MiMail worm free removal tool
A NEW variant of the MiMail worm family, version C, is proliferating across the world, according to security firm iDefense.
|
A NEW variant of the MiMail worm family, version C, is proliferating across the world, according to security firm iDefense.
MiMail.C has a DDoS component to attack DarkProfits domains and there's likely to be increased activity on Port 80, according to Ken Dunham a security officer at the firm.
He says it's dangerous for corporation, many of which allow people to transfer ZIP files to each other using email.
That means, he says, that MiMail.C "has the upper hand when infiltrating networks configured to allow ZIP attachments".
Symptoms:
Presence of the following file in Windows System directory: SMVC32.EXE
Presence of the following registry key:
HKEY_LOCAL_MACHINESoftwareMicrosoftCurrentVersionRun
with the value:
SMVC = %SYSDIR%SMVC32.EXE
Technical description:
When ran, the worm does the following:
Copies itself to Windows System directory as SMVC32.EXE.
Creates the following registry keys:
- HKLMSoftwareMicrosoftCurrentVersionRunSMVC = %SYSDIR%SMVC32.EXE, so it will be executed every time Windows starts up;
- HKCUSoftwaresocks ;
- HKCUSoftwareserv;
HKCUSoftwarechan;
Connects to an predefined IRC server and listens for commands (such as "execute", shutdown" etc.).
Harvests e-mai addresses from the infected computer, stores them in "c:cyclop.bin" file and periodically sends them to the attacker through e-mail.
MiMai
tags
the following sysdirsmvc32 exe following registry system directory windows system smvc32 exe

Download MiMail worm free removal tool
Download MiMail worm free removal tool
Similar software
MiMail worm free removal tool
SoftWin
A NEW variant of the MiMail worm family, version C, is proliferating across the world, according to security firm iDefense.
CleanZafi 1.2
AxBx Corporation
Clean Zafi is a free tool to detect and remove all variant of the Zafi virus (b, c and d) that have been spreading since 12/14/2004.
McAfee AVERT Stinger 2.6.0
Networks Associates
Stinger is a stand-alone utility used to detect and remove specific viruses.
W32.Sasser Removal Tool 1.04
Symantec
variants of the W32.
W32.Welchia.Worm Removal Tool 1.06
Symantec
W32.
FireLite Virus Scanner 2.7
Prognet Technologies
FireLite is a scan only version of Fire Anti-virus and it contains only limited features.
avast! Virus Cleaner 1.0.211
ALWIL Software
avast! Virus Cleaner is a free tool that will help you remove selected virus & worm infections from your computer.
Law Firm Management ToolKit 1.0
Testiment Browsers
Law Firm Management Toolkit software represents a compilation of essential tools for solo and small firm attorneys.
VCleaner 0.998
Grisoft
Vcleaner removal utility will detect and remove following viruses:
ยท BackDoor.
Microsoft Blaster Worm Removal Tool for Win2k/XP
Microsoft
Microsoft released a removal tool for the MSBlast worm.