| Pacmaniac Winner!
Warning has been issued by AVG and Symantec about this virus.
W32.Dumaru.AH@mm is a multi-threaded, mass-mailing worm that opens a backdoor, runs a keylogger, and attempts to steal personal information. It is similar to the W32.Dumaru.Y@mm worm.
This worm uses its own SMTP engine to spread to the email addresses it finds in the files on the infected system. The email has the following characteristics: From: random characters@<domains of the email addresses that the worm finds from the infected machine> Subject: Unknown Message: If you cant see message text from: <some random characters> , read attached file. Attachment: document.zip
The attachment is a zip file that contains the worm executable as myphoto.jpg<56 spaces>.exe.
The worm may arrive as a dropper.
Also Known As:
W32/Mimail.u@MM [McAfee], Win32.Mimail.U[Computer Associates]
Type: Worm
Infection Length:
40,960, 28020
Systems Affected:
Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected:
DOS, Linux, Macintosh, OS/2, UNIX
Is your anti-virus uptodate.
Eshie |