Jump to content

Worm On The Loose


mark2
 Share

Recommended Posts

A new worm is now in the wild, AVG, Mcafee and Avast have all released updates to detect it.

Name: W32.Mimail.A@mm (Symantec)

Aliases: Worm_Mimail.A (Trend)

Type: Worm

Platforms: Windows 32-bit

Status: In the Wild

Threat: Medium (V-CON 3)

The following has been derived from information provided by Trend, Symantec

Virus Characteristics

=====================

Upon execution, W32.Mimail.A@mm, drops a copy of itself as VIDEODRV.EXE in

the Windows directory.

It creates the following registry entries so that it is executed at every

Windows startup:

HKEY_Local_Machine\Software\Microsoft\Windows\CurrentVersion\Run

" VideoDriver "=" %Windows% \videodrv.exe "

W32.Mimail.A@mm, propagates via email, with the following characteristics:

Subject: "your account %n%"

Body:

"Hello there, I would like to inform you about important information

regarding your email address.

This email address will be expiring. Please read attachment for details.

Best regards,

Administrator"

Attachment:

"message.zip"

(Note: %n% is a variable string.)

It arrives as an HTML attachment which contains a Win32 EXE file. When the

HTML file is opened, it takes advantage of an Internet Explorer security

system vulnerability that can allow a script to execute on the Local

computer. See the following link for more information:

http://www.microsoft.com/technet/treeview/...url=/technet/se curity/bulletin/MS02-015.asp

The exploit code then launches the .EXE file containing the worm program.

The worm component uses the following SMTP servers to send email to target

addresses:

acm.org

mirc.com

mx2.daemonmail.net

iglou.com

ft.com

winamp.com

mail.winamp.com

smtp.ceruleanstudios.com

ceruleanstudios.com

It also tries a list of usernames to connect to the above SMTP servers.

Preventative Measures

=====================

Block messages which have an attachment named "messages.zip" or similar

message body at the Internet gateway where possible.

Fixes Available

===============

Network Associates:

Minimum DAT: 4282

Release Date: 08/01/2003

Minimum Engine: 4.1.60

Symantec:

Virus Definitions (Intelligent Updater): 8/1/2003

Virus Definitions (LiveUpdate): 8/1/2003

Trend:

Pattern File: 597

Avast 0307-5

might be a good idea to check you have the latest updates for your own A/V :ph34r:

Link to comment
Share on other sites

LB your sig might give us a clue perhaps they're insane genius's :D

do you do any programming  :lol:  :lol:  :lol:

in college (all those years ago) my tutor told me that i would be better at debugging than actually writing programs (we were taught PASCAL back then!!!!), i also did a logic test when i worked for Rank Xerox as i really wanted to work in their networking department....i failed miserably and was consigned to the scrapheap........

incidentally, the signature was taken from a flag seen at anfield.......

Link to comment
Share on other sites

i hate people that send worms and trogens <----(i think that is how you spell it) thats why i want a kick back wall if some one sends you any thing i changes all the direction and all of that and sends it back to the person who sent it ha ha ha ha ha ha

i so want one

MONKEY

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Privacy Policy