Alias:WORM_MIMAIL.A [Trend], W32/Mimail@MM [McAfee], Win32.Mimail.A [CA], W32/Mimail-A [Sophos], I-Worm.Mimail [Kaspersky]
Type:Worm 
Size:~ 16 KBytes 
Origin: 
Date:00-00-0000 
Damage:Sent by email. 
VDF Version:6.23.00.00 
Danger:Low 
Distribution:High 

DistributionThe email sent by the worm contains:
Subject: your account [random string]
Body: Hello there, I would like to inform you about important information regarding your email address. This email address will be expiring. Please read attachment for details. Best regards, Administrator
Attachment: Message.zip

Technical DetailsIt copies itself as: %WinDIR%\Videodrv.exe.
It makes the autostart registry entry:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "VideoDriver"="%WinDIR%\videodrv.exe"

It collects email addresses from files, excluding the following types: .bmp .jpg .gif .exe .dll .avi .mpg .mp3 .vxd .ocx .psd .tif .zip .rar .pdf .cab .wav .com
All these addresses are saved in the file %WinDIR%\eml.tmp

The attachment Message.zip contains the file Message.htm, that uses a code base for installing a worm copy named Foo.exe in the temporary Internet directory.
When the .html file is opened, the following registry entry is made:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{11111111-1111-1111-1111-111111111111}
The worm creates two files in %Windir%:
Zip.tmp: This is a temporary copy of message.zip (30,079 bytes).
Exe.tmp: This is a temporary copy of message.html (29,957 bytes).
Descrizione inserita da Crony Walker su martedì 15 giugno 2004

Indietro . . . .