Win32.Evaman.A@mm Removal Tool 1.0
Symptoms:
Presence of registry key:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerWintasks,
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerWintasks,
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunwintasks.
|
Symptoms:
Presence of registry key:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerWintasks,
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerWintasks,
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunwintasks.exe and the value
%SYSTEM%/wintasks.exe.
Presence of the wintasks.exe file in the %SYSTEM% directory.
Presence of a named mutex "MyNameIsEva".
Technical description: The worm comes by mail, with the following characteristics:
The message subject is one of:
returned mail
failure delivery
failed transaction
server error
mail failure
Delivery Status (Failure)
Once executed, the worm copies itself to Windows System directory as wintasks.exe, and it then opens notepad.
The worm creates the following registry key so as to run each time Window starts: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunwintasks.exe with the value the path in the
Windows System directory where it has just copied itself.
tags the worm wintasks exe hkey local mail failure failure delivery windows system system directory the following with the exe and the value registry key local machinesoftwaremicrosoftwindowscurrentversionrunwintasks
Download Win32.Evaman.A@mm Removal Tool 1.0
Download Win32.Evaman.A@mm Removal Tool 1.0
Similar software
Win32.Evaman.A@mm Removal Tool 1.0
BitDefender
Symptoms:
Presence of registry key:
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionExplorerWintasks,
HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionExplorerWintasks,
HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunwintasks.
MiMail worm free removal tool
SoftWin
A NEW variant of the MiMail worm family, version C, is proliferating across the world, according to security firm iDefense.
Win32.Bagle.AL@mm free removal tool 1.0
Bitdefender
Symptoms:
- Presence of file %SYSTEM%WINdirect.
Win32.MyDoom.M@mm Free Removal tool 1.0
SOFTWIN
Symptoms:
- Presence of the following registry key:
- HKLMSoftwareMicrosoftWindowsCurrentVersionRunJavaVM
with the following value:
- %WINDIR%java.
Win32.MyDoom.S@mm Free Removal tool 1.0
Bitdefender
Symptoms:
Presence of "winpsd.
WinTasks Professional 5.04
Uniblue Systems Ltd
In the recesses of your computer, 20-30 invisible processes run silently in the background.
W32.Mydoom.A Cleaning Utility 1.0.1
Computer Associates
Win32.
Win32.Mydoom.V@mm Free Removal tool 1.0
Softwin
Symptoms: Presence of files Documents and SettingsAdministratorStart MenuProgramsStartuprx32hh00.
XP Registry Cleaner 3.92
XP-Tools
The Windows registry is a database repository for information about a computer's configuration.
Directory Watch 4.0
Steve Lohja & Associates
Directory Watch is a Server Side application to monitor queues.