goto UNSW  home page
CONTACTS
Notices
 IT Notices forums
 Security: AL-2005.0043 [Win]
 Magellan disk corruption
 Power shutdown July 6 2005
 Magellan new disk rollout
 Newt RAID5 rollout
 Telnet and FTP service
 Mimail.D virus
 Sobig.E virus
 Newt replacement
 Bugbear worm
 W32/klez
 Nimda worm

Help
 Physics Mail
 Secure Shell
 Cygwin X11 Server
 Paper guidelines
 Helpdesk
 Request help
 Contact us

Downloads
 Software
 Account application PDF
 Useful mirrors

Network connection
 Network Access Request
 Network settings

Info exchange
 Physics e-mail lists
 School forums
 Computing forum

Documentation
 Workstation Guide HTML/PDF
 PDF Scanning
 Computing Facilities
 Workstation Software
 UN*X Security Guide
 Multimedia Facility
 CD creation quick guide
 OCR quick guide
 C Language Course Notes
 DEC F77 guide
 Proxy information

Quicklinks
 Physics IT Support
 School of Physics
 Linux links
 AARnet Mirror
 Web design
 Web statistics

Mimail.D virus

Another mass-mailing worm affecting Microsoft Windows operating systems.

Operating systems affected

  • Windows 95
  • Windows 98
  • Windows ME
  • Windows NT
  • Windows 2000
  • Windows XP

Email characteristics

Most vendors have a different version of the email, such as;

Subject: Re[2]: our private photos ???
Attachment: readnow.zip

______________
From: james@
Subject: don't be late! [random string of letters] Message Body:
Hello Dear!,
Finally i've found possibility to right u, my lovely girl :) All our photos which i've made at the beach (even when u're without ur bh:)) photos are great! This evening i'll come and we'll make the best SEX :)

Right now enjoy the photos.
Kiss, James.
??? (Note: ??? is a variable string)
Attachment: photos.zip

Bulletin from ACSU

------ Forwarded message ----------
Date: Mon, 3 Nov 2003 10:56:31 +1100
From: ACSU Anti-Virus Support
To: IT-Support@explode.unsw.edu.au
Subject: [IT] VIRUS ADVISORY - Mimail

Most antivirus vendors have the Mimail.C or Mimail.D virus on medium alert. Mimail is a mass mailing worm that sends a variation of fairly standard emails with a .zip attachment. It steals user info and does a DoS on selected sites. Affects Windows 95, 98, ME, NT, 2000, XP.

There seem to be a few variants of the basic virus so have a look at a few vendor sites for info.

DETECTION:

NOTE: Norton AntiVirus Definitions dated 01/11/2003 or later. Some systems will display this date as 11/01/2003.

REMOVAL TOOL:

http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.removal.tool.html

MORE INFORMATION:

http://securityresponse.symantec.com/avcenter/venc/data/w32.mimail.d@mm.html

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MIMAIL.C&VSect=T

  CRICOS Provider Code - 00098G Disclaimer
School of Physics - The University of New South Wales - Sydney Australia 2052
Site comments physicsweb@phys.unsw.edu.au © School of Physics UNSW