The carnage caused by the Klez virus largely overshadowed other major security issues this month, but despite being top of the virus charts, a worm on KaZaA, security problems with Microsoft`s instant messenger, and one particular hoax virus are also noteworthy. Another virus is using the Klez-frenzy to spread itself.
Peer-to-peer service KaZaA Networks boasts the most recent security concern for users. A worm called "Benjamin" has been spreading across the popular file-trading service, albeit slowly. The worm creates a directory that is shared over KaZaA, and copies itself into that directory thousands of times, using different names. Other users who download and execute one of the "Trojan" files are infected by Benjamin, and spread the worm further.
A second major security concern is Microsoft`s instant messenger, which was found to have a buffer overflow problem that would make users running MSN Chat vulnerable to attack. Microsoft has since posted a patch for the security issue on its site.
Finally, a hoax virus has spread quickly over the last month, causing more damage than either of the above real security problems. The hoax requests that users delete their Microsoft Java registrar file for Java, "jdbgmgr.exe". Deleting this file can cause Java applications to not run under Windows, and ITWeb has received reports of users being duped by this hoax.
However, none of these security problems matched the damage and spread of Klez, which has in turn spurned yet another security risk - fake Klez fixes. The supposed Klez "cure" comes as an attachment to a message, purportedly from an anti-virus software vendor. In fact, the attachment is a Trojan virus, with some of the incidents reported to have been the fairly new Smokedown Trojan.
Anti-virus vendors advise users to install critical patches from software vendors and ensure their virus definitions are regularly updated.
Related stories:
Microsoft warns of `critical` chat security flaw
Klez worm continues to dominate virus lists

