RE: New Virus?

From: Dan Denton (ddenton_at_PAYLESSOFFICE.com)
Date: 06/28/05

  • Next message: Nick Duda: "RE: program to store passwords"
    Date: Tue, 28 Jun 2005 16:28:22 -0500
    To: "Hamish Stanaway" <koremeltdown@hotmail.com>, <security-basics@securityfocus.com>
    
    

    I would also be interested in seeing if anyone else know what this is.
    One of our users received an email with the same identical subject line,
    with the attachment 'new.zip'. The email also had an identical user
    name, but from 'roi.net'. We quarantine zip files at the mail gateway
    before it actually gets scanned, so I've no idea what it is either.

    -----Original Message-----
    From: Hamish Stanaway [mailto:koremeltdown@hotmail.com]
    Sent: Monday, June 27, 2005 5:42 PM
    To: security-basics@securityfocus.com
    Subject: New Virus?

    Hey there everyone,

    I recieved a mysterious email this morning at 1728 GMT which had headers
    as
    follows:

    Return-path: <hamish1@voyager.co.nz>
    Envelope-to: hamish1@webhosting.net.nz
    Delivery-date: Tue, 28 Jun 2005 05:22:44 +1200
    Received: from [217.125.252.60] (helo=david.org)
            by fearless.absolutewebhosting.biz with smtp (Exim 4.24)
            id 1DmxJg-0003ou-Rg
            for hamish1@webhosting.net.nz; Tue, 28 Jun 2005 05:22:41 +1200
    Date: Mon, 27 Jun 2005 19:20:42 +0100
    To: "Hamish" <hamish1@webhosting.net.nz>
    From: "Hamish" <hamish1@voyager.co.nz>
    Subject: The picture is sent on SMS
    Message-ID: <pvkpnopcnwraqblcgfg@webhosting.net.nz>
    MIME-Version: 1.0
    Content-Type: multipart/mixed;
            boundary="--------hukvuvgobciyuhmojdug"

    -------------------- END SNIP-----------------------

    As you can guess, I'm hamish1@webhosting.net.nz.
    This email contained no text, only an attachment called legs.zip, which
    Norton (fully updated to its' latest version and data files) did not
    detect
    any viruses in.
    Within the legs.zip file there is a file called ds-rwe.exe - this again
    was
    not detected as a virus.
    My girlfriend thought she would be smart and ran ds-rwe.exe, which gave
    me a
    memory overflow message for explorer.exe immidiately.
    Does anyone have any idea of what this might be, and also if it is a
    virus
    that has already been identified? If not, I am willing to pass it
    through to
    someone to take a look at in its' zip format.
    Otherwise if the effects cannot be reversed, I am afraid I will have to
    reformat this machine *sigh* NOT AGAIN :(
    Have a great day everyone and thanks in advance for your help.

    Kindest of regards,

    Hamish Stanaway, CEO

    Absolute Web Hosting / -= KoRe WoRkS =- Internet Security Auckland, New
    Zealand

    http://www.webhosting.net.nz
    http://www.buywebhosting.co.nz
    http://www.koreworks.com


  • Next message: Nick Duda: "RE: program to store passwords"

    Relevant Pages

    • New Virus?
      ... I recieved a mysterious email this morning at 1728 GMT which had headers as ... The picture is sent on SMS ...
      (Security-Basics)
    • RE: Messenger Pro 3 from Clickatell.{Allows you to spoof Mobile Numbers}
      ... email message, it is arbitrary and can contain anything. ... possession of an SMS gateway can set the Sender ID to any alphanumeric ... the level of trust on creating SMS headers to their users. ...
      (Vuln-Dev)
    • RE: [SLE] OT: Candada
      ... I forgot to add that this is a cell phone. ... i used to beable to sms and my ... Check the headers for your unsubscription address For additional commands send e-mail to suse-linux-e-help@suse.com Also check the archives at http://lists.suse.com Please read the FAQs: suse-linux-e-faq@suse.com -- ...
      (SuSE)
    • Re: Need Cingular Subscriber to help me with SMS/MMS test
      ... With regard to Cingular accounts: ... YOURNUMBER@xxxxxxxxxxxxxx sends an SMS text message to your phone (no ... picture). ... YOURMEdiaID@xxxxxxxxxxxxxx sends an email to your Cingular email, ...
      (alt.cellular.cingular)
    • Re: Header and Footer missing: Word 2003 doc edited in Word 2000
      ... A white square in front of the picture)? ... Normal view does not show headers and footers. ... I have researched to no avail and yes I have read about showing whitespace. ...
      (microsoft.public.word.docmanagement)