Skip to content

FAO Agentwood / Mr Disco / Maybe others

Archived

12 replies · 303 views

This is an archived legacy thread. Replies are closed, but the discussion is preserved.

I'm receiving viruses from you! or someone you mailed, so check your systems!

-----Original Message----- From: agentwood10 [mailto:agentwood10@hotmail.com] Sent: April 7, 2003 10:09 AM To: nleblanc@neworderonline.com Subject: A IE 6.0 patch

This is a IE 6.0 patch I hope you would like it.

---- Header -----

eturn-Path: Received: from cmailm4.svr.pol.co.uk (cmailm4.svr.pol.co.uk [195.92.193.211]) by sl1.mobisun.org (8.11.6/8.11.6) with ESMTP id h37DWw532352 for ; Mon, 7 Apr 2003 09:33:00 -0400 Received: from modem-3577.guenon.dialup.pol.co.uk ([81.76.221.249] helo=Jch) by cmailm4.svr.pol.co.uk with smtp (Exim 4.14) id 192XIw-0006xp-AU for nleblanc@neworderonline.com; Mon, 07 Apr 2003 15:08:59 +0100 From: agentwood10 To: nleblanc@neworderonline.com Subject: A IE 6.0 patch MIME-Version: 1.0 Content-Type: multipart/alternative; boundary=HE0734Hw4V9777JlOR9yPM966KAxA67v1 Message-Id: Date: Mon, 07 Apr 2003 15:08:59 +0100 Status:

0 likes

That's a klez one, isn't it, Nic, which spoofs the originating e-mail address, so it may not be from those folk at all, regrettably :nerd:

0 likes

I'd agree with that diagnosis (Klez-H). Of the viruses being sent to work its about 10-1 Klez, thank the lordy for Sophos.

0 likes

Well, Office XP is bulletproof for those type of mails, but well.. it's very annoying, I'm receving tons daily on the neworderonline email...

That and spam......

0 likes

Nic, there's a way you can put your e-mail address on the website as a scripted image, rather than as a hyperlink, so that it doesn't get picked up by the spammers.

I'll see if I can remember how you do it....

0 likes

yeah, i got one from you too, nic, the other day! and from a few others on NOOL. i think it's similar to that last one that did the rounds a while ago.... they just go around and around and around.

0 likes

Yes,it is true.

Mr. Disco is a famous terrorist here in brazil. :D

0 likes

It's modem-3577.guenon.dialup.pol.co.uk that has the virus...

:nonono:

Very annoying little thing.

0 likes

does the virus actually do anything? i have mc afee, so i'm hoping whatever it tried to infect was protected. irritating buggers. i'm still getting the occasional goldfish one, as well.

0 likes

I've been getting one a day from mrdisco@neworderonline.com.

0 likes

Originally posted by AgentWood does the virus actually do.... i'm still getting the occasional goldfish one, as well.

From Sophos - more info than you may want. I've had to deal with one PC that Klez got through to and it was a total pain in the arse getting rid of it. Hope this helps with any diagnosis!

W32/Klez-H copies itself into the Windows system directory with a random filename. The filename begins with the characters "wink" and has the extension EXE.

The worm searches for email addresses in the Windows address book and also in files with the extensions TXT, HTM, HTML, WAB, ASP, DOC, RTF, XLS, JPG, CPP, C, PAS, MPG, MPEG, BAK, MP3 and PDF.

The email message "From:" field will contain either one of the addresses found in the search or an address taken from a list inside the virus body.

The worm sends itself using emails with the following characteristics:

Subject line: The subject line is randomly created using one of the following rules.

1. A combination of "Hi,", "Hello," "Re:", "Fw:", or nothing

with

"Very", "special", "Happy" or "Have a" as the first part of the sentence

and

"New", "funny", "nice", "humour", "excite", "good", "powful", "WinXP", "IE 6.0" or nothing as the second, arranged in one of the following sentences:

"A %s %s game." "A %s %s tool." "A %s %s website." "A %s %s patch." "%s %s Allhallowmas" "%s %s Epiphany"

e.g. "A special powful tool" or "Happy Allhallowmas"

2. A combination of "W32.Elkern" or "W32.Klez.E" and "removal tools".

e.g. "W32.Klez.E removal tools"

3. One chosen from the following list:

how are you let's be friends darling so cool a flash,enjoy it your password honey some questions please try again welcome to my hometown the Garden of Eden introduction on ADSL meeting notice questionnaire congratulations Sos! japanese girl VS playboy look,my beautiful girl friend eager to see you spice girls' vocal concert japanese lass' sexy pictures Undeliverable mail -- Returned mail --

4. Worm Klez.E immunity

Message text: The message text is randomly composed by the worm, and may be left blank.

If the subject line is "Worm Klez.E immunity", then the message text is "Klez.E is the most common world-wide spreading worm. It's very dangerous by corrupting your files. Because of its very smart stealth and anti-anti-virus technic,most common AV software can't detect or clean it. We developed this free immunity tool to defeat the malicious virus. You only need to run this tool once,and then Klez will never come into your PC. NOTE: Because this tool acts as a fake Klez to fool the real worm,some AV monitor maybe cry when you run it. If so,Ignore the warning,and select 'continue'. If you have any question,please mail to me."

Attached file: Randomly named with the extension PIF, SCR, EXE or BAT.

Because the worm uses its own SMTP engine, the message may appear to come from any email address. Some of the messages will have a "From:" field and message text which imply that the message was sent by a major anti-virus vendor (namely Kaspersky, F-Secure, Sophos, Symantec and Trend Micro).

The SMTP server used to send the messages is taken from the value "SMTP Server" of the registry key

HKCU\Software\Microsoft\Internet Account\Manager\Accounts

When sending email, W32/Klez-H may attach a randomly chosen file from the infected computer with the extension TXT, HTM, HTML, WAB, ASP, DOC, RTF, XLS, JPG, CPP, C, PAS, MPG, MPEG, BAK, MP3, or PDF. This means that the worm may cause the disclosure of confidential company data.

W32/Klez-H attempts to disable several anti-virus software products and to delete some anti-virus related files.

The worm attempts to exploit a MIME and an IFRAME vulnerability in some versions of Microsoft Outlook, Microsoft Outlook Express, and Internet Explorer to allow the executable file to run automatically without the user double-clicking on the attachment. Microsoft has issued a patch which secures against this vulnerability which can be downloaded from Microsoft Security Bulletin MS01-027. (This patch was released to fix a number of vulnerabilities in Microsoft's software, including the one exploited by this worm.)

W32/Klez-H may also spread to remote shares on other machines using random filenames. The dropped files may have a double extension formed by using a combination of extensions randomly taken from the two lists. The first extension is taken from the following list:

TXT HTM HTML WAB ASP DOC RTF XLS JPG CPP C PAS MPG MPEG BAK MP3 PDF

The second extension is taken from:

PIF SCR EXE BAT

For example, the double extension may be .txt.exe.

W32/Klez-H will add a value "wink" to registry run command, so that the dropped file will run on Windows startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\

Additionally the worm will attempt to disable anti-virus software by stopping any of the following processes,

_AVP32 _AVPCC NOD32 NPSSVC NRESQ32 NSCHED32 NSCHEDNT NSPLUGIN NAV NAVAPSVC NAVAPW32 NAVLU32 NAVRUNR NAVW32 _AVPM ALERTSVC AMON AVP32 AVPCC AVPM N32SCANW NAVWNT ANTIVIR AVPUPD AVGCTRL AVWIN95 SCAN32 VSHWIN32 F-STOPW F-PROT95 ACKWIN32 VETTRAY VET95 SWEEP95 PCCWIN98 IOMON98 AVPTC AVE32 AVCONSOL FP-WIN DVP95 F-AGNT95 CLAW95 NVC95 SCAN VIRUS LOCKDOWN2000 Norton Mcafee Antivir TASKMGR

and deleting the files

ANTI-VIR.DAT CHKLIST.DAT CHKLIST.MS CHKLIST.CPS CHKLIST.TAV IVB.NTZ SMART CHK.MS SMARTCHK.CPS AVGQT.DAT AGUARD.DAT

0 likes

Sorry, I didn't catch all that. Would you mind running it passed us again ? :lol:

0 likes

Originally posted by clayts Sorry, I didn't catch all that. Would you mind running it passed us again ? :lol:

No problem!

From Sophos - more info than you may want. I've had to deal with one PC that Klez got through to and it was a total pain in the arse getting rid of it. Hope this helps with any diagnosis!

W32/Klez-H copies itself into the Windows system directory with a random filename. The filename begins with the characters "wink" and has the extension EXE.

The worm searches for email addresses in the Windows address book and also in files with the extensions TXT, HTM, HTML, WAB, ASP, DOC, RTF, XLS, JPG, CPP, C, PAS, MPG, MPEG, BAK, MP3 and PDF.

The email message "From:" field will contain either one of the addresses found in the search or an address taken from a list inside the virus body.

The worm sends itself using emails with the following characteristics:

Subject line: The subject line is randomly created using one of the following rules.

1. A combination of "Hi,", "Hello," "Re:", "Fw:", or nothing

with

"Very", "special", "Happy" or "Have a" as the first part of the sentence

and

"New", "funny", "nice", "humour", "excite", "good", "powful", "WinXP", "IE 6.0" or nothing as the second, arranged in one of the following sentences:

"A %s %s game." "A %s %s tool." "A %s %s website." "A %s %s patch." "%s %s Allhallowmas" "%s %s Epiphany"

e.g. "A special powful tool" or "Happy Allhallowmas"

2. A combination of "W32.Elkern" or "W32.Klez.E" and "removal tools".

e.g. "W32.Klez.E removal tools"

3. One chosen from the following list:

how are you let's be friends darling so cool a flash,enjoy it your password honey some questions please try again welcome to my hometown the Garden of Eden introduction on ADSL meeting notice questionnaire congratulations Sos! japanese girl VS playboy look,my beautiful girl friend eager to see you spice girls' vocal concert japanese lass' sexy pictures Undeliverable mail -- Returned mail --

4. Worm Klez.E immunity

Message text: The message text is randomly composed by the worm, and may be left blank.

If the subject line is "Worm Klez.E immunity", then the message text is "Klez.E is the most common world-wide spreading worm. It's very dangerous by corrupting your files. Because of its very smart stealth and anti-anti-virus technic,most common AV software can't detect or clean it. We developed this free immunity tool to defeat the malicious virus. You only need to run this tool once,and then Klez will never come into your PC. NOTE: Because this tool acts as a fake Klez to fool the real worm,some AV monitor maybe cry when you run it. If so,Ignore the warning,and select 'continue'. If you have any question,please mail to me."

Attached file: Randomly named with the extension PIF, SCR, EXE or BAT.

Because the worm uses its own SMTP engine, the message may appear to come from any email address. Some of the messages will have a "From:" field and message text which imply that the message was sent by a major anti-virus vendor (namely Kaspersky, F-Secure, Sophos, Symantec and Trend Micro).

The SMTP server used to send the messages is taken from the value "SMTP Server" of the registry key

HKCU\Software\Microsoft\Internet Account\Manager\Accounts

When sending email, W32/Klez-H may attach a randomly chosen file from the infected computer with the extension TXT, HTM, HTML, WAB, ASP, DOC, RTF, XLS, JPG, CPP, C, PAS, MPG, MPEG, BAK, MP3, or PDF. This means that the worm may cause the disclosure of confidential company data.

W32/Klez-H attempts to disable several anti-virus software products and to delete some anti-virus related files.

The worm attempts to exploit a MIME and an IFRAME vulnerability in some versions of Microsoft Outlook, Microsoft Outlook Express, and Internet Explorer to allow the executable file to run automatically without the user double-clicking on the attachment. Microsoft has issued a patch which secures against this vulnerability which can be downloaded from Microsoft Security Bulletin MS01-027. (This patch was released to fix a number of vulnerabilities in Microsoft's software, including the one exploited by this worm.)

W32/Klez-H may also spread to remote shares on other machines using random filenames. The dropped files may have a double extension formed by using a combination of extensions randomly taken from the two lists. The first extension is taken from the following list:

TXT HTM HTML WAB ASP DOC RTF XLS JPG CPP C PAS MPG MPEG BAK MP3 PDF

The second extension is taken from:

PIF SCR EXE BAT

For example, the double extension may be .txt.exe.

W32/Klez-H will add a value "wink" to registry run command, so that the dropped file will run on Windows startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\

Additionally the worm will attempt to disable anti-virus software by stopping any of the following processes,

_AVP32 _AVPCC NOD32 NPSSVC NRESQ32 NSCHED32 NSCHEDNT NSPLUGIN NAV NAVAPSVC NAVAPW32 NAVLU32 NAVRUNR NAVW32 _AVPM ALERTSVC AMON AVP32 AVPCC AVPM N32SCANW NAVWNT ANTIVIR AVPUPD AVGCTRL AVWIN95 SCAN32 VSHWIN32 F-STOPW F-PROT95 ACKWIN32 VETTRAY VET95 SWEEP95 PCCWIN98 IOMON98 AVPTC AVE32 AVCONSOL FP-WIN DVP95 F-AGNT95 CLAW95 NVC95 SCAN VIRUS LOCKDOWN2000 Norton Mcafee Antivir TASKMGR

and deleting the files

ANTI-VIR.DAT CHKLIST.DAT CHKLIST.MS CHKLIST.CPS CHKLIST.TAV IVB.NTZ SMART CHK.MS SMARTCHK.CPS AVGQT.DAT AGUARD.DAT

0 likes

You're leaving NewOrderOnline

This link goes to an external website we don't operate, which has its own privacy policy and terms.

Destination:
Continue ↗