Computing.Net > Forums > Security and Virus > Klez : How it works.

Klez : How it works.

Reply to Message Icon

Original Message
Name: Syed Imran Ali
Date: August 5, 2002 at 02:45:25 Pacific
Subject: Klez : How it works.
Comment:

The Klez worm is approaching its seventh month of wriggling across the Web, making it one of the most persistent viruses ever. And experts warn that it may be a harbinger of new viruses that use a combination of pernicious approaches to go from PC to PC.

Antivirus software makers Symantec and McAfee both report more than 2000 new infections daily, with no sign of letup at press time. The British security firm MessageLabs estimates that 1 in every 300 e-mail messages holds a variation of the Klez virus, and says that Klez has already surpassed last summer's SirCam as the most prolific virus ever.

And some newer Klez variants aren't merely nuisances--they can carry other viruses in them that corrupt your data.

How It Works

Klez is an example of a blended threat: software that distributes itself like a virus but sometimes behaves like a worm and at other times like a Trojan horse. (See "How It Works: Viruses" for more on different virus types.) Klez usually arrives in the in-boxes of unsuspecting victims as a file attachment. It uses various subject lines, including "Klez removal tool". (For the real tool, visit our Downloads library.) Some variants also draw subject lines from random words in files on a victim's hard drive.

When the victim double-clicks the attachment, or even just previews the message, the fun begins for Klez. It pilfers addresses from the victim's e-mail address books, and also searches the hard drive for addresses from the Web browser cache or temporary files.

What makes Klez particularly insidious is that it draws both a new sender and a new recipient from the infected party's sources. This creates at least three victims: the person who first got the worm, the one who is sent the worm, and the one whose address was taken from the original victim and is used as the new sender (see "Klez's Path of Infection").

Because the infected sender's address is not on the new e-mail, the worm is difficult to track. And blocking the return address is ineffective, because that person didn't send the worm. Worse, the innocent sender may well be someone you know, making you more likely to open the message, click on the attachment, and perpetuate the virus.

"These types of social-engineering tricks are extremely effective," says virus researcher Sarah Gordon. People don't want to ignore a friend or colleague, she says. "They feel compelled to look at an attachment--even though they've heard the warning."

In the months since Klez was first identified, antivirus vendors have discovered seven versions of the virus. These strains share many behavioral traits but act slightly differently from one another. For example, some later versions can attack other systems over networks by copying infected files to file servers and shared hard drives. One of the newest variants, W32.Klez.H@mm, contains another worm called ElKern that can damage an operating system beyond repair. In some instances, users must reformat the entire hard drive and reinstall Windows to purge the virus from a PC.

Can You Fight Back?

With these types of blended threats, it's not enough just to update your antivirus software's data definitions regularly; you need comprehensive security protection, including both privacy and intrusion protection, according to Vincent Weafer, senior director of Symantec Security Response. Users who also make it a habit to install new security patches are better equipped to defend their PCs against the kinds of worms that attack well-known Windows weaknesses.

But even if you take all appropriate measures, others who have your e-mail address in their books may not. You won't get the worm, but you will still get neutralized and irritating notes in your in-box.

There's little you can do to prevent such e-mail from reaching you; however, your ISP may be able to help. Some ISPs use so-called antivirus appliances that are capable of filtering millions of messages and stopping infected ones from getting to your in-box.

But ultimately, each of us who uses a PC is responsible, in a small way, for preserving our neighbors' security--by keeping our own PC clean.



Report Offensive Message For Removal


Response Number 1
Name: sirkitmain
Date: August 5, 2002 at 04:53:10 Pacific
Subject: Klez : How it works.
Reply: (edit)

...on behalf of all, thank you Syed for your detailed and informative post. It's a serious warning to us all not to be complacent. i have recently had several emails with the W32.Klez.H@mm virus. Fortunately Norton detected them, and i did not open the attachments. The source of the infection, i am told in this case, came from a local golf club. Was somebody 'blackballed'?!...


Report Offensive Follow Up For Removal

Response Number 2
Name: Hellsbells
Date: August 5, 2002 at 10:00:00 Pacific
Subject: Klez : How it works.
Reply: (edit)

Thanks - got it 2 weeks ago, NAV saved me but m still getting returned messages I didn't send.Can i stop these????


Report Offensive Follow Up For Removal

Response Number 3
Name: Hellsbells
Date: August 5, 2002 at 11:38:57 Pacific
Subject: Klez : How it works.
Reply: (edit)

Sorry, but where did you get the info so I can follow the links mentioned?


Report Offensive Follow Up For Removal

Response Number 4
Name: dsbal
Date: August 6, 2002 at 16:07:04 Pacific
Subject: Klez : How it works.
Reply: (edit)

Klez is just a pain in the you-know-what. I started getting Klez many months ago, and began saving the files just to see how many I'd get. For those of you that receive it regularly, it probably comes as no surprise I receive it 1-2 times PER DAY. And it is hard to track, but no impossible. If the infected user has set his email software to show a different return path than his default path, you can often view the details of the email to see just who is infected. In my case, a co-worker who just laughs it off. He KNOWS his system is infected, but can't take the time to cleanse it. Others have complained to him also, but to no avail. I find myself secrectly wishing his system is eventually disabled, and he has to format. Especially when I get emails from other less informed users in his address book chastising ME for sending them a virus>


Report Offensive Follow Up For Removal

Response Number 5
Name: michelle mcafee
Date: August 8, 2002 at 07:31:35 Pacific
Subject: Klez : How it works.
Reply: (edit)

i had this virus and was able to remove but im having trouble with system since this happend,i am having page file to small and every time i start program it says fail to initialize ...can this be part of the virus????


Report Offensive Follow Up For Removal







Use following form to reply to current message:

   Name: From My Computing.Net Settings
 E-Mail: From My Computing.Net Settings

Subject: Klez : How it works.

Comments:

 


  Homepage URL (*): 
Homepage Title (*): 
         Image URL: 
 
Data Recovery Software




How often do you use Computing.Net?

Every Day
Once a Week
Once a Month
This Is My First Time!


View Results

Poll Finishes In 3 Days.
Discuss in The Lounge