Klez.e worm threat fizzles

By David Becker, CNET News.com
Thursday, March 07, 2002 11:07 AM
The Klez.e worm packed a miniscule punch after it activated Wednesday, with antivirus companies reporting little or no damage from the pest.

The worm, which began spreading through e-mail messages in early February, is set to activate on infected PCs on the sixth day of odd-numbered months, potentially triggering a barrage of activity that would destroy many common types of PC files.

By late Wednesday morning, however, antivirus-software company Symantec had no reports of PCs being damaged by the worm, said Sharon Ruckman, senior director of the company's Security Response center.

Reports of the worm spreading via e-mail had increased in the past few days, though, prompting Symantec to boost the threat rating for Klez.e on Wednesday from Level 2 to 3, on a scale of 5.

The assessment was similar from antivirus-software maker Trend Micro, which ranked Klez.e as the 12th most active worm on the Internet, well behind more robust pests such as the Sircam and Nimda worms.

"Apparently, it's pretty much a no-show," said David Perry, public education director for Trend Micro.

Klez.e's weak punch was largely attributed to there being almost a full month between the time the worm appeared and when it went active, allowing people plenty of time to update their antivirus software and stomp out the pest.

"The more time we have, the better it is," Ruckman said. "People have more of a chance to get updated."

Perry added that Klez.e was fairly unsophisticated for a modern e-mail worm, enabling a more thorough response. "For this kind of thing, we have much better protection than a year ago."

Perry noted that Wednesday's Klez.e scare occurred 10 years to the day after the first major virus panic of the PC era, the Michelangelo virus that sent PC owners into a tizzy on March 6, 1992. "It's kind of nostalgic for those of us in the antivirus field," he said.

Meanwhile, a new worm that poses as a Microsoft security update was showing little signs of spreading. The Gibe worm arrives attached to an e-mail message supposedly from Microsoft with the subject "Internet Security Update." Recipients are instructed to open the attached file--named "Q216309.exe"--to install patches for recently discovered security holes in Microsoft products. In reality, the file creates programs that help the worm spread via e-mail and leave the infected PC vulnerable to hackers.

Symantec had received reports from fewer than 50 users infected by the Gibe worm as of midday Wednesday, leading it to categorize the pest as a Level 2 threat.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Hands-on programming: Extract plain text from documents with Syncfusion's components

Web Development

Justin James recently tried Syncfusion's Essential DocIO and Essential PDF to help him extract text from documents he downloaded from the Internet. Here's the code he wrote to get the plain text.


Read more »



Will technology divide us further?

Blog thumbnail

So I finally watched 2012 over the weekend, but the film left me feeling extremely agitated.

The possibility that the world may meet its watery end in three years didn't..... by Eileen Yu

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web