Skip to main content

Kaspersky Lab has detected a new variant of Zhelatin spreading

February 6, 2007

Kaspersky Lab, a leading developer of secure content management solutions, has detected that Email-Worm.Win32.Zhelatin.o is spreading rapidly. The worm spreads as an attachment to email messages.

Kaspersky Lab, a leading developer of secure content management solutions, has detected that Email-Worm.Win32.Zhelatin.o is spreading rapidly. The worm spreads as an attachment to email messages.

The worm, which was detected by Kaspersky Lab virus analysts, is the latest modification in the Zhelatin family. Just like many other email worms, it uses social engineering, with message topics and subjects being designed to attract users' attention and cause them to open the attachment.

When the attachment is opened, the worm copies itself to the hard disk; it will be automatically launched when the victim machine is rebooted. The worm also harvests email addresses from the victim machine, and sends copies of itself to these addresses. As part of its malicious payload, the worm also disables firewall and antivirus services on the infected computer. It uses rootkit technology in order to mask the worm's presence in the system. Zhelatin.o also infects executable files (.exe) and files with the .scr extension which it finds in the system by copying its code to these files.

It should be noted that the Proactive Detection Module in Kaspersky Anti-Virus 6.0 and Kaspersky Internet Security 6.0 blocks the virus without using signatures. Nevertheless, detection and disinfection routines for this malicious program have been added to Kaspersky Anti-Virus antivirus databases. Due to this epidemic, users are recommended to update their antivirus databases, and not to open attachments to email messages which come from unknown users.

A detailed description of Zhelatin.o is available on Viruslist.com.

Kaspersky Lab has detected a new variant of Zhelatin spreading

Kaspersky Lab, a leading developer of secure content management solutions, has detected that Email-Worm.Win32.Zhelatin.o is spreading rapidly. The worm spreads as an attachment to email messages.
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect individuals, businesses, critical infrastructure, and governments around the globe. The company’s comprehensive security portfolio includes leading digital life protection for personal devices, specialized security products and services for companies, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help millions of individuals and nearly 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Related Articles Press Releases