New Virus making the rounds.

shiner

Lifer
Jul 18, 2000
17,112
1
0
W32/Mimail.c@MM

Info here

Idiot virus writers....we should beat them all with printer cables.
 

shiner

Lifer
Jul 18, 2000
17,112
1
0
Originally posted by: redly1
hehe...with printer cables. How about old surplus keyboards?
Either way...

Mods might want to sticky this.....our helpdesk is getting a lot of calls about it. I'm sure others are as well.

 

Ogg

Diamond Member
Sep 5, 2003
4,829
1
0
I think well be allright as I wont be unzipping anything from James about his beach photos and Im certainly not gonna have sex with him this evening.......
And Im not a lovely girl:D



>>>>>>>>>>>>>>>>>>.
Subject : Re[2]: our private photos (plus additional spaces then random characters)
Attachment : PHOTOS.ZIP (12,958 bytes) which contains PHOTOS.JPG.EXE (12,832 bytes)
Message Body :
Hello Dear!,
Finally, i've found possibility to right u, my lovely girl :)
All our photos which i've made at the beach (even when u're withou ur bh:))
photos are great! This evening i'll come and we'll make the best SEX :)

Right now enjoy the photos.
Kiss, James.
(random characters - the same as those terminating the subject)

Messages are constructed with the following X-headers:

X-Mailer: The Bat! (v1.62)
X-Priority: 1 (High)

The 'From' address of outgoing messages may be spoofed as follows:

james@(target domain.com)
Such as
james@abc.com
james@xyz.com
etc
 

EyeMWing

Banned
Jun 13, 2003
15,670
1
0
Avert is currently analyzing an additional payload of the worm. The following email address are encrypted within the virus body and are believed to be used to send captured information to:

* omnibbb@gmx.net
* drbz@mail15.com
* omnibcd@gmx.net
* kxva@mail15.com

DESTROY THEM!

Open the floodgates to hell! Unleash your collections of ancient and obscure virii. CODE YOUR OWN! Do everything within your power and abilities.
 

Originally posted by: EyeMWing
Avert is currently analyzing an additional payload of the worm. The following email address are encrypted within the virus body and are believed to be used to send captured information to:

* omnibbb@gmx.net
* drbz@mail15.com
* omnibcd@gmx.net
* kxva@mail15.com

DESTROY THEM!

Open the floodgates to hell! Unleash your collections of ancient and obscure virii. CODE YOUR OWN! Do everything within your power and abilities.

HACK THE GIBSON!
 

jamautosound

Diamond Member
Oct 15, 2000
6,754
0
76
Originally posted by: shinerburke
W32/Mimail.c@MM

Info here

Idiot virus writers....we should beat them all with printer cables.

Thanks for the heads up.


. . . and I think we should beat them with printer cables, with the printers still attached! :evil:
 

EyeMWing

Banned
Jun 13, 2003
15,670
1
0
Originally posted by: FallenHero
Originally posted by: EyeMWing
Avert is currently analyzing an additional payload of the worm. The following email address are encrypted within the virus body and are believed to be used to send captured information to:

* omnibbb@gmx.net
* drbz@mail15.com
* omnibcd@gmx.net
* kxva@mail15.com

DESTROY THEM!

Open the floodgates to hell! Unleash your collections of ancient and obscure virii. CODE YOUR OWN! Do everything within your power and abilities.

HACK THE GIBSON!

This ain't no gibson - these are loser ass script kiddies. Much more worthwhile target.
 

If these guys could write english better, mabey more people would fall for it.
 

cLe0

Member
Oct 30, 2003
113
0
0
yeap. i received an email warning from my school's Manager of Networking and Operations this morning and in good timing too because i received an email containing that worm in another inbox just a while ago. Pretty tempting email I have to say. :D
 

Zenmervolt

Elite member
Oct 22, 2000
24,514
41
91
Originally posted by: redly1
hehe...with printer cables. How about old surplus keyboards?
Well, an old IBM Model M might be good for beating a person, but I'd rather use it to type with.

ZV
 

oniq

Banned
Feb 17, 2002
4,196
0
0
Originally posted by: EyeMWing
Originally posted by: FallenHero
Originally posted by: EyeMWing
Avert is currently analyzing an additional payload of the worm. The following email address are encrypted within the virus body and are believed to be used to send captured information to:

* omnibbb@gmx.net
* drbz@mail15.com
* omnibcd@gmx.net
* kxva@mail15.com

DESTROY THEM!

Open the floodgates to hell! Unleash your collections of ancient and obscure virii. CODE YOUR OWN! Do everything within your power and abilities.

HACK THE GIBSON!

This ain't no gibson - these are loser ass script kiddies. Much more worthwhile target.

Theres a script that makes viruses for people? Wow..
 

shabby

Diamond Member
Oct 9, 1999
5,782
45
91
I dont rely on nav anymore, i just use mailwasher to check my mail.
Even if i open the email i dont get infected, i just click on bounce and it sends it back to the sender and blacklists the email addy, easy as pie.... mmm pie :)
 

compudog

Diamond Member
Apr 25, 2001
5,782
0
71
I'd like to smack 'em up with a few MFM/RLL drives. Those things would leave a mark. Thanks for the heads up.

<===runs to update defs...
 

Medea

Golden Member
Dec 5, 2000
1,606
0
0
Originally posted by: shabby
I dont rely on nav anymore, i just use mailwasher to check my mail.
Even if i open the email i dont get infected, i just click on bounce and it sends it back to the sender and blacklists the email addy, easy as pie.... mmm pie :)

Yep. Convenient [and safe] isn't it? :cool: