View Full Version : @kaizen (moderator)
Razorblade2000
9th August 2002, 13:29
Since the last week, I get spammed by a lot of taiwanese people. One of the first mails came from kaizen@D00M9.org ... could sb please explain this to me?
(here are some headers of the mails)
Return-Path: <lulu271@yam.com>
X-Flags: 0000
Delivered-To: GMX delivery to razorblade2OOO@gmx.net
Received: (qmail 4909 invoked by uid 0); 6 Aug 2002 01:37:16 -0000
Received: from lnksmtp.cgmh.org.tw (210.61.73.27)
by mx0.gmx.net (mx023-rz3) with SMTP; 6 Aug 2002 01:37:16 -0000
Received: from Zhdwqn ([10.30.64.45])
by lnksmtp.cgmh.org.tw (8.9.3/8.9.3) with SMTP id JAA20087
for <Razorblade2OOO@gmx.net>; Tue, 6 Aug 2002 09:37:01 +0800
Date: Tue, 6 Aug 2002 09:37:01 +0800
Message-Id: <200208060137.JAA20087@lnksmtp.cgmh.org.tw>
From: kaizen <kaizen@D00M9.org>
To: Razorblade2OOO@gmx.net
Subject: So cool a flash,enjoy it
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=W1w851j184o6VYQ884Bz
Return-Path: <lulu271@yam.com>
X-Flags: 0000
Delivered-To: GMX delivery to razorblade2OOO@gmx.net
Received: (qmail 8881 invoked by uid 0); 6 Aug 2002 10:51:48 -0000
Received: from lnksmtp.cgmh.org.tw (210.61.73.27)
by mx0.gmx.net (mx006-rz3) with SMTP; 6 Aug 2002 10:51:48 -0000
Received: from Wnbh ([10.30.64.45])
by lnksmtp.cgmh.org.tw (8.9.3/8.9.3) with SMTP id SAA32676
for <Razorblade2OOO@gmx.net>; Tue, 6 Aug 2002 18:51:07 +0800
Date: Tue, 6 Aug 2002 18:51:07 +0800
Message-Id: <200208061051.SAA32676@lnksmtp.cgmh.org.tw>
From: tim_wang1976 <tim_wang1976@yahoo.com.tw>
To: Razorblade2OOO@gmx.net
Subject: Please try again
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=Y2kW6eObp3149N1WQiu78VWD8
Return-Path: <lulu271@yam.com>
X-Flags: 0000
Delivered-To: GMX delivery to razorblade2OOO@gmx.net
Received: (qmail 17411 invoked by uid 0); 9 Aug 2002 04:55:44 -0000
Received: from 61-222-243-194.hinet-ip.hinet.net (HELO lnksmtp.cgmh.org.tw) (61.222.243.194)
by mx0.gmx.net (mx022-rz3) with SMTP; 9 Aug 2002 04:55:44 -0000
Received: from Qbrpvlsjp ([10.30.64.45])
by lnksmtp.cgmh.org.tw (8.9.3/8.9.3) with SMTP id MAA04955
for <Razorblade2OOO@gmx.net>; Fri, 9 Aug 2002 12:55:33 +0800
Date: Fri, 9 Aug 2002 12:55:33 +0800
Message-Id: <200208090455.MAA04955@lnksmtp.cgmh.org.tw>
From: support <support@via.com.tw>
To: Razorblade2OOO@gmx.net
Subject: A good tool
MIME-Version: 1.0
Content-Type: multipart/alternative;
boundary=Ck5XHFZloJ96o4YV61R8v9J0
(all mail adresses have been changed (O->0...)
Koepi
9th August 2002, 13:54
RazorBlade,
before asking something like that in such an "aggressive" sound you should do a google search on "worm kleez" and read hopw it works, before you make yourself look like a jerk.
Internet Worm Name Risk Assessment
W32/Klez.e@MM
Corporate User : Medium
Home User : Medium
Internet Worm Information
Discovery Date: 01/17/2002
Origin: Unknown
Length: about 80kbytes
Type: Internet Worm
SubType: Win32
Minimum DAT:
Release Date: 4182
01/23/2002
Minimum Engine: 4.0.70
Description Added: 02/20/2002
Description Modified: 04/26/2002 3:43 PM (PT)
Description Menu
Internet Worm Characteristics
Symptoms
Method Of Infection
Removal Instructions
Variants / Aliases
Rate This page
Print This Page
Email This Page
Legend
Internet Worm Characteristics:
-- Update 3/4/2002 --
Due to a slow, but steady, increase in prevalence over the past few weeks, AVERT has raised the risk assessment of this threat to MEDIUM.
This W32/Klez variant has the ability to spoof the email FROM: field. The senders address used by the virus, may be one that was found on the infected user's system. Thus, it may appear that you have received this virus from one person, when it was actually sent from a different user's system. Viewing the entire email header will display the actual senders address.
This worm makes use of Incorrect MIME Header Can Cause IE to Execute E-mail Attachment vulnerability in Microsoft Internet Explorer (ver 5.01 or 5.5 without SP2)
This worm arrives in an Email message with a subject and body randomly composed from a rather long pool of strings that the virus carries inside itself (the virus can also add other strings):
"Hi, Hello, Re: Fw: Undeliverable mail-- Returned mail-- game a tool a website new funny nice humour excite good powful WinXP IE 6.0 W32.Elkern W32.Klez how are you let's be friends darling don't drink too much your password honey some questions please try again welcome to my hometown the Garden of Eden introduction on ADSL meeting notice question naire congratulations sos! japanese girl VS playboy look, my beautiful girlfriend eager to see you spice girls' vocal concert japanese lass' sexy pictures Symantec Mcafee F-Secure Sophos The following mail can't be sent to The attachment The file is the original mail give you the is a dangerous virus that can infect on Win98/Me/2000/XP. spread through email. very special For more information,please visit This is I you would it. enjoy like wish hope expect Christmas New year Saint Valentine's Day Allhallowmas April Fools' Day Lady Day Assumption Candlemas All Souls'Day Epiphany Happy Have a"
In our experiments we have, for example, observed the following Subject lines (more common at the top):
Subject: Document End
Subject: Happy Lady Day
Subject: From
Subject: Eager to see you
Subject: Returned mail--"Document End "
Subject: HEIGHT
Subject: A WinXP patch
Subject: Hi,spice girls' vocal concert
Subject: Happy nice Lady Day
Subject: Have a humour Lady Day
Subject: Happy good Lady Day
Subject: ALIGN
Subject: Have a good Lady Day
Subject: Undeliverable mail--"IIS services with this Web administration tool."
(the virus can also send mails with empty Subject and/or body)
This virus can also unload several antivirus programs from memory.
Top of Page
Symptoms
1) The worm interferes with running programs and frequently displays a fake error message:
Note - the name displayed is random but is always an EXE.
2) Alien WINKxxx.EXE files in \WINDOWS\SYSTEM folder (ex., WINKIDT.EXE or WINKKR.EXE).
3) Reference to a WINKxxx.EXE file (and "xxx" looks random) in a registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run or HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
4) Executable files have "companions" of about the same size and random extension (ex., apart from MSOFFICE.EXE you may have MSOFFICE.HRH which is a hidden system file). On top of that if you run an infected file you will temporarily have a third file with "~1" in the name (ex., NETSCAPE.EXE will not only have NETSCAPE.PXB but also NETSCA~1.EXE of exactly the same size as NETSCAPE.EXE). This third file is a reconstructed host and it is deleted by the worm once you quit the program.
5) This worm also causes serious system performance degradation and some programs stop running.
Top of Page
Method Of Infection
When the Email is opened the worm immediately activates using mentioned vulnerability (previewing the message may be enough if your system is not patched). The worm copies itself under WINKxxx.EXE name (where xxx are random characters) into the WINDOWS\SYSTEM folder (can be different if your installation is not a default one) and this file is set to run every time the system starts.
W32/Klez.e@MM is based on the W32/Klez.gen@MM but unlike its predecessors this variant can itself infect files (on top of being able to also drop W95/Elkern.cav.b virus). W32/Klez.e@MM worm overwrites files and they are padded with zeroes to the original uninfected host size. The worm saves original contents of the hosts in files with the same name and random extension. These files are "Hidden" and "System" (to be able to see them you need to change "View/Folder Options" in Windows Explorer by selecting "Show all files").
Running infected files causes the worm to reconstruct the uninfected host file using saved data. Such reconstructed files will have "~1" appended to the name (ex., infected MSOFFICE.EXE will be accompanied by an uninfected MSOFFI~1.EXE). The worm deletes them as soon as the program stops running so they exist only temporarily.
W32/Klez.e@MM sends itself out using SMTP protocol. It harvests the Windows address book for email addresses.
The virus may save a copy of itself into .RAR archives.
There is a date-activated payload associated with this threat. On the 6th day of March, May, September, or November, the virus may overwrite local and network files containing the following extensions with zeros: .txt, .htm, .html, .wab, .doc, .xls, .jpg, .cpp, .c, .pas, .mpg, .mpeg, .bak, or .mp3.
If the month is January or July, all files may be overwritten. This behavior was not observed in a lab environment.
Top of Page
Removal Instructions
Use current engine and DAT files for detection.
Once infected, VirusScan may not be able to run as the virus can terminate the process before any scanning/removal is accomplished. The following steps will circumvent this action and allow for proper VirusScan scanning/removal, by using the command-line scanner.
1. Ensure that you are using the minimum DAT specified or higher.
2. Close all running applications
3. Disconnect the system from the network
4. Go to a command prompt, then change to the VirusScan engine directory:
* Win9x/ME - Click START | RUN, type command and hit ENTER.
Type cd \progra~1\common~1\networ~1\viruss~1\40~1.xx and hit ENTER
*
WinNT/2K/XP - Click START | RUN, type cmd and hit ENTER.
Type cd \progra~1\common~1\networ~1\viruss~1\4.0.xx and hit ENTER
5. Rename SCAN.EXE to CLEAN.EXE to prevent the virus from terminating the process and deleting files. Type, ren scan.exe clean.exe and hit ENTER
6. First, scan the system directory
* Win9x/ME - Type clean.exe %windir%\system\win*.exe and hit ENTER
*
WinNT/2K/XP - Type clean.exe %windir%\system32\win*.exe and hit ENTER
7. Once the scan has completed, Type clean.exe /adl /clean and hit ENTER
8. Rename scan.exe. Type, ren clean.exe scan.exe and hit ENTER
9. After scanning and removal is complete, reboot the system
Apply Internet Explorer patch if necessary.
Klez can delete anti-virus software files. It may be necessary to reinstall VirusScan after cleaning a system.
Additional Windows ME/XP removal considerations
Top of Page
Variants
Name Type Sub Type Differences
Top of Page
Aliases
Name
I-Worm/Klez.E (AVP)
W32.Klez.E@mm (Symantec)
W32/Klez.F (Panda)
Win32.HLLM.Klez.1 (DrWeb)
Worm/Klez.E (H+BEDV)
WORM_KLEZ.E (Trend)
CaPPyD
9th August 2002, 16:54
In addition to what has already been stated, note that the address for kaizen is @d00m9.org with ZEROS and not O's. A Zero is rectangular in shape, while an O is more circular. If you could differentiate between, you would know that a DOOM9 address is not spamming you!!!!
Also, by looking at all of the headers there, the return path for ALL EMAILS is lulu271@yam.com THEREFORE, all three emails came from the same source!!!!
Razorblade2000
9th August 2002, 21:08
In addition to what has already been stated, note that the address for kaizen is @d00m9.org with ZEROS and not O's. A Zero is rectangular in shape, while an O is more circular. If you could differentiate between, you would know that a DOOM9 address is not spamming you!!!!
at the end of my post:
(all mail adresses have been changed (O->0...)
It was @doom0.org!
Razorblade2000
9th August 2002, 21:20
Oh sure... when I read this mails I should have known that I have to search for the words "worm klez" at google... how couldn't I...
But now really:
aggresive??? I only asked for help/explenation!!!! (You know, forums were ment to give answers on questions)
and:
aggressive... I think considering me to be a jerk (you know:
"before you make yourself look like a jerk." )
is a little bit aggressive, don't you think so???
this post may be a lil bit aggressive... but I don't care :D
Koepi
9th August 2002, 21:25
Well, it sounded aggressive to me. And sure, we're here to help. But those worms are around for a long time now, so i wonder why you didn't read that aynwhere else yet.
Btw., my post wasn't aggressive, I wanted to help you, look again...
Razorblade2000
9th August 2002, 21:29
I read about Klez... but why sould I know that is was Klez???
(kaizens PC is infected, isn't it?)
Koepi
9th August 2002, 21:31
Please reread the article about that virus again.
Or head over to www.freeav.de and try to find the german version of this text.
CaPPyD
9th August 2002, 21:38
Didnt see the 0->0 part, sorry bout that. However the rest of my post cleared kaizen of any fault and it appears that you have ignored that. If I were you, i would contact lulu271@yam.com and ask them to either clean their computer or stop spamming you.
Also, by looking at all of the headers there, the return path for ALL EMAILS is lulu271@yam.com THEREFORE, all three emails came from the same source!!!!
Doom9
10th August 2002, 00:03
to sum it all up: certain viruses send emails with fake senders out. Plus.. you can actually do that yourself if you find a mail server that allows mail relay. The mail header will usually tell you that the From address is a fake. So.. be careful before you accuse somebody of harassing you via email. I too have gotten emails with fake addys but that just happens.. if you get something that doesn't quite look right... delete it!
vBulletin® v3.8.11, Copyright ©2000-2026, vBulletin Solutions Inc.