How to Remove MiMail.A worm
virus
What is
the MiMail.A Worm?
From: admin@<current domain> (The from
address may be spoofed to appear that it is coming from the current
domain) How Does MiMail.A Worm Infect My System? Once unzipped, the worm creates an exe file named foo.exe in the Temporary Internet Files directory and runs it. The following files are then created in the Windows directory
It also adds the following registry key to the system. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ Run "VideoDriver" = C:\Windows\videodrv.exe as well as HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111111111} What Does the MiMail.A Worm Do? Once a computer is infected, the virus checks to see if the system is connected to the Internet by trying to contact google.com. If it can contact google, then the worm attempts to gather email addresses from the infected computer. It grabs addresses from all files on the system, EXCEPT files that have the following extensions:
These addresses are then stored in a file named eml.tmp in the Windows directory. The worm has its own SMTP engine. For each email address the worms sends, it will
How Can I Remove the MiMail.A worm? Follow these steps in removing the MiMail worm. 1) Terminate the running program
VIDEODRV.EXE
2) Remove the Registry entries
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>Current Version>Run
Repeat this procedure for HKEY_LOCAL_MACHINE>Software>Microsoft>Code Store Database>Distribution Units
3) Delete the infected files (for Windows ME and XP remember to turn off System Restore before searching for and deleting these files to remove infected backed up files as well)
4) Reboot the computer and run a thorough virus scan using your favorite antivirus program. 5) Apply the patches, MHTML exploit and codebase exploit, to avoid viruses like this in the future. For Automatic Removal of MiMail.A, download the Symantec removal tool Other Variations of the MiMail virus MiMail.C Removal
Instructions
|
Tools for Removing Spyware, Adware, and Malware PC HELL Welchia (Dllhost.exe and SVCHost.exe) Worm Removal Uninstall Antivir Instructions How to Manually Run the Microsoft Malicious Software Removal Tool Bloodhound.Exploit.6 Virus Removal Backdoor SDBot.H Trojan Removal
iPadastic - News, Tutorials, Help, Tips, and Hints for the iPad Download Hoyle Games |
Recommended Software for PC Hell Visitors | |||||
Malwarebytes Anti-Malware |
iolo System Mechanic® |
Emsisoft Anti Malware |
|||
Search PCHELL.COM |
|