
Klez.E Worm
Information
about Klez.E worm:
Klez.E
is modified variant of original Klez
worm. Klez.E variant rapidly spreads in
the wild. I-worm/Klez.E arrives as
an e-mail attachment. The attachments are
embedded within the e-mail and it won't
visible to the user.
When the user
views the attachment the embedded code is
executed automatically and it drops the
virus. Microsoft released security
patches to close this security hole. If
you haven't installed, you can get a copy
at http://www.microsoft.com/windows/ie/download/critical/Q290108/default.asp
Klez.e uses its
own SMTP to e-mail infected messages.The
message body will be empty or it will
contain a random text. The subject will
be one of the following.
Hi,
Hello,
Re:
Fw:
how are you
let's be friends
darling
don't drink too much
your password
honey
some questions
please try again
welcome to my hometown
the Garden of Eden
introduction on ADSL
meeting notice
questionnaire
congratulations
sos!
japanese girl VS playboy
look,my beautiful girl friend
eager to see you
spice girls' vocal concert
Japanese lass' sexy pictures
When executed
Klez.e installs itself into a Windows
system file with a random name beginning
with 'Wink,' for example, 'Winkad.exe.'
Klez contains a deadly payload, when
activated it will overwrite the files
with random text. It also deletes well
known antivirus programs form the
infected machine.
Removing
Klez.E worm from your system:
Fire has
incorporated I-Worm/Klez in its signature
file to protect Fire users from this worm
attack. Fire anti-virus users can update
this signature file by using online
update facility. It is available
with the registered version of Fire
anti-virus Kit.
If you
are already infected with this worm,
download and install security patches
from the link http://www.microsoft.com/windows/ie/download/critical/Q290108/default.asp according to
your Internet Explorer version. Then run
registered version of Fire anti-virus and
choose delete option to remove the worm
components.
A
free download
of FireLite
[ 1100KB]
version is also available to detect
I-Worm/Klez.E. Fire anti-virus
kit removes I-Worm/Klez.E without
problems. If you find this worm,
use registered version of Fire to remove.
To get the registered version of Fire
call us at 044-8170440, 8171082 or mail
to service@fireav.com
or
purchase Fire online using
[Analysis:
Mr.Ramesh, Mr. Stanley Rakesh, Prognet
Technologies Pvt. Ltd, Feb. 2002]

|