Feeds

Newmedia agency cleared of spreading worm

Klez-E is as cunning as a Fox

  • alert
  • submit to reddit

Intelligent flash storage arrays

Updated Subscribers to a mailing list on news about 20th Century Fox received an unwelcome release yesterday when they were sent a copy of the Klez-E worm.

The infection-bearing email appeared to come from fox-news@lists.foresight.co.uk, prompting Reg readers to conclude that some breach of security at the new media agency was responsible for the spread of the pathogen.

Although a techie at Foresight told us earlier today that the worm was sent out after vandals broke into a Linux server that was used to run the list up until February 2000, this turns out to be incorrect.

Further investigation by Foresight of its Internet logs reveals it did not send out any virus. Foresight uses email screening services from Star Internet which means any virus coming from its email server would be blocked before reaching any of the 30,000 people on the list, which is now run by 20th Century Fox - not Foresight.

Klez-E, a damaging worm which normally spreads by email, has the ability to spoof the destination it comes from, AV experts at Sophos confirm.

It seems the virus infected the Windows box of a user who had fox-news@lists.foresight.co.uk in his Outlook contact list, and it then spread itself to other addresses in that user's email address book. It did this with Foresight's email address in the 'From' field, so the worm appeared to come from Foresight's servers even though its systems remained free of infection.

Fiendishly nasty things, these viruses... ®

Related Stories

Undead virus infects the dim-witted
Klez-E worm triggers today

Top 5 reasons to deploy VMware with Tegile

Whitepapers

Choosing cloud Backup services
Demystify how you can address your data protection needs in your small- to medium-sized business and select the best online backup service to meet your needs.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.
Reg Reader Research: SaaS based Email and Office Productivity Tools
Read this Reg reader report which provides advice and guidance for SMBs towards the use of SaaS based email and Office productivity tools.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.