All the latest UK technology news, reviews and analysis

Bug Watch: beware of the quiet ones

by Eric Chien, Symantec

14 Jul 2000

Be the first to comment

  • Tweet this
Bug Watch: Each week vnunet.com asks a different expert from the antivirus world to give their views on recent virus and security issues, with advice, warnings and information on the latest threats. This week's expert is Eric Chien, head of Symantec's antivirus research centre.

While everyone heard about LoveLetter, it wasn't the most reported virus to Symantec during May. That honour went to Kakworm, a seven-month-old worm that was also the most reported virus in April, May and June on a global basis.

Every major antivirus company has a definition for this virus, so why is it still a headache for business and home users?

What does Kakworm do? Nothing that would be seen by the infected user. Through the ever popular Outlook, this worm can embed itself into legitimate emails you generate and send without you ever knowing, and the recipient wouldn't know either - it isn't an attachment.

However, come the first of the month at 5pm BST, it will shut down Windows without warning. Not great damage, but the kind of jiggery-pokery could cause you to lose unsaved work and potentially lead to system instability - let alone the reputation issues to your business.

Think of how many emails you will have sent to clients, customers, suppliers and friends during those 30 or even 60 days before you notice a problem.

Kakworm relies on user apathy. Even if you have the latest virus definitions from your antivirus supplier, you could still contract it. If your antivirus software does not scan for viruses in your Outlook database then you may be at risk. Don't assume that your software is capable of scanning for this type of embedded virus - not all of them can.

Microsoft released a patch to prevent this type of exploit back in October 1999. Using this patch would prevent the worm spreading, but not many users have installed it.

Kakworm will be cropping up on WildLists and researchers' top 10s for a long time. We must heed the warnings and become vigilant with all software updates, so we are prepared for the even more destructive versions that may come along.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

Flame virus poll

Are you confident that the UK's IT infrastructure is secure from attack in the wake of the Flame malware revelations?

35%

0%

11%

54%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Symanteccloud

Social networking: a guide for IT managers

Social networking is almost ubiquitous. This white paper examines the benefits and risks and it looks at the different ways companies can reconcile them

Riverbed

Mitigating the risks of IT change

The importance of understanding your infrastructure

Business Readiness/ Change manager

As part of a major implementation of a new inventory...

Information/Data Architect - MDM - SOA

Information/Data Architect - MDM - Master Data Management...

Softwaren Developer - .Net/SQL Server

Code Red Associates (CRA) is a leading supplier of Permanent...

Senior Test Analyst, Quality Assurance, QA, To £47,000 + Benefits

A fantastic opportunity has arisen for an experienced...

To send to more than one email address, simply separate each address with a comma.