Klez worm refuses to die

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

NEWS
It may only be a matter of time before you're accused of spreading the Klez virus. A month after it started spreading, the Klez.h worm isn't slowing down, said antivirus experts on Friday. Moreover, the worm's technique of forging the address of the sender on each infected e-mail message is creating a flood of warnings from gateway antivirus software informing the wrong people that they are infected. "A lot of traffic is being multiplied by the response mechanisms and refusal mechanisms," said Fred Cohen, security practitioner in residence at the University of New Haven in the US. In many cases, antivirus software protecting a company's e-mail gateways is sending out a response to each infected e-mail inadvertently sent out by a victim -- but that warning is going to the wrong person. "So, in effect, you're getting twice the fun you would normally get," Cohen said. Apart from magnifying the amount of spam produced by the virus, the incorrect identification of those who are infected is also responsible for hindering efforts to fight the spread of the worm, said Cohen. Faked addresses
The Klez.h variant, which appeared in mid-April, infects PCs whose users open the attachment to an infected e-mail. Confusing matters, the e-mail will have a random "from" address, selected from various sources on the original victim's hard drive. And it pairs this bogus sender's address with one of more than 120 different subject lines. When a user opens the attachment, the virus starts up its own e-mail engine and mass mails itself to e-mail addresses found in various files on the PC, using a source address culled from those addresses. Klez.h can also send out a random file from the PC as an attachment, along with the e-mail that carries the worm, potentiall passing confidential information. In some instances, the worm also drops one of several other viruses, including the destructive CIH, and tries to remove any active antivirus software from the system. Overall, the Klez.h variant has been extremely successful. "The spread has been really steady," said John Harrington, director of US marketing for e-mail service provider MessageLabs. "We've seen 20,000 again today (Friday), and there's no indication that this is dying down." While the worm has not spread as quickly as, say, the LoveLetter virus--of which MessageLabs received one copy for every 23 legitimate e-mails during the virus' peak in May 2000 -- it does make up one out of nearly every 170 e-mails, Harrington said. In fact, the steady spread -- rather than a firestorm of e-mails--may actually be part of the reason for the worm's success, said Harrington. The Klez.h variant did manage to top the charts of computer viruses in April. "It kind of cruises below the radar screen," Harrington said. "Everyone had heard of LoveLetter. But if you go into a computer shop and ask people if they've heard of Klez, they'll shake their heads." Hard to track
The Klez variant's ability to spoof the source of infected e-mail makes it nearly impossible to track down the infected users who sent the virus. "The whole spoofing thing adds a dimension to it that is a little different," said Vincent Gullotto, vice president of Network Associates' antivirus emergency response team. "It's definitely possible that the false addresses are slowing response." Network Associates still receives more than 50 reports a day of the worm from customers, and some corporate clients are seeing more than 20,000 messages carrying the virus at their e-mail gateways. The response to Klez -- that uninfected users are being told they sent a virus -- shows the holes in the system, added Gullotto. In addition, some out-of-the-office auto-reply mechanisms may be going haywire as a result of an infected user sending an e-mail with a random source and receiver who are both away. "I am sure there are some auto-reply wars that have been going on," Gullotto said. "There has been a lot of mail that is going around that is caused by this." Until system administrators disable antivirus notification on the e-mail gateway servers, the confusion will only continue.
For all security-related news, including updates on the latest viruses, hacking exploits and patches, check out ZDNet UK's Viruses and Hacking News Section. Have your say instantly, and see what others have said. Go to the Security forum. Let the editors know what you think in the Mailroom.

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

BrownieBoy

@Jack, > Works really well for thieves.... Nice attempt to deflect the argument by tossing in a point that's totally irrelevant, even it were...

3 hours ago by BrownieBoy on AMD Ultrathins to challenge Intel Ultrabooks
bootlegger

Make that 13 people now - I got refused today at Manchester airport. I thought I was up to date on this legislation - I knew of the EU ruling from...

6 hours ago by bootlegger on UK airport body scans will not be opt out
tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

8 hours ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

13 hours ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

23 hours ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

1 day ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

1 day ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

1 day ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

1 day ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

2 days ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 days ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

2 days ago by JCB33 on ACTA stumbles in Germany
Moley

@GrueMaster. I prefer horses for courses rather than one size fits all. I, and I suspect most other computer users, do not really wish to have...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
greycynic

The product that scares me every time I have to use it is the Office 2007 version of Excel. The first bug that I found was applying the median...

2 days ago by greycynic on Ten flawed products that derail productivity
GrueMaster

Nice review and very informative. One thing I'd like to add (in reply to whs001's 1st question), the main reason to have the same interface from...

2 days ago by GrueMaster on A tale of two distros: Ubuntu and Linux Mint
Frederick Wrigley

I'be been using Mint 12 since the RC came out, and I am far more happy with the Cinnamon, the Mate, and, yes (with extensions), theGnome 3...

2 days ago by Frederick Wrigley via Facebook on A tale of two distros: Ubuntu and Linux Mint