I-Worm.Mimail
Mimail is an internet worm spreading via infected emails. The worm uses a built in SMTP engine.
Infected messages has the following fields:
From: admin@%fake email address% where %fake email address% is different every time.
Subject: your account %rnd str% where %rnd str% is different every time.
Body:
Hello there, I would like to inform you about important information regarding your email address. This email address will be expiring.
Please read attachment for details.
---
Best regards, Administrator
---
Attach: message.zip with "message.html" file.
This HTML file drops the FOO.EXE file (worm copy) into the "Downloaded Program Files" directory and runs it.
(To do this action the worm exploits a vulnerability in Internet Explorer: allows a Java script in the HTML file to get access to disk files without any prompts.)
Worm copies itself to the Windows directory under the name "videodrv.exe" and registers this file in the system registry autorun key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
VideoDriver = %WinDir%\videodrv.exe
The worm also creates the following files in the Windows directory:
exe.tmp - worm in HTML file
zip.tmp - worm's HTML file in ZIP archive (method "stored" - no compression).
eml.tmp - list of emails found on infected machine
(The worm uses its own ZIP file format supporting routine.)
Use RegRun Startup Optimizer to remove it from startup.
Removal: videodrv.exe is removed by RegRun.
Download RegRun Suite. Click here.
Unzip downloaded file to any folder on your hard drive.
Open an executable file to start program installation.
Follow the installer instructions.
At the end of installing software on your computer you will be prompted
to run "Scan for Viruses".
Wait for a couple seconds to finish scanning.
Click on the "Fix Problems" button.
Is it serious?
|
The
programs is known as malware.
|
Item name:
|
videodrv.exe
|
Click on the "Get it out!" button.

We suggest you to reboot your computer to be sure that your computer is
clean now.
Do not hesitate to contact us:
Support center
Recommended software:
UnHackMe - easy removal Rootkits/Adware/Spyware.
http://www.unhackme.com
RegRun Security Suite - removal and protection.
http://www.regrun.com
RegRun Reanimator - free removal tool.
greatis.com/reanimator
RegRun - User's Choice
Vista Programs - full info...
What is hidden in MSDN?
.NET Secrets Revealed
Why software developers prefer Win32.FreeTechSecrets.com?
All Unix Manuals in Alphabetical Order
C# controls for .NET in 3 simple steps.
Constantly updated. Last update:
June 30 2008
Interesting information about Vista programs...
Need consultation?
Would you like to add your opinion?