its author. This text is never displayed:

 Win32 Klez V2.01 & Win32 Foroux V1.0
 Copyright 2002,made in Asia
 About Klez V2.01:
 1,Main mission is to release the new baby PE virus,Win32 Foroux
 2,No significant change.No bug fixed.No any payload.
 About Win32 Foroux (plz keep the name,thanx)
 1,Full compatible Win32 PE virus on Win9X/2K/NT/XP'
 2,With very interesting feature.Check it!
 3,No any payload.No any optimization'
 4,Not bug free,because of a hurry work.No more than three weeks
   from having such idea to accomplishing coding and testing'

5. The worm drops the new Elkern virus variant. Unlike the previous Klez versions, Klez.H puts the virus dropper into \Program Files\ folder with a random name and activates it.

6. The worm added 2 more names to the list of anti-virus companies that it previously had. These new names are:

	Trendmicro
	Kaspersky

These names are used by the worm to compose messages when it sends itself as a virus removal tool from anti-virus companies.

7. It was also noticed that latest Klez variants including Klez.H can send out user's files with its message. The worm can randomly pick up a file with one of the following extensions and attach it to its infected message:

 .txt
 .htm
 .html
 .wab
 .asp
 .doc
 .rtf
 .xls
 .jpg
 .cpp
 .c
 .pas
 .mpg
 .mpeg
 .bak
 .mp3
 .pdf

So in some cases user's confidential data can be sent out from an infected system.

Back to the Top


Detection

Detection in F-Secure Anti-Virus was published on April 17th, 2002:

[FSAV_Database_Version]

Version=2002-04-17_03

Back to the Top


Technical Details: Alexey Podrezov

Description Updated: F-Secure Anti-Virus Research Team, April 17th-22nd, 2002

F-Secure Corporation