Main Restorations Software Audio/Jukebox/MP3 Everything Else Buy/Sell/Trade
Project Announcements Monitor/Video GroovyMAME Merit/JVL Touchscreen Meet Up Retail Vendors
Driving & Racing Woodworking Software Support Forums Consoles Project Arcade Reviews
Automated Projects Artwork Frontend Support Forums Pinball Forum Discussion Old Boards
Raspberry Pi & Dev Board controls.dat Linux Miscellaneous Arcade Wiki Discussion Old Archives
Lightguns Arcade1Up Try the site in https mode Site News

Unread posts | New Replies | Recent posts | Rules | Chatroom | Wiki | File Repository | RSS | Submit news

  

Author Topic: Klez email filter  (Read 2329 times)

0 Members and 1 Guest are viewing this topic.

Dave Dribin

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 152
  • Last login:May 26, 2007, 11:17:39 pm
  • ugh... yeah
    • Dave Dribin's Home Page
Klez email filter
« on: September 07, 2002, 01:18:45 pm »
I know the best way to stop Klez is to have people disinfect their computer.  But, if you receive the virus email a lot like I do and want to just filter them out of the way, here is a simple Procmail filtering rule to do so:

# Klez worm procmail filter - courtesy of www.shove-it.com
:0 B
* ^135AAItEjhyJRI8ci0SOGIlEjxiLRI4UiUSPFItEjhCJRI8Qi0SODIlEjwyLRI4IiUSPCItE$
${KLEZ}


Yeah, Procmail is a Unix-only mail filter, but I'm sure someone could adapt it to some Windows variant.  All the filter is doing is seeing if one of the lines in the body matches that long string.  So far it's caught 215 copies of Klez without a single false positive or missed Klez.  Not too shabby. :)

-Dave

tom61

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 495
  • Last login:September 18, 2017, 12:46:56 am
Re:Klez email filter
« Reply #1 on: September 07, 2002, 03:28:54 pm »
Hmm... interesting. Maybe Saint or PJ could have that run when forwarding emails...

I tried setting up Outlook Express with a message rule to delete messages that have '* ^135AAItEjhyJRI8ci0SOGIlEjxiLRI4UiUSPFItEjhCJRI8Qi0SODIlEjwyLRI4IiUSPCItE' in their body, but it appearently excludes attachments from being considered.

Dave Dribin

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 152
  • Last login:May 26, 2007, 11:17:39 pm
  • ugh... yeah
    • Dave Dribin's Home Page
Re:Klez email filter
« Reply #2 on: September 08, 2002, 02:59:54 pm »
I tried setting up Outlook Express with a message rule to delete messages that have '* ^135AAItEjhyJRI8ci0SOGIlEjxiLRI4UiUSPFItEjhCJRI8Qi0SODIlEjwyLRI4IiUSPCItE' in their body, but it appearently excludes attachments from being considered.


Sorry, I should have explained the Procmail stuff a little better.  The text you need to match on is "135AA....SPCItE".  The star ("*"), caret ("^"), and dollar sign ("$") are special characters for Procmail and are not actually in the string to be matched.  Maybe that'll help, though I can see Outlook skipping attachments, too.

Aparently this string is in the Base-64 encoded Klez binary and unique to its exe.

-Dave


tom61

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 495
  • Last login:September 18, 2017, 12:46:56 am
Re:Klez email filter
« Reply #3 on: September 08, 2002, 06:28:37 pm »
I didn't include the caret or star when I put it OE, only when I pasted it here.

Dave Dribin

  • Trade Count: (0)
  • Full Member
  • ***
  • Offline Offline
  • Posts: 152
  • Last login:May 26, 2007, 11:17:39 pm
  • ugh... yeah
    • Dave Dribin's Home Page
Re:Klez email filter
« Reply #4 on: September 08, 2002, 10:53:11 pm »

I didn't include the caret or star when I put it OE, only when I pasted it here.


Eh, crap.  Oh well. :(

-Dave