Security Basics mailing list archives

Re: Possible Virus or trojan?


From: "Lou" <LouC () tmlp com>
Date: Mon, 3 Nov 2003 12:53:20 -0500

semi-new virus, read about it here  =>
http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.c () mm html
_LC_
----- Original Message ----- 
From: "PAUL NICKELSON" <pjn308 () yahoo com>
To: <security-basics () securityfocus com>
Sent: Friday, October 31, 2003 11:07 AM
Subject: Possible Virus or trojan?


Has anyone ever seen an email with the following body?


Re[2]: our private photos ocooeaoe
Importance: High



Hello Dear!,

Finally i've found possibility to right u, my lovely
girl :)
All our photos which i've made at the beach (even when
u're without ur bh:))
photos are great! This evening i'll come and we'll
make the best SEX :)

Right now enjoy the photos.
Kiss, James.
ocooeaoe

With an attached file named photos.zip and within
that, photo.jpg.exe.  Is this something new or a
targeted attack?  I did find a reference to
netwatch.exe in hex editor and if installed will start
netwatch.exe.  Thanks.

__________________________________
Do you Yahoo!?
Exclusive Video Premiere - Britney Spears
http://launch.yahoo.com/promos/britneyspears/

--------------------------------------------------------------------------
-
Forum Systems PRESIDIO: PGP / XML GATEWAY APPLIANCE
The Presidio integrates PGP data encryption and XML Web Services security
to
simplify the management and deployment of PGP and reduce overall PGP costs
by up to 80%.
FREE WHITEPAPER & 30 Day Trial -
http://www.securityfocus.com/sponsor/ForumSystems_security-basics_031027
--------------------------------------------------------------------------
--




---------------------------------------------------------------------------
Forum Systems PRESIDIO: PGP / XML GATEWAY APPLIANCE
The Presidio integrates PGP data encryption and XML Web Services security to 
simplify the management and deployment of PGP and reduce overall PGP costs 
by up to 80%.
FREE WHITEPAPER & 30 Day Trial - 
http://www.securityfocus.com/sponsor/ForumSystems_security-basics_031027 
----------------------------------------------------------------------------


Current thread: