Home > Archive > microsoft.public.cert.exams.mcse > January 2004 > New MiMail threat





You are viewing an archived Text-only version of the thread. To view this thread in it's original format and/or if you want to reply to this thread please [click here]

Author New MiMail threat
Larry Samuels

2004-01-29, 11:23 am

MiMail.S (new highly polymorphic variant)
http://www.symantec.com/avcenter/ve...imail.s@mm.html
http://vil.nai.com/vil/content/v_100989.htm
http://www.f-secure.com/v-descs/mimail_s.shtml

W32.Mimail.S@mm is variant of W32.Mimail.A@mm. The worms display a
dialog box prompting you for credit card information. The worm scans
infected computers for email addresses, sending itself as an attachment
to the addresses found. The message body and subject lines can vary.

This one is highly polymorphic:

Subject of email: Varies
Name of attachment: Varies with .exe, .pif, or .scr file extension
Size of attachment: 11,520 bytes
Time stamp of attachment: n/a



Consultant

2004-01-29, 12:23 pm

how does this relate to the mcse certification?

"Larry Samuels" <larry@mvps.org> wrote in message
news:uh2k61n5DHA.2760@TK2MSFTNGP09.phx.gbl...
> MiMail.S (new highly polymorphic variant)
> http://www.symantec.com/avcenter/ve...imail.s@mm.html
> http://vil.nai.com/vil/content/v_100989.htm
> http://www.f-secure.com/v-descs/mimail_s.shtml
>
> W32.Mimail.S@mm is variant of W32.Mimail.A@mm. The worms display a
> dialog box prompting you for credit card information. The worm scans
> infected computers for email addresses, sending itself as an attachment
> to the addresses found. The message body and subject lines can vary.
>
> This one is highly polymorphic:
>
> Subject of email: Varies
> Name of attachment: Varies with .exe, .pif, or .scr file extension
> Size of attachment: 11,520 bytes
> Time stamp of attachment: n/a
>
>
>



Larry Samuels

2004-01-29, 12:23 pm

Anyone working as a network admin needs to be on the lookout for this one.
Since hopefully most of us here are actually working in the industry (as
opposed to going for bootcamps and braindumps to try getting into the
industry) I thought it was relevant.

--
Larry Samuels
Unofficial FAQ for Windows Server 2003 at
http://pelos.us/SERVER.htm

"Consultant" < consultant_mcngp_removepants@y
ahoo.com> wrote in message
news:ejZylWo5DHA.2524@TK2MSFTNGP11.phx.gbl...
> how does this relate to the mcse certification?
>
> "Larry Samuels" <larry@mvps.org> wrote in message
> news:uh2k61n5DHA.2760@TK2MSFTNGP09.phx.gbl...
>
>



Consultant

2004-01-29, 12:23 pm

i agree those who work on a network should be aware of this and other
threats. that is why there are subscriptions to sans, etc. this is not
tested as part of the mcse and therefore is irrelevant to this forum.


"Larry Samuels" <larry@mvps.org> wrote in message
news:OBLA$bo5DHA.1592@TK2MSFTNGP10.phx.gbl...
> Anyone working as a network admin needs to be on the lookout for this one.
> Since hopefully most of us here are actually working in the industry (as
> opposed to going for bootcamps and braindumps to try getting into the
> industry) I thought it was relevant.
>
> --
> Larry Samuels
> Unofficial FAQ for Windows Server 2003 at
> http://pelos.us/SERVER.htm
>
> "Consultant" < consultant_mcngp_removepants@y
ahoo.com> wrote in message
> news:ejZylWo5DHA.2524@TK2MSFTNGP11.phx.gbl...
>
>



Politician Spock

2004-01-29, 12:23 pm

Certainly applicable to the audience, but an "OT -" in the subject would be
appreciated.

--
Politician Spock
Thug #24601


"Larry Samuels" <larry@mvps.org> wrote in message
news:OBLA$bo5DHA.1592@TK2MSFTNGP10.phx.gbl...
> Anyone working as a network admin needs to be on the lookout for this one.
> Since hopefully most of us here are actually working in the industry (as
> opposed to going for bootcamps and braindumps to try getting into the
> industry) I thought it was relevant.
>
> --
> Larry Samuels
> Unofficial FAQ for Windows Server 2003 at
> http://pelos.us/SERVER.htm
>
> "Consultant" < consultant_mcngp_removepants@y
ahoo.com> wrote in message
> news:ejZylWo5DHA.2524@TK2MSFTNGP11.phx.gbl...
>
>



JaR

2004-01-29, 1:23 pm

"Politician Spock" <rhammersmith@hotmail.com> wrote in message
news:uHyePno5DHA.2392@TK2MSFTNGP11.phx.gbl...
> Certainly applicable to the audience, but an "OT -" in the subject would

be
> appreciated.
>

Picky, picky, picky


John W. Thompson

2004-01-29, 3:23 pm

Dear Mr. Samuels,

I would like you to know that I do not appreciate you posting computer
virus outbreak security alerts onto this Microsoft newsgroup. I am getting
inundated with calls by poor scared to death unsuspecting newbie wannabie
MCSE candidates asking me how to better protect their silly Braindumps.

Please stop this at once otherwise I will have to take legal action.

Sincerely,
John W. Thompson
CEO and Chairman of Symantec Corporation
http://www.symantec.com/corporate/ceo.html


"Larry Samuels" <larry@mvps.org> wrote in news:OBLA$bo5DHA.1592
@TK2MSFTNGP10.phx.gbl:

> Anyone working as a network admin needs to be on the lookout for this

one.
> Since hopefully most of us here are actually working in the industry (as
> opposed to going for bootcamps and braindumps to try getting into the
> industry) I thought it was relevant.
>


JaR

2004-01-29, 4:23 pm

"John W. Thompson" <johnWthompson@symantec.com> wrote in message
news:Xns947F954B3F157rowdyyate
s2123@207.46.248.16...
> Dear Mr. Samuels,
>
> I would like you to know that I do not appreciate you posting computer
> virus outbreak security alerts onto this Microsoft newsgroup. I am getting
> inundated with calls by poor scared to death unsuspecting newbie wannabie
> MCSE candidates asking me how to better protect their silly Braindumps.
>
> Please stop this at once otherwise I will have to take legal action.
>
>


Well, there goes another perfectly good keyboard.


John W. Thompson

2004-01-29, 4:23 pm

Memo to Judy the intern

RE: Keyboard replacement

Dear Judy,

Please arrange for new Symantec keyboard with special delete virus key to
be shipped to JaR.

Sincerely,
John W. Thompson
CEO and Chairman of Symantec Corporation
http://www.symantec.com/corporate/ceo.html


"JaR" <plente@nospamsofthome.net> wrote in news:#TJ$JPq5DHA.2312
@TK2MSFTNGP12.phx.gbl:

> "John W. Thompson" <johnWthompson@symantec.com> wrote in message
> news:Xns947F954B3F157rowdyyate
s2123@207.46.248.16...
getting[color=blue]
wannabie[color=blue]
>
> Well, there goes another perfectly good keyboard.
>
>


Brat

2004-01-29, 4:23 pm

"NNTP-Posting-Host: pcws185.dur.utoronto.ca 128.100.87.227" <--- hmmmm I
wonder who lives in Toronto...


and no it is not me :P

--
Sue "I do, do you?" Thugette #69

"John W. Thompson" <johnWthompson@symantec.com> wrote in message
news:Xns947F954B3F157rowdyyate
s2123@207.46.248.16...
> Dear Mr. Samuels,
>
> I would like you to know that I do not appreciate you posting computer
> virus outbreak security alerts onto this Microsoft newsgroup. I am getting
> inundated with calls by poor scared to death unsuspecting newbie wannabie
> MCSE candidates asking me how to better protect their silly Braindumps.
>
> Please stop this at once otherwise I will have to take legal action.
>
> Sincerely,
> John W. Thompson
> CEO and Chairman of Symantec Corporation
> http://www.symantec.com/corporate/ceo.html
>
>
> "Larry Samuels" <larry@mvps.org> wrote in news:OBLA$bo5DHA.1592
> @TK2MSFTNGP10.phx.gbl:
>
> one.
>



Rowdy Yates

2004-01-29, 4:23 pm

Hey, what the hell's going on! that's one of my users.

<rowdy gets cranks up the Bolivian torture device - runs out of room in a
rage - looking for the poor SOB>


"Brat" < likeIwouldtellyou@inyourdreams
.com> wrote in news:#0iQ8Zq5DHA.1672
@TK2MSFTNGP12.phx.gbl:

> "NNTP-Posting-Host: pcws185.dur.utoronto.ca 128.100.87.227" <--- hmmmm I
> wonder who lives in Toronto...
>
>
> and no it is not me :P
>




--
The Champ comes out swinging every morning @ 9AM.
Remove the "removethis" from email address to email me.
==============
I am Against-TCPA
http://www.againsttcpa.com
==============
Brat

2004-01-29, 4:23 pm

lol :P

--
Sue Thugette #69

"Rowdy Yates" <rowdy_yates2@removethis.lycos.com> wrote in message
news:Xns947F9E72EDE86rowdyyate
s2123@207.46.248.16...
> Hey, what the hell's going on! that's one of my users.
>
> <rowdy gets cranks up the Bolivian torture device - runs out of room in a
> rage - looking for the poor SOB>
>
>
> "Brat" < likeIwouldtellyou@inyourdreams
.com> wrote in news:#0iQ8Zq5DHA.1672
> @TK2MSFTNGP12.phx.gbl:
>
>
>
>
> --
> The Champ comes out swinging every morning @ 9AM.
> Remove the "removethis" from email address to email me.
> ==============
> I am Against-TCPA
> http://www.againsttcpa.com
> ==============



The Poster Formerly Known as Kline Sphere

2004-01-29, 4:23 pm

>Please arrange for new Symantec keyboard with special delete virus key to
>be shipped to JaR.


Would it be too much trouble to send me one as well?

Thank you.

Kline Sphere (Chalk) MCNGP #3
JaR

2004-01-29, 4:23 pm

"Rowdy Yates" <rowdy_yates2@removethis.lycos.com> wrote in message
news:Xns947F9E72EDE86rowdyyate
s2123@207.46.248.16...
> Hey, what the hell's going on! that's one of my users.
>


Awwww! I s'pose this means I'm not gonna get that shiney! new keyboard
w/virus delete key?

>cranks up the Bolivian torture device -


Can I get one of ^ those ^ instead?

JaR
Thug Torquemada


The Poster Formerly Known as Kline Sphere

2004-01-29, 4:23 pm

>>cranks up the Bolivian torture device -
>
>Can I get one of ^ those ^ instead?


Why do you want one of those? So you can torture newbies? You thug
you, people like you make me sick.

Kline Sphere (Chalk) MCNGP #3
Larry Samuels

2004-01-29, 5:23 pm

OK Rowdy--you get to come clean the coffee off my monitor and keyboard.

--
Larry Samuels
Unofficial FAQ for Windows Server 2003 at
http://pelos.us/SERVER.htm

"Rowdy Yates" <rowdy_yates2@removethis.lycos.com> wrote in message
news:Xns947F9E72EDE86rowdyyate
s2123@207.46.248.16...
> Hey, what the hell's going on! that's one of my users.
>
> <rowdy gets cranks up the Bolivian torture device - runs out of room in a
> rage - looking for the poor SOB>
>
>
> "Brat" < likeIwouldtellyou@inyourdreams
.com> wrote in news:#0iQ8Zq5DHA.1672
> @TK2MSFTNGP12.phx.gbl:
>
>
>
>
> --
> The Champ comes out swinging every morning @ 9AM.
> Remove the "removethis" from email address to email me.
> ==============
> I am Against-TCPA
> http://www.againsttcpa.com
> ==============



The Poster Formerly Known as Kline Sphere

2004-01-29, 5:23 pm

>OK Rowdy--you get to come clean the coffee off my monitor and keyboard.

Can't you out source that to someone in India?

Kline Sphere (Chalk) MCNGP #3
JaR

2004-01-29, 5:23 pm


"The Poster Formerly Known as Kline Sphere" <.> wrote in message
news:3dti10dukfgqcqdq4k93prf2c
cbncq13br@4ax.com...
> Why do you want one of those? So you can torture newbies? You thug
> you, people like you make me sick.
>
>

Ahhh. Thank you. It is good to be recognized by others in one's field.

JaR
Modest Thug


JaR

2004-01-29, 5:23 pm

"The Poster Formerly Known as Kline Sphere" <.> wrote in message
news:3cui1012tvnp5p65cohp106j8
ut2nr65gq@4ax.com...
> Can't you out source that to someone in India?
>


He doesn't need to. That's what H1B's are for.


Rowdy Yates

2004-01-29, 7:23 pm

Hey, enough of that!! what are you trying to do? get me out of a job?

The Poster Formerly Known as Kline Sphere <.> wrote in
news:3cui1012tvnp5p65cohp106j8
ut2nr65gq@4ax.com:

>
> Can't you out source that to someone in India?
>
> Kline Sphere (Chalk) MCNGP #3




--
Rowdy Yates
I am Against-TCPA
http://www.againsttcpa.com
Sponsored Links





Free Braindumps | MCSE braindumps software forum

Copyright 2003 - 2008 examnotes.net