Club Cobra Keith Craft Racing  

Go Back   Club Cobra > Cobra Talk Areas > ALL COBRA TALK

MMG Superformance
Nevada Classics
MMG Superformance
Main Menu
Module Jump:
Nevada Classics
Nevada Classics
MMG Superformance
Keith Craft Racing
Advertise at CC
Banner Ad Rates
MMG Superformance
MMG Superformance
November 2025
S M T W T F S
            1
2 3 4 5 6 7 8
9 10 11 12 13 14 15
16 17 18 19 20 21 22
23 24 25 26 27 28 29
30            

Kirkham Motorsports

 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #11 (permalink)  
Old 01-26-2004, 08:46 PM
computerworks's Avatar
Senior Club Cobra Member
Visit my Photo Gallery
Lifetime Contributor
 
Join Date: Mar 2001
Location: Northport, NY
Cobra Make, Engine: Kirkham, KMP178 / '66 GT350H, 4-speed
Posts: 10,362
Not Ranked     
Default

(Sorry for the long-winded, techie stuff here, but this worm may get epidemic in the next few days).

As of this evening, both McAfee and Trend Micro Antivirus software will detect and fix this worm, as well as Norton. McAfee recognizes it as W32/Mydoom@MM and Trend sees it as WORM_MIMAIL.R.

If you did open the attachment, it did the following:

It creates the following files:

"shimgapi.dll" in %System%
"Message" in %temp%. This file is full of random letters and is displayed via Notepad.
"taskmon.exe" in %System%. If a copy of taskmon.exe exists in the %System%, it is overwritten and replaced by this copy of the worm.


Shimgapi.dll acts as a proxy server. It opens TCP ports in the range of 3127 to 3198 for listening.


Adds the value
TaskMon = %System%\taskmon.exe
to the registry keys
HKEY_CURRENT_USER\Software\Microsft\Windows\Curren tVersion\Run
and
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run


Can perform a Denial of Service against www.sco.com. Creates 64 threads which send GET requests. The DoS is active between February 1, 2004 and February 12, 2004.


Creates the following registry keys:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\
Explorer\ComDlg32\Version
and
HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\
Explorer\ComDlg32\Version


Searches for email addresses in files with the following extensions. It ignores addresses which end in ".edu".

.htm
.sht
.php
.asp
.dbx
.tbb
.adb
.pl
.wab
.txt


Attempts to send emails by using its own SMTP engine. It performs a lookup of the mail server of the recipient in order to send. If it is unsuccessful it will use the local mail server.


The email will have the following characteristics:

From: may be a spoofed from address
Subject:
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error

Message:
Mail transaction failed. Partial message is available.
The message contains Unicode characters and has been sent as a binary attachment.
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.

Attachment:
document
readme
doc
text
file
data
test
message
body

with one of the following suffixes:
pif
scr
exe
cmd
bat
zip


Copies itself to KaZaA download directory as one of the following files:

winamp5
icq2004-final
activation_crack
strip-girl-2.0bdcom_patches
rootkitXP
office_crack
nuke2004

with a file extension of pif or scr or bat

To get rid of it

Update your virus defitions, disconnect from the internet, scan and delete any file that is found to be infected.

Then, CAREFULLY edit the Registry to remove the starter files:
(If you have never edited the Registry, and are unsure of what you are doing, as for help from someone who can do it)

Click Start, and then click Run. (The Run dialog box appears.)
Type regedit

Then click OK. (The Registry Editor opens.)

Navigate to the keys:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
and
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run

In the right pane, delete the value:

"Taskmon"="%System%\taskmon.exe"


Navigate to the key

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\
Explorer\ComDlg32\Version

and delete it.


Navigate to the key

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\
Explorer\ComDlg32\Version

and delete it.

Exit the Registry Editor.
Reply With Quote
 


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 03:18 AM.


Powered by vBulletin® Version 3.8.0
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Search Engine Friendly URLs by vBSEO 3.6.0
The representations expressed are the representations and opinions of the clubcobra.com forum members and do not necessarily reflect the opinions and viewpoints of the site owners, moderators, Shelby American, any other replica manufacturer, Ford Motor Company. This website has been planned and developed by clubcobra.com and its forum members and should not be construed as being endorsed by Ford Motor Company, or Shelby American or any other manufacturer unless expressly noted by that entity. "Cobra" and the Cobra logo are registered trademarks for Ford Motor Co., Inc. clubcobra.com forum members agree not to post any copyrighted material unless the copyrighted material is owned by you. Although we do not and cannot review the messages posted and are not responsible for the content of any of these messages, we reserve the right to delete any message for any reason whatsoever. You remain solely responsible for the content of your messages, and you agree to indemnify and hold us harmless with respect to any claim based upon transmission of your message(s). Thank you for visiting clubcobra.com. For full policy documentation refer to the following link: CC Policy
Links monetized by VigLink