View Single Post
  #1  
Old 02-26-02, 02:39 PM
Cutriss's Avatar
Cutriss Cutriss is offline
Dancing Hero
 
Join Date: Feb 2001
Location: Over there
Posts: 1,163
Cutriss is off the scale
Default Virus Alert: W32.Klez.E

From Symantec's Security Response page:

W32.Klez.E@mm is similar to W32.Klez.A@mm. It is a mass-mailing email worm that also attempts to copy itself to network shares. The worm uses random subject lines, message bodies, and attachment file names.

The worm exploits a vulnerability in Microsoft Outlook and Outlook Express in an attempt to execute itself when you open or even preview the message in which it is contained. Information and a patch for the vulnerability can be found at http://www.microsoft.com/technet/security/bulletin/MS01-020.asp.

The worm overwrites files and creates hidden copies of the original. In addition, the worm drops the virus W32.Elkern.3587 which is similar to W32.ElKern.3326. The worm attempts to disable some common antivirus products and has a payload which fills files with all zeroes.

Read about it here. I've seen this going around a *lot* on my campus. It's insidious in that it appears to be a server-bounced e-mail message when it arrives. Time to get those patches...
Reply With Quote