Summary
Worm:W32/Klez is a mass-mailer worm which drops a polymorphic EXE virus called ElKern.
Removal
Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.
A False Positive is when a file is incorrectly detected as harmful, usually because its code or behavior resembles known harmful programs. A False Positive will usually be fixed in a subsequent database update without any action needed on your part. If you wish, you may also:
- Check for the latest database updatesFirst, check if your F-Secure security program is using the latest updates, then try scanning the file again.
- Submit a sampleAfter checking, if you still believe the file is incorrectly detected, you can submit a sample of it for re-analysis.Note: If the file was moved to quarantine, you need to collect the file from quarantine before you can submit it.
- Exclude a file from further scanningIf you are certain that the file is safe and want to continue using it, you can exclude it from further scanning by the F-Secure security product.Note: You need administrative rights to change the settings.
Technical Details
Propagation (email)
- Hi
- Hello
- How are you?
- Can you help me?
- We want peace
- Where will you go?
- Congratulations!!!
- Don't cry
- Look at the pretty
- Some advice on your shortcoming
- Free XXX Pictures
- A free hot porn site
- Why don't you reply to me?
- How about have dinner with me together?
- Never kiss a stranger

Variants
- 'HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WinSvc'
- 'I will try my best to kill some virus'
- The worm installs itself to Windows System directory as WINKxxxx.EXE file. The 'xxxx' can be 2-3 random letters. The worm creates an autostarting key for its file in System Registry.
- The worm now has file infection capabilities. When infecting an EXE file, the worm overwrites it and creates a backup file with the same name as the infected file, but with a random extension with hidden, system and read-only attributes. When the infected file is run, the worm extracts the original program from a backup file with its original name plus 'MP8' and runs it. After the program terminates, the worm deletes it. The worm does not infect files with the following names:
- EXPLORER
- CMMGR
- MSIMN
- ICWCONN
- WINZIP
- The worm has network spreading capabilities. The worm enumerates network resources and copies itself to remote drives twice - once as an executable file with single or double extension, and second time as a RAR archive that can have single or double extension as well. The RAR archive contains the worm's executable file with one of the following names:
- setup
- install
- demo
- snoopy
- picacu
- kitty
- play
- rock
- The first extension of the RAR archive or of the worm's executable can be:
- .txt
- .htm
- .html
- .wab
- .doc
- .xls
- .jpg
- .cpp
- .c
- .pas
- .mpg
- .mpeg
- .bak
- .mp3
- The second or the only extension of the worm's executable file can be:
- .exe
- .scr
- .pif
- .bat
- The dropped RAR archive and worm's executable file name is either random or belongs to a file, that a worm found on a host system. So it can be for example QQ.PAS.EXE , KERNEL.MP3.PIF , DOCUMENT.SCR and so on.
- The worm kills tasks of anti-virus and security software as well as tasks of several other worms - Nimda, Sircam, Funlove and CodeRed. The worm opens processes and looks for the specific text strings there. If a specific text string is found in a process, the worm terminates this process. The strings the worm looks for are:
- Sircam
- Nimda
- CodeRed
- WQKMM3878
- GRIEF3878
- Fun Loving Criminal
- Norton
- Mcafee
- Antivir
- Avconsol
- F-STOPW
- F-Secure
- Sophos
- virus
- AVP Monitor
- AVP Updates
- InoculateIT
- PC-cillin
- Symantec
- Trend Micro
- F-PROT
- NOD32
- Also the worm terminates processes with the following names:
- _AVP32
- _AVPCC
- NOD32
- NPSSVC
- NRESQ32
- NSCHED32
- NSCHEDNT
- NSPLUGIN
- NAV
- NAVAPSVC
- NAVAPW32
- NAVLU32
- NAVRUNR
- NAVW32
- _AVPM
- ALERTSVC
- AMON
- AVP32
- AVPCC
- AVPM
- N32SCANW
- NAVWNT
- ANTIVIR
- AVPUPD
- AVGCTRL
- AVWIN95
- SCAN32
- VSHWIN32
- F-STOPW
- F-PROT95
- ACKWIN32
- VETTRAY
- VET95
- SWEEP95
- PCCWIN98
- IOMON98
- AVPTC
- AVE32
- AVCONSOL
- FP-WIN
- DVP95
- F-AGNT95
- CLAW95
- NVC95
- SCAN
- VIRUS
- LOCKDOWN2000
- Norton Mcafee
- Antivir
- TASKMGR
Protect your devices from malware with F‑Secure Total
Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.
- Award‑winning antivirus and malware protection
- Online browsing, banking, and shopping protection
- 24/7 online identity and data breach monitoring
- Unlimited VPN service to safeguard your privacy
- Password manager with private data protection
Choose how many devices you want to protect to get started.
- Free customer support
- Cancel anytime
- The trial does not obligate you to buy the product
After 30 days your subscription will renew automatically for one year at €69.99.
More Support
Community
Ask questions in our Community.
User guides
Check the user guide for instructions.
Contact Support
Chat with with or call an agent.
Submit a Sample
Submit a file or URL for analysis.
)
)