This new version of the Klez worm has been found from various parts of Asia on April 17th, 2002. A week after its discovery Klez.H is globally spread. This worm, like its previous versions sends e-mail messages with randomly named attachments and subject fields.
Once detected, the F-Secure security product will automatically disinfect the suspect file by either deleting it or renaming it.
We have produced a video showing step-by-step how to get rid of the Klez worm. View the video at: http://www.f-secure.com/virus-info/video/klez.ram
Note: The video requires RealPlayer to view. You may download RealPlayer from: http://www.real.com/player/index.html?lang=en
The Klez.H variant it quite close to previous variants Klez.E, F and G.
Here is a screenshot showing what Klez messages could look like:
F-Secure Virus Research Team found the following differences in Klez.H variant compared to its previous versions:
Subject: Worm Klez.E immunity Body: Klez.E is the most common world-wide spreading worm.It's very dangerous by corrupting your files. Because of its very smart stealth and anti-anti-virus technic,most common AV software can't detect or clean it. We developed this free immunity tool to defeat the malicious virus. You only need to run this tool once,and then Klez will never come into your PC. NOTE: Because this tool acts as a fake Klez to fool the real worm,some AV monitor maybe cry when you run it. If so,Ignore the warning,and select 'continue'. If you have any question,please mail to me.The 'mail to me' is represented as a link to the sender's e-mail address. Note that this address is not always the real sender's address.
Win32 Klez V2.01 & Win32 Foroux V1.0 Copyright 2002,made in Asia About Klez V2.01: 1,Main mission is to release the new baby PE virus,Win32 Foroux 2,No significant change.No bug fixed.No any payload. About Win32 Foroux (plz keep the name,thanx) 1,Full compatible Win32 PE virus on Win9X/2K/NT/XP' 2,With very interesting feature.Check it! 3,No any payload.No any optimization' 4,Not bug free,because of a hurry work.No more than three weeks from having such idea to accomplishing coding and testing'