|
|
I-Worm.Mimail. Viruses Information
| Name: |
I-Worm.Mimail. |
| Category: |
Viruses |
| Description:
|
Details
I-Worm.Mimail.j
This worm is a modification of I-Worm.Mimail.i
It spreads via the Internet as a file named InfoUpdate.exe attached to infected messages. The worm itself is a Windows PE EXE file, packed with UPX. The size of the compressed file is approximately 13KB and the size of the decompressed file is approximately 30KB.
Characteristics of infected messages:
Sender's address:
Do_Not_Reply@paypal.com
Message header
IMPORTANT
Message body
Dear PayPal member, We regret to inform you that your account is about to be expired in next five business days. To avoid suspension of your account you have to reactivate it by providing us with your personal information.
To update your personal profile and continue using PayPal services you have to run the attached application to this email. Just run it and follow the instructions. IMPORTANT! If you ignore this alert, your account will be suspended in next five business days and you will not be able to use PayPal anymore.
Thank you for using PayPal.
Attachment name:
www.paypal.com.pif or InfoUpdate.exe
All other details, such as how the worm installs itself, manifests itself in the system and replicates are the same as I-Worm.Mimail.i |
Top Viruses Visited Pages:
Invader. - 239 visits
not-a-virus:RiskWare.Tool.RegPatch. - 73 visits
Worm.P2P.Harex. - 66 visits
not-a-virus:RemoteAdmin.Win32.RAdmin.2 - 60 visits
Small.58. - 56 visits
Coito.64 - 54 visits
I-Worm.Mapson. - 48 visits
Win32.Hidra - 43 visits
Win16.Klon.1177 - 42 visits
Marine.500 - 35 visits
Random Viruses Pages:
Tout.27
Polimer.51
Email-Worm.Win32.Bagz.
Hi Famil
CD_Joke.84
Fewster.178
Macro.Word97.Mutalis
Penetrator.98
Macro.Word97.PaixViru
Horse.1154.
|
|