Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Jan 8th, 2009, 11:11am
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   Mimail.I
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Mimail.I  (Read 285 times)
Ian
Stole All the Forum Stars
********



Good things come to those who wait ...

   


Posts: 2913
Mimail.I
« on: Nov 17th, 2003, 8:58pm »
Quote Quote  Modify Modify

W32/Mimail.I.worm. I wonder if there'll be a race to see who can come up with a 'Z' variant of something?

This variant, like its predecessors, is designed to spread rapidly in e-mail messages that use so-called social engineering techniques to trick users and infect their computers. In this particular case, the message refers to the  PAYPAL payment system.
 
Mimail.I arrives in an e-mail with the subject: YOUR PAYPAL.COM ACCOUNT EXPIRES, while the message text tells users that they should update their PAYPAL account as it is about to expire.
 
The attachment that accompanies the message is called either w w w.paypal.com.scr or paypal.asp.scr. If the user runs the file, Mimail.I searches the computer for e-mail addresses in all files on the computer with extensions other than: COM, WAV, CAB, PDF, RAR, ZIP, TIF, PSD, OCX, VXD, MP3, MPG, AVI, DLL, EXE, GIF, JPG and BMP. These addresses are stored in a file called el388.tmp. The worm then uses its own SMTP engine to send itself to these addresses, without the user being aware of what's happening.
 
Mimail.I generates other files (EE98AF.TMP and SVCHOST32.EXE) in the computer, which are really copies of the worm itself.  
 
Finally, creates a Windows registry entry in order to ensure it is run every time the system is started up.  
 
Mimail.I is the latest in a string of variants that have appeared over the last few weeks. It would therefore seem that the author or authors of these viruses want to spread as many worms as possible in order to increase the probability of a computer being hit by a variant of Mimail.
IP Logged

... but crap arrives pretty much straight away.
claire
Stole All the Forum Stars
********



carpe diem

   


Gender: female
Posts: 3479
Re: Mimail.I
« Reply #1 on: Nov 17th, 2003, 9:18pm »
Quote Quote  Modify Modify

Thanks for the heads up Ian.I suppose everybody here has his
AV updated Wink Grin
IP Logged

Claire
Ian
Stole All the Forum Stars
********



Good things come to those who wait ...

   


Posts: 2913
Re: Mimail.I
« Reply #2 on: Nov 17th, 2003, 9:26pm »
Quote Quote  Modify Modify

You'd hope so, but never know... Grin
IP Logged

... but crap arrives pretty much straight away.
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register