This virus comes to you in an email that looks like:
Outgoing messages are sent using the worm’s own SMTP engine. They are formatted as follows:
Subject : don’t be late! (plus additional spaces then random characters)
Attachment : readnow.zip (10,912 bytes) which contains readnow.doc.scr (10,784 bytes)
Message Body :
Will meet tonight as we agreed, because on Wednesday I don’t think I’ll make it,
so don’t be late. And yes, by the way here is the file you asked for.
It’s all written there. See you.
(random characters - the same as those terminating the subject)
The ‘From’ address of outgoing messages may be spoofed as follows:
john@(target domain.com)
Such as
john@abc.com
john@xyz.com
etc
You can remove this virus with the latest McAfee dat file 4301 see McAfee site for additional instructions. Network Associates site on how to remove the W32.MiMail worm
Latest McAfee Definition file 4301 Save to your desktop and double click to install. Check here for latest update.
Or read below and download the removal tool to remove the virus.
(more…)