ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Online business Toolkit

Deadlier Klez worm on the prowl

Published: 12 Feb 2002 11:01 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new variant of the destructive Klez worm has had moderate success, prompting one antivirus company this past weekend to release free tools to deal with its spread.

The variant, carried by email and known as Klez.e, overwrites victims' files with random content on the sixth day of odd-numbered months. It can spread automatically on Windows systems that use an unpatched version of Microsoft's Internet Explorer.

"The latest version, Klez.e, (poses) the most serious threat to computer safety," said Moscow-based antivirus company Kaspersky Labs.

Though antivirus companies discovered the Klez.e variant in late January, its tenacity has prompted Kaspersky Labs to release an antivirus tool to remove it.

Based on how many instances of each worm and virus the company has intercepted in the past 24 hours, UK-headquartered mail service provider MessageLabs ranks Klez.e fourth on its top 10 list, behind Sircam, BadTrans and Magistr -- old worms that continue to plague the Internet. However, the company has intercepted fewer than 400 copies of Klez.e.

In the same 24 hours, BadTrans popped up about 750 times, and Sircam made about 1,600 appearances.

Klez.e arrives in an email message with a subject heading generated from a list of more than 20 keywords or forged to look like the heading on an undelivered message. The body of the message is empty or has random text.

"That's the way it runs automatically, but it still could come onto your system," said Vincent Weafer, senior director of antivirus firm Symantec's security response team. In that instance, a dialogue box would appear, asking computer users if they want to run a program called Klez.e. Users should, of course, click no.

Microsoft patched the IE hole last March, so any Windows system that has been recently updated should be immune to the worm's auto-infecting function. Weafer said Klez is in the top 10 but has caused only one-eighth as many reports as BadTrans.

The worm infects Windows archive files with a copy of itself. It also attempts to circumvent antivirus programs and defeat some competing worms by shutting them down if they're found running.

"It tends to attack the user-interface component, but in most cases the real-time scanner is still active," Weafer said. Antivirus software consists of two basic components: the real-time scanner, which catches viruses that attempt to run, and an application with an interface that allows PC users to scan their machine for infections.

Hence, Klez.e "becomes a pain more than a real threat," Weafer said. Symantec has updated virus definitions that are available to protect against the worm.

Microsoft Windows users should run Windows Update to ensure they are protected against the auto-executing features of this worm.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
66 out of 120 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:









Related Jobs

Security Document Manager

Contribute to the review and implementation of updated Information and Network Security Oversight Ensure that Information and Security Processes and ...

SAN / Storage Lead - EMC

Short Description: Enterprise Labs is the standard organisation to facilitate all non-production server environments within the corporation. Housing ...

Application Developer Middleware

All applicants must have hands-on experience in using both IBM WebSphere MQ and WebSphere Message Broker. Desired experience Ideally candidates will ...

Sentry Posts Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Skype - The Roach Motel

Here is an interesting article from The National Business Review, pointing out once again that you can never delete a Skype account. Never. Period. This is something I am familiar... More

Post a comment

The vPhone: Why Visa Should Go Mobile

The vPhone: Why Visa Should Go Mobile Author: Eric Everson, Founder MyMobiSafe.com With all of the success of Apple’s iPhone, there is a growing case to support a company like Visa... More

Post a comment

Featured Talkback

I wonder, who needs .asia domain? I cannot imagine, what would be useful for Microsoft.asia? Toyota.asia? Then let's register .europe (if .eu is too short). Or perhaps Microsoft.southamerica, Dell.australiaandnewzealand, Coca-Cola.africa... Sound funny? Then why not just use the global and country domains? Or perhaps it is time to drop the domains at all?

By: LadyRoot

Read full story:
Businesses advised to register .asia domains