The Register® — Biting the hand that feeds IT

Feeds

Klez storms monthly virus charts

Klutzes infected by virus variants

  • print
  • alert

Regcast training : Hyper-V 3.0, VM high availability and disaster recovery

Variants of the Klez worm were by far the most common viruses circulating on the Internet this month.

That's according to monthly statistics from managed services firm MessageLabs, which stopped 422,507 viruses in April, way up on the 161,904 it blocked in March, after a mercifully quiet start to the year in terms of virus infections. MessageLabs reports that virus infection rates are currently running at around one per 265 emails, which compares to one in 30 infected emails at the heights of the Goner and Love Bug epidemics.

Antivirus vendors such as Symantec have recently upgraded the threat level posed by Klez, but the worm is more accurately described as the latest high-profile virus rather than one of the most damaging.

In the last four weeks MessageLabs blocked 251,171 emails infected with Klez-H, with 40,239 SirCam infection-bearing emails stopped, and Klez-E (37,831) also featuring prominently in its monthly chart.

Klez is a mass-mailing worm that searches the Windows address book for email addresses and sends messages to all recipients that it finds. The worm uses its own SMTP engine to send the messages.

The subject and attachment name of incoming emails is randomly chosen, making it harder for users to spot. The attachment will have one of the following extensions: .bat, .exe, .pif or .scr. Klez is capable of infecting files.

The worm exploits a vulnerability in Microsoft Outlook and Outlook Express in an attempt to execute itself when you open or even preview the message. Information and a patch for the vulnerability can be found here. ®

Top ten viruses blocked by MessageLabs in April


  1. Klez-H
  2. SirCam
  3. Klez-E
  4. Magistr-B
  5. Hydris-B
  6. Magistr-A
  7. BadTrans-B
  8. Vavidad.E1
  9. Yaha-A
  10. MyLife-J


External Links

Analysis of the spread of the Klez-H worm by MessageLabs

Related Stories

Cisco and Sophos spoofed in virus mail-outs
Klez worm infects and infuriates
All quiet on the malware front
Bill Clinton virus proves user security sucks
Thousands of idiots still infected by SirCam
SirCam virus hogs connections with spam
Hybrid viruses set to become bigger threat
MS security memo a mere gesture
Users haven't learned any lessons from the Love Bug
Rise in viruses within emails outpacing growth of email
A plague on all our networks
AV vendors sell 'blunt razor blades'
Virus writers outpace traditional AV

Agentless Backup is Not a Myth

More from The Register

 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?
 breaking news
'BadNews is malware' says outfit that found it
Google says code harmless but Lookout says code base is evolving
Panda-peddlers cuffed for chess gambling gambit
More porridge on the menu for Chinese coders after second offence
 breaking news
Yes, maybe we should keep hackers in the clink for YEARS, mulls EU
Watch out black hats, they just might throw away the key
Microsoft borks botnet takedown in Citadel snafu
Stupid Redmond kicked over our honeypots, wail white hats