Welcome, Guest. Please login or register.

Author Topic: Virus Top 10: Klez still can't be shaken  (Read 1227 times)

Description:

0 Members and 1 Guest are viewing this topic.

Offline SkippyTopic starter

  • Hero Member
  • *****
  • Join Date: Jun 2002
  • Posts: 710
    • Show only replies by Skippy
Virus Top 10: Klez still can't be shaken
« on: March 03, 2003, 03:07:34 PM »
Klez has claimed a remarkable thirteenth month in the top 10 list of most frequently occurring viruses - raising concerns about the vigilance of IT managers and administrators charged with updating their company's anti-virus software.

For the full story visit: Silcon

Squareroot of all fluffiness.
 

Offline Hardboy

  • Full Member
  • ***
  • Join Date: Feb 2002
  • Posts: 248
    • Show only replies by Hardboy
Re: Virus Top 10: Klez still can't be shaken
« Reply #1 on: March 03, 2003, 04:18:38 PM »
Is this me, or is this virus Yet-Another-Made-In-VB-Virus-And-Is-Only-Spread-Because-People-Use-MSOutlook ??
 

Offline odin

  • Colonization had Galleons
  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 6796
    • Show only replies by odin
Re: Virus Top 10: Klez still can't be shaken
« Reply #2 on: March 03, 2003, 05:25:42 PM »
Yup, and cos ppl dont use their virus scanners.

Offline DanDude

  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 505
    • Show only replies by DanDude
Re: Virus Top 10: Klez still can't be shaken
« Reply #3 on: March 03, 2003, 05:39:06 PM »
Haha, I'm still using my Amiga for emails!
#AmIRC
mesra.dal.net or hotspeed.dal.net
irc2.beyondirc.net
 

Offline Elektro

  • Hero Member
  • *****
  • Join Date: Feb 2002
  • Posts: 1424
    • Show only replies by Elektro
Re: Virus Top 10: Klez still can't be shaken
« Reply #4 on: March 03, 2003, 10:21:32 PM »
Or eat chicken soup.
#amiga.org @ irc.synirc.net
 

Offline Waccoon

  • Hero Member
  • *****
  • Join Date: Apr 2002
  • Posts: 1057
    • Show only replies by Waccoon
Re: Virus Top 10: Klez still can't be shaken
« Reply #5 on: March 04, 2003, 12:20:08 AM »
Quote
Hardboy:  Is this me, or is this virus Yet-Another-Made-In-VB-Virus-And-Is-Only-Spread-Because-People-Use-MSOutlook ??

Not as far as I know.  I get this virus e-mailed to me five times a day, and it doesn't cause any major warnings, VB scripting, or ActiveX requests in Outlook Express.  After two years of no problems, I finally bought Norton Antivirus just to be safe, and found no viruses on my computer.  I've never gotten a virus just by downloading mail from my mail server, although I heard that it can happen.

Mostly, it's just the same old crap:  people being stupid and running executable files they get in their mail.  Actually, Klez spreads itself as a PIF, but it is really an executable.  PIFs are Program Information Files, and are normally links to executables.  You still have to "run" it to get the virus.

What really ticks me off is that Klez spoofs the "From" address, so the address that shows up in the "From" line might not be from the computer that sent the e-mail.  Klez is a real pain

BTW, what does Klez *DO*?
 

Offline csirac_

  • Full Member
  • ***
  • Join Date: Feb 2002
  • Posts: 154
    • Show only replies by csirac_
Re: Virus Top 10: Klez still can't be shaken
« Reply #6 on: March 04, 2003, 09:14:16 AM »
Klez is a mass mailer, as you have observed, it spreads, infects other files, corrupts files and ultimately causes much system instability. I'm sure I've seen klez ultimately it destroy data on customer's HDDs; When it is finally triggered to be destructive, you get a colourful screen spewing garbage ascii on bootup and it basically sits there corrupting your drive, I think, but this is from symantec (there are many varients of Klez, this is one of them):

"Payload: This worm infects executables, by creating a hidden copy of the original host file, and then by overwriting the original file with itself. The hidden copy is encrypted, but contains no viral data. The name of the hidden file is the same as the original file, but with a random extension.

    * Large scale e-mailing: This worm searches the Windows address book, the ICQ database, and local files for email addresses. The worm sends an email message to these addresses with itself as an attachment.
    * Releases confidential info: Worm randomly chooses a file from the machine to send with the worm to recipients. So, the files with the extensions: ".mp8", ".txt", ".htm", ".html", ".wab", ".asp", ".doc", ".rtf", ".xls", ".jpg", ".cpp", ".pas", ".mpg", ".mpeg", ".bak", ".mp3", or ".pdf" would be attached to the email messages with the viral attachment."
 

Offline System

  • Full Member
  • ***
  • Join Date: Jul 2003
  • Posts: 199
    • Show only replies by System
    • http://amiga.org
Re: Virus Top 10: Klez still can't be shaken
« Reply #7 on: March 05, 2003, 11:35:08 AM »
For those of U that uses Amiga, your have nothing to fear. This is an PC/Windows virus. There is NO way that it can infect an Amiga