Page 9 of 9 FirstFirst ... 789
Results 81 to 83 of 83

Thread: Virus Alert: Novarg / MiMail / MyDoom

  1. #81
    Antionline Herpetologist
    Join Date
    Aug 2001
    Posts
    1,165
    I'm just going to install a fresh copy of XP on another partition and play with the damn virus. I'll let you know what I find.
    Cheers,
    cgkanchi
    Buy the Snakes of India book, support research and education (sorry the website has been discontinued)
    My blog: http://biology000.blogspot.com

  2. #82
    Senior Member
    Join Date
    Jun 2003
    Posts
    236
    ive actually been spending a lot of time with this virus.
    My assembly skills are not the sharpest but Ive decompiled and figured out as much as possible
    I dont see anywhere where it attempts to mess with the bios

    cgkanchi
    I wish I would have made another partition or ran on a vmware because I managed to infect myself when I played with it on windows...anyways heres some things that helped me

    the email comes mime encoded -> linux tool mpuck can encode and decode mime
    the executable is upx encoded -> upx tool (multi-platform) can encode and decode upx
    at this point your can perform some reverse engineering
    linux 'strings' will actually produce quite a few the names and email extensions are plainly visible but he/she attempts to hide many of the registry and system i/o with a ceasar cipher of right shift 13 characters


    id be interested in hearing any other things you find
    That which does not kill me makes me stronger -- Friedrich Nietzche

  3. #83

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •