Grey03.eml and jpg file... Virus??????
Results 1 to 10 of 10

Thread: Grey03.eml and jpg file... Virus??????

  1. #1
    Registered User
    Join Date
    Jul 2000
    Posts
    447

    Post Grey03.eml and jpg file... Virus??????

    I just came back from one of our clients offices where there are several computers that are Infected with a file named grey03.eml. I found 164 instances of this file as well as one file named Grey03.jpg (photo of a rather homely looking woman standing in front of a block wall) and several more of grey03.scr. I know the .eml is an e-mail file and .scr is a script file. Does anyone know what virus they are associated with??

    Any help would be GREATLY appreciated.

  2. #2
    Registered User Stalemate's Avatar
    Join Date
    May 2001
    Location
    d4-e5
    Posts
    15,120

    Post

    <a href="http://securityresponse.symantec.com/avcenter/venc/data/[email protected]" target="_blank">Nimda</a> uses the *.eml extension and you may also have a variant of <a href="http://securityresponse.symantec.com/avcenter/venc/data/[email protected]" target="_blank">goner</a> whiche uses *.scr.

    Grey03.jpg is probably the file nimda emulated to start transferring itself. It did the same thing at my workplace with a couple of "good" files.

    Good luck

  3. #3
    Registered User
    Join Date
    Jul 2000
    Posts
    447

    Post

    Thanks, Looks like Nimda.d is the culprit.

  4. #4
    Registered User Stalemate's Avatar
    Join Date
    May 2001
    Location
    d4-e5
    Posts
    15,120

    Post

    [quote]Originally posted by *MAYHEM*:
    <strong>Thanks, Looks like Nimda.d is the culprit.</strong><hr></blockquote>

    Sorry to hear that.

    My condolences for your weekend, as you'll probably be spending it cleaning out your servers and workstations

  5. #5
    Registered User Gabriel's Avatar
    Join Date
    Aug 2000
    Location
    Tel Aviv Israel
    Posts
    2,161

    Post

    Sorry I can't help it...
    THE JOY of using Mcafee Groupshield for exchange....

  6. #6
    Banned Ya_know's Avatar
    Join Date
    Jun 2001
    Posts
    10,692

    Post

    It looks like these guys have you squared away. I just wanted to correct a mistake you made in your first post. The SCR file extension is typically associated with screen savers. I have not heard of its use with scripts.

  7. #7
    Intel Mod Platypus's Avatar
    Join Date
    Jan 2001
    Location
    Australia
    Posts
    5,783

    Post

    Yep, as a screensaver is an executable file, .SCR is likely to be used by malicious code since it is accepted by Windows as a default extension for executables.

  8. #8
    Registered User Gabriel's Avatar
    Join Date
    Aug 2000
    Location
    Tel Aviv Israel
    Posts
    2,161

    Post

    you can almost be sure about exe...
    goto Command prompt (or the beloved DOS).
    DO:
    type filename.scr (exe, com whatever).
    you can clearly see the Header is similar
    MZ

    Every compiled Executables gets this MZ header.
    If I'm Correct this MZ is the Initials of the guy who first produced it.

  9. #9
    Registered User Stalemate's Avatar
    Join Date
    May 2001
    Location
    d4-e5
    Posts
    15,120

    Post

    [quote]Originally posted by Gabriel:
    <strong>Sorry I can't help it...
    THE JOY of using Mcafee Groupshield for exchange....</strong><hr></blockquote>

    You mean you do use Groupshield?

    How do you like it against this type of virus infection?

  10. #10
    Intel Mod Platypus's Avatar
    Join Date
    Jan 2001
    Location
    Australia
    Posts
    5,783

    Post

    [quote]Originally posted by Gabriel:
    <strong>
    Every compiled Executables gets this MZ header.
    If I'm Correct this MZ is the Initials of the guy who first produced it.</strong><hr></blockquote>

    Yup, Mark Zbikowsi.

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •