Advertisement
Promo

Online business Toolkit

Deadlier Klez worm on the prowl

Published: 12 Feb 2002 11:01 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A new variant of the destructive Klez worm has had moderate success, prompting one antivirus company this past weekend to release free tools to deal with its spread.

The variant, carried by email and known as Klez.e, overwrites victims' files with random content on the sixth day of odd-numbered months. It can spread automatically on Windows systems that use an unpatched version of Microsoft's Internet Explorer.

"The latest version, Klez.e, (poses) the most serious threat to computer safety," said Moscow-based antivirus company Kaspersky Labs.

Though antivirus companies discovered the Klez.e variant in late January, its tenacity has prompted Kaspersky Labs to release an antivirus tool to remove it.

Based on how many instances of each worm and virus the company has intercepted in the past 24 hours, UK-headquartered mail service provider MessageLabs ranks Klez.e fourth on its top 10 list, behind Sircam, BadTrans and Magistr -- old worms that continue to plague the Internet. However, the company has intercepted fewer than 400 copies of Klez.e.

In the same 24 hours, BadTrans popped up about 750 times, and Sircam made about 1,600 appearances.

Klez.e arrives in an email message with a subject heading generated from a list of more than 20 keywords or forged to look like the heading on an undelivered message. The body of the message is empty or has random text.

"That's the way it runs automatically, but it still could come onto your system," said Vincent Weafer, senior director of antivirus firm Symantec's security response team. In that instance, a dialogue box would appear, asking computer users if they want to run a program called Klez.e. Users should, of course, click no.

Microsoft patched the IE hole last March, so any Windows system that has been recently updated should be immune to the worm's auto-infecting function. Weafer said Klez is in the top 10 but has caused only one-eighth as many reports as BadTrans.

The worm infects Windows archive files with a copy of itself. It also attempts to circumvent antivirus programs and defeat some competing worms by shutting them down if they're found running.

"It tends to attack the user-interface component, but in most cases the real-time scanner is still active," Weafer said. Antivirus software consists of two basic components: the real-time scanner, which catches viruses that attempt to run, and an application with an interface that allows PC users to scan their machine for infections.

Hence, Klez.e "becomes a pain more than a real threat," Weafer said. Symantec has updated virus definitions that are available to protect against the worm.

Microsoft Windows users should run Windows Update to ensure they are protected against the auto-executing features of this worm.


For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section.

Have your say instantly, and see what others have said. Go to the Security forum.

Let the editors know what you think in the Mailroom.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
66 out of 120 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:









Sentry Posts Blog

Civil liberties groups attack file-sha...

Civil liberties and digital rights organisations have strongly criticised Lord Mandelson's Digital Economy Bill. Liberty said in a position paper on Tuesday that the bill, part of... More

Post a comment

Authentication risks all too human

Risks to successful online banking identification and authentication using smartcards involve a mixture of human and technological factors, according to the European Network and Information... More

1 comment

Opera censors Chinese content

Opera has updated the Chinese version of its mobile browser to stop users accessing restricted content. Opera Mini was updated on Friday from an international to a Chinese version,... More

2 comments

Video icon

Video

Google Chrome

Roundup: Full coverage of Google Chrome

The search giant has launched a beta of its own open-source browser, sending a clear challenge to Microsoft in the way it lets users work with applications More

Blog: Google Chrome has Microsoft's code inside, says MS manager

And furthermore, he says, that's a good thing... More

Blog: Google Chrome — nine things we've found since launch

Google must be very happy with the coverage Chrome has gathered. But it's not all good news... More


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters