Pages

Saturday, September 07, 2002

sophos virus infoW32/Klez-H
Type
Win32 worm

Detection
Detected by Sophos Anti-Virus since March 2002.
The worm searches for email addresses in the Windows address book and also in files with the extensions TXT, HTM, HTML, WAB, ASP, DOC, RTF, XLS, JPG, CPP, C, PAS, MPG, MPEG, BAK, MP3 and PDF.

The email message "From:" field will contain either one of the addresses found in the search or an address taken from a list inside the virus body.

The worm sends itself using emails with the following characteristics:

Subject line:
The subject line is randomly created using one of the following rules.

1.
A combination of "Hi,", "Hello," "Re:", "Fw:", or nothing

with

"Very" and "special" as the first word

and

"New", "funny", "nice", "humour", "excite", "good", "powful", "WinXP" and "IE 6.0" as the second, arranged in one of the following sentences:

"A %s %s game."
"A %s %s tool."
"A %s %s website."
"A %s %s patch."

e.g. "A special powful tool"

51 comments:

  1. VqXCcH The best blog you have!

    ReplyDelete
  2. kosT37 Wonderful blog.

    ReplyDelete
  3. actually, that's brilliant. Thank you. I'm going to pass that on to a couple of people.

    ReplyDelete
  4. Thanks to author.

    ReplyDelete
  5. Thanks to author.

    ReplyDelete
  6. Please write anything else!

    ReplyDelete
  7. Thanks to author.

    ReplyDelete
  8. Please write anything else!

    ReplyDelete
  9. 6VwVbR write more, thanks.

    ReplyDelete
  10. actually, that's brilliant. Thank you. I'm going to pass that on to a couple of people.

    ReplyDelete
  11. Thanks to author.

    ReplyDelete
  12. actually, that's brilliant. Thank you. I'm going to pass that on to a couple of people.

    ReplyDelete
  13. Please write anything else!

    ReplyDelete
  14. Wonderful blog.

    ReplyDelete
  15. Thanks to author.

    ReplyDelete
  16. actually, that's brilliant. Thank you. I'm going to pass that on to a couple of people.

    ReplyDelete
  17. Lottery: A tax on people who are bad at math.

    ReplyDelete
  18. C++ should have been called B

    ReplyDelete
  19. Build a watch in 179 easy steps - by C. Forsberg.

    ReplyDelete
  20. When there's a will, I want to be in it.

    ReplyDelete
  21. What is a free gift ? Aren't all gifts free?

    ReplyDelete
  22. What is a free gift ? Aren't all gifts free?

    ReplyDelete
  23. If ignorance is bliss, you must be orgasmic.

    ReplyDelete
  24. Clap on! , Clap off! clap@#&$NO CARRIER

    ReplyDelete
  25. What is a free gift ? Aren't all gifts free?

    ReplyDelete
  26. Change is inevitable, except from a vending machine.

    ReplyDelete
  27. The gene pool could use a little chlorine.

    ReplyDelete
  28. All generalizations are false, including this one.

    ReplyDelete
  29. Oops. My brain just hit a bad sector.

    ReplyDelete
  30. Change is inevitable, except from a vending machine.

    ReplyDelete
  31. What is a free gift ? Aren't all gifts free?

    ReplyDelete
  32. C++ should have been called B

    ReplyDelete
  33. A lot of people mistake a short memory for a clear conscience.

    ReplyDelete
  34. Wonderful blog.

    ReplyDelete
  35. The gene pool could use a little chlorine.

    ReplyDelete
  36. Thanks to author.

    ReplyDelete
  37. Friends help you move. Real friends help you move bodies.

    ReplyDelete
  38. When there's a will, I want to be in it.

    ReplyDelete
  39. actually, that's brilliant. Thank you. I'm going to pass that on to a couple of people.

    ReplyDelete
  40. Suicidal twin kills sister by mistake!

    ReplyDelete
  41. What is a free gift ? Aren't all gifts free?

    ReplyDelete