winmgr32.exe - Dangerous

winmgr32.exe

Jeff's Story:

My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.

I sought a solution on the Internet and discovered your product and tried out the trial.

You quickly found the rootkit and SAVED my PC!

I haven't had any problems since, and I'm extremely grateful.

Manual removal instructions:

winmgr32.exe
I-Worm.Mimail.p
This worm spreads via the Internet as the files attached to infected messages.
Contents of infected messages:
Sender: donotreply@paypal.com
Message header: "GREAT NEW YEAR OFFER FROM PAYPAL.COM!"
Attachment name: pp-app.zip

To send infected messages the worm uses its own SMTP library.
To find email addresses to send messages to, the worm looks for address lines which contain the predefined suffixes:
but does not search for addresses in files with the following extensions: jpg, gif, exe, dll, avi, mpg, mp3, vxd, ocx, psd, tif, zip, rar, pdf, cab, wav, com.
When executed, the worm displays a dialogue box on screen which asks for PayPal credit card details.
Data entered is stored in 'c:\tmpny3.txt' and is then sent on to the author of the worm.
The worm opens port 5555 to listen for commands.
The worm changes the home page in Internet Explorer to a link containing pictures of George Bush:
http://www.anvari.org/db/fun/World_Trade...

Use RegRun Startup Optimizer to remove it from startup.

Remove winmgr32.exe now!