Klez set to return--but may backfire

By Robert Lemos, Special to ZDNet
06 September 2002 09:00 AM
Tags: security, virus, klez, infect, variant, mail, payload, pest
A minor variant of the Klez virus is set to go into action tomorrow, erasing a host of files on infected hard drives. But the attack may also wipe out the attacker.

The 8-month-old mass-mailing computer virus called Klez.E triggers its payload on the sixth day of March, May, September and November, erasing 14 different types of files, including Word documents and HTML files.

But the variant has all but disappeared from the Internet, said Vincent Gullotto, director of the antivirus emergency response team at security company Network Associates, and the year's two remaining payloads should call attention to the few computers still infected with Klez.E, allowing the pest to be exterminated.

The Klez.E variant runs a distant second to its far more prevalent Klez.H cousin, making up only 3 percent of the junk e-mail associated with the Klez virus. Klez.H accounts for the other 97 percent.

Data from e-mail services provider MessageLabs shows that in August, the company intercepted 580,000 e-mails carrying the prolific Klez.H variant but only 16,000 carrying Klez.E. On Thursday, the minor Klez variant was present in only 338 infected e-mails in the last 24 hours.

Klez.E arrives in e-mail and uses an old flaw in Microsoft Internet Explorer to execute automatically. On infected PCs, the computer virus activates a malicious payload and overwrites any file accessible to it--both local and on the network-- of the following types: .txt, .htm, .html, .wab, .doc, .xls, .jpg, .cpp, .c, .pas, .mpg, .mpeg, .bak and .mp3.

Klez.H doesn't overwrite files, but it may randomly choose a document from a victimized computer and attach it to the e-mails it sends out to spread itself. In addition, Klez.H spoofs the sender's address to make it look like a random person from the infected PC's address book is actually sending the virus-laden mail. This makes it harder to pinpoint an infected system and can lead to a muddle when people without the pest are told they have it.

Advertisement

Talkback 1 comments

    I'm an oldie and I love the in ...Anonymous -- 11/09/02

    I'm an oldie and I love the internet! You can imagine! Pretend etc! The fact that busines uses the technology, it isn't important! Everytime a virus is created simply re-inforces the view that access etc should be monitored and controlled! (and creates a business in its own way). We're talking traceability to offenders not how clever you are or how much damage you can cause! Forget about fighting to keep it de-regulated! Forget about the innnocent users who are usually the most affected! What is it doing to you're freedom of expression! Eliminating It!!! Like kids in my day throwing stones at a window! When it happens too often, you build an elite block with security guards, and you're on the outside! Those inside can afford to ignore, stop or minimise the effects. So who are you hurting?
    L

Latest Videos

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Suzanne Tindal Sick of broken tender sites
    Some of the state governments desperately need to invest in more user-friendly tender sites so that looking for information on government tenders doesn't have to be a game of blind man's bluff.
  • Array Cyberwar: What is it good for?
    In this week's episode, Cyberwar. What is Australia's place in the world of digital warfare? What are the implications for the NBN?
  • Array Is wholesale-only backhaul just a pipedream?
    The potential acquisition of Pipe Networks by SP Telemedia has raised the question about whether vertically integrated backhaul providers will mean higher wholesale prices for ISP customers.
  • More blogs »

Tags

Back to top

Featured