W32.Mimail.M@mm

Risk Level 2: Low

Download Removal Tool | Printer Friendly Page

Discovered: December 3, 2003
Updated: February 13, 2007 12:14:38 PM
Also Known As: W32.Mimail.Gen, W32/Mimail.m@MM [McAfee], I-Worm.Mimail.m [Kaspersky], WORM_MIMAIL.M [Trend], W32/Mimail-M [Sophos], Win32.Mimail.M [Computer Assoc
Type: Worm
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP



W32.Mimail.M@mm is a variant of W32.Mimail.L@mm.

The email has the following characteristics:

Subject: Re[3]
Attachment:

Wendy.zip (Contains the file Wendy.exe)

or

Only_for_greg.zip (Contains the file For_greg.jpg.exe)


Notes:
    • The Wendy.zip file is found only in copies of the worm that were part of the initial distribution of the worm by its creator. Once these initial copies are opened, if the Wendy.exe file is run, all the subsequent copies will have the file, Only_for_greg.zip, attached.
    • Virus definitions dated prior to December 3, 2003 may detect this as W32.Mimail.Gen.



Protection

  • Initial Rapid Release version December 3, 2003
  • Latest Rapid Release version July 19, 2008 revision 019
  • Initial Daily Certified version December 3, 2003
  • Latest Daily Certified version January 20, 2009 revision 048
  • Initial Weekly Certified release date December 3, 2003

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Moderate

Damage

  • Damage Level: Medium

Distribution

  • Distribution Level: High

Writeup By: Kevin Ha
Search by name
Example: W32.Beagle.AG@mm
Learn more about Zero-Day / Operation Aurora / Hydraq
Symantec DeepSight Screensaver