Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > malware problems & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old March 5th, 2002, 01:28 PM
Paul Wilders's Avatar
Paul Wilders Paul Wilders is offline
Administrator
 
Join Date: Jul 2001
Location: The Netherlands
Posts: 12,383
Default Warning: Klez.E worm activates the 6th

the Klez.E email worm will activate destructively tomorrow, on 6th of month. Klez.E is among the ten most common viruses wordwide.

Klez.E was originally found in January 2002. It has been getting steadily more common over the last weeks and by now it has become one of the most common viruses in USA, Europe and Asia.

Klez.E activates on every 6th of the month, but the activations in January and February 2002 were causing relatively small damage. Situation is now more serious.

Klez.E is a very complex virus. It sends itself via e-mail using a wide variety of different messages, including messages which look like virus warnings. Sometimes Klez fakes the e-mail sender, making it look like an
innocent bystander has been spreading the virus. Klez.E also fights against various anti-virus products, trying to delete them.

In addition, the e-mail attachments sent by Klez can execute automatically on some systems, causing infection by just reading or viewing an infected e-mail message.

"Klez.E activation routine is destructive", comments Mikko Hypponen, Manager of Anti-Virus Research at F-Secure. "It overwrites data files such as Word DOC files, Excel XLS files, MP3 music files, website HTML contents
and ASCII text files. Even worse, it does this not only on the infected machine but also in the local network. One infected PC with write access can overwrite data companywide".

The Klez virus family is apparently written by a single virus writer somewhere in Asia, as they contain texts such as "made in Asia", "Well paid jobs are wanted", "I want a good job, I must support my parents", and "I want a salary of $5500 a month".

some screen shots:

http://www.f-secure.com/virus-info/v-pics/klez_e1.jpg

http://www.f-secure.com/virus-info/v-pics/klez_e2.jpg

Thus: take care!

regards.

paul
__________________
01110010 01100101 01100111 01100001 01110010 01100100 01110011 00100000 01110000 01100001 01110101 01101100
  #2  
Old March 5th, 2002, 05:22 PM
wizard's Avatar
wizard wizard is offline
Frequent Poster
 
Join Date: Feb 2002
Location: Europe - Germany - Duesseldorf
Posts: 818
Default Re: Warning: Klez.E worm activates the 6th

Kaspersky has a free removal tool for this virus.

ftp://ftp.kaspersky.com/utils/clrav.zip

wizard
__________________
wizardRESEARCH - Malware Research & Analysis since 1989
 

Wilders Security Forums > Other Security Topics > malware problems & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -5. The time now is 01:27 AM.


Powered by vBulletin® Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2009, Wilders Security Forums