Information Age: News, analysis & insight for IT & business leaders

 

Klez most widespread virus in 2002

10 February 2006  

Just three viruses accounted for more than half of all computer virus infections during 2002, according to anti-virus software vendor Sophos.

 
 
 

5 December 2002 Just three viruses accounted for more than half of all computer virus infections during 2002, according to anti-virus software vendor Sophos.

Even more surprisingly, the email worm Klez accounted for a quarter of the total, despite the fact that a fix for the hole in Microsoft Outlook that it exploits had been available for more than a year when it was first identified.

"Unlike previous chart toppers like the LoveBug, which disappeared almost as quickly as it arrived, Klez is the ultimate in slow burning worms. It has managed to consistently infect users throughout the year," said Graham Cluley, senior technology consultant at Sophos.

 
Top ten viruses
in 2002
Klez 24.1%
Bugbear 17.5%
Badtrans 14.6%
Elkern 4.6%
Magistr 4.2%
MyParty 2.2%
Sircam 2%
Yaha 1.9%
Frethem-Fam 1.4%
Nimda 1.2%
Others 26.3%
Source: Sophos
 
 

Instead of the user having to double-click on an attachment to activate the virus, Klez can be activated on unpatched PCs by the user simply viewing the email in Outlook's 'preview pane'.

Furthermore, while most Outlook worms do little more than send copies of themselves automatically to everyone in the user's address book, Klez's payload includes variants of the Elkern virus that disables anti-virus software.

Klez was particularly prevalent among poorly protected and technically illiterate home users.

It was just one of 7,189 viruses identified by Sophos during the year, although only a tiny fraction of that number are virulent enough to infect more than a handful of machines.

Most ominous of these, perhaps, was a 'proof of concept' virus distributed by virus writer 'Gigabyte'. Called Sharp, it is designed to demonstrate security shortcomings in Microsoft .Net, the software giant's web services technology.

Sharp does not cause any significant damage beyond sending itself to everyone in the user's Outlook address book. But if it detects the presence of .Net, it displays the message, "You're infected with Win32.HLLP.Sharp, written in C#, by Gigabyte/Metaphase".

Cluley also warns that virus writers are increasingly trying to spread remote access 'Trojans', hacking tools enabling them to take control of infected users' PCs and discover passwords to sensitive systems, such as corporate networks and online banking services.

Other new threats expected to surface in 2003 include worms targeting instant messaging services. But Cluley remains sceptical that handheld computers will be targeted soon because of their general lack of network connectivity.

Infoconomy links:
Sophos' top ten viruses and hoaxes in 2002


Comments 

There are currently no comments on this article

People who read this also read...

What next for .Net?

A summary of some of the key .Net components, and Infoconomy'sperspective on what happpens next.

 
Advertisement

White Papers

Read article

Developing ios Solutions for Business

Whitepapers

Quickly develop and deploy custom iPad and iPhone solutions. With FileMaker Pro, iPad and iPhone solutions can be prototyped and completed in hours or days versus weeks or months. No iOS application programming or design experience is required.

Read article

IDC Spotlight: Access Control and Certification

Whitepapers

Read this brief for best practices on managing user access compliance.

Read article

GPS World

Whitepapers

Is the PREMIER global media brand serving the exploding world of positioning and navigation for OEM, commercial and consumer applications.

More
div class="banner">