Skip to main content

Be ON Guard for a False Klez Fix

May 16, 2002

An imitation cure for the Klez Internet worm has emerged. Kaspersky Labs warns computer users about a distribution by an unknown malicious person of the Trojan program "TrojanDownloader.Win32.Smokedown", which is hidden under the guise of a cure for the Klez Internet-worm. This malicious...

An imitation cure for the Klez Internet worm has emerged. Kaspersky Lab, an international data-security software developer, warns computer users about a distribution by an unknown malicious person of the Trojan program "TrojanDownloader.Win32.Smokedown", which is hidden under the guise of a cure for the Klez Internet-worm. This malicious program was distributed via email. The infected message has an HTML format and harbors the following characteristics: Subject:
You're under a serious threat!
Message Text:
Kaspersky Lab urging users to take the necessary measures to protect themselves against the mounting threat from the latest version of the Internet-worm Klez, most users lightly regarded the problem of securing their personal data, resulting in a global Internet virus epidemic. Over the past several days our technical support services have received over twelve thousand inquiries concerning Klez Internet worm infections.
The sender is shown as "Kaspersky Lab" and the address shown is "support@kaspersky.com". In actuality the anonymous evildoer sent out this malicious program from a mail server located in Australia and the aforementioned sender information was deliberately falsified. The message body also contains a disguised Java script that imperceptibly loads the Trojan horse "Smokedown" from a remote server and installs it on the user's computer. To complete this the malicious code exploits a vulnerability in the Internet Explorers security system that was first revealed in March 2001 and described in the Microsoft bulletin found here: http://www.microsoft.com/technet/security/bulletin/MS01-020.asp. The patch for this vulnerability can be downloaded from the following address: http://www.microsoft.com/windows/ie/downloads/critical/q290108/default.asp At this time Kaspersky Lab has not registered actual contaminations from "Smokedown", regardless we recommend users proceed with extreme care if they receive an email containing the contents described above. The cure for "Smokedown" was included in the Kaspersky Anti-Virus database nearly a month ago.

Be ON Guard for a False Klez Fix

An imitation cure for the Klez Internet worm has emerged. Kaspersky Labs warns computer users about a distribution by an unknown malicious person of the Trojan program "TrojanDownloader.Win32.Smokedown", which is hidden under the guise of a cure for the Klez Internet-worm. This malicious...
Kaspersky logo

About Kaspersky

Kaspersky is a global cybersecurity and digital privacy company founded in 1997. With over a billion devices protected to date from emerging cyberthreats and targeted attacks, Kaspersky’s deep threat intelligence and security expertise is constantly transforming into innovative solutions and services to protect businesses, critical infrastructure, governments and consumers around the globe. The company’s comprehensive security portfolio includes leading endpoint protection, specialized security products and services, as well as Cyber Immune solutions to fight sophisticated and evolving digital threats. We help over 200,000 corporate clients protect what matters most to them. Learn more at www.kaspersky.com.

Related Articles Press Releases