Win7 Download
bookmark Windows 7 Download add as favorite Windows 7 Download Windows 7 Download RSS register at Windows 7 Download

Dumaru Removal Tool for Windows 7 - A cleaning utility for the Dumaru malware - Windows 7 Download

Dumaru Removal Tool Windows 7

Dumaru Removal Tool

A cleaning utility for the Dumaru malware and for all its varaints

Dumaru Removal Tool is a lightweight application that can completely erase the Win32.Dumaru worm in all its variants.

Dumaru Removal Tool full details

File Size: 61 kB
License: Freeware
Price: FREE
Released: 2010-07-30
Downloads: Total: 121 | This Month: 0
Publisher: Bitdefender
Publisher URL: http://www.bitdefender.com


Download Dumaru Removal Tool

Save Dumaru Removal Tool to My Stuff

View full Dumaru Removal Tool screenshot
Dumaru Removal Tool

User Rating: 0 (0 votes)

Dumaru Removal Tool - Windows 7 Download awards

Dumaru Removal Tool windows 7 compatible windows 7 download editor's pick

Dumaru Removal Tool full description

Dumaru Removal Tool is a lightweight application that can completely erase the Win32.Dumaru worm in all its variants.

Win32.Dumaru.A@mm arrives as a fake email from Microsoft:

From: "Microsoft" email

Subject: Use this patch immediately !

Body:

Dear friend , use this Internet Explorer patch now!
There are dangerous virus in the Internet now!
More than 500.000 already infected!

Attachment: patch.exe

When executed, the virus will do the following:

Copy itself as:
%SYSTEM%load32.exe
%WINDOWS%dllreg.exe
%SYSTEM%vxdmgr32.exe

Drops and executes a backdoor component

%WINDOWS%windrv.exe (8192 bytes)

which connects to a IRC server and joins a password protected channel, sends a login notice and waits for the author to issue commands.

Creates the value

"load32"="%SYSTEM%load32.exe"

in the registry key

[HKLMSoftwareMicrosoftWindowsCurrentVersionRun]


On Windows 9x/Me systems, it does the following:

uses RegisterServiceProcess to hide its presence;

modifies system.ini by adding the entry in the [Boot] section:

shell=explorer.exe %System%vxdmgr32.exe

modifies win.ini by adding the following entry in the [Windows] section:

run=C:WINDOWSdllreg.exe

Harvests e-mail addresses from files matching

*.htm
*.wab
*.html
*.dbx
*.tbb
*.abd

and stores them in %WINDOWS%winload.log file.

It uses it's own SMTP engine and sends itself to the e-mails harvested in winload.log file (see above for the infected e-mail format).

It searches for *.exe files belonging to several antivirus/security products and attempts to overwrite them with copies of the virus.

Win32.Dumaru.B/C@mm is a mass mailer that has backdoor abilities (listens on TCP ports 1001, 2283, 10000) and also comes with a keylogger.
Attempts to terminate processes belonging to several security and antivirus programs.
On NTFS partitions, it may overwrite .exe files with copies of the virus.

It spreads using this format:

From:
email

Subject:
Use this patch immediately !

Body:
Dear friend , use this Internet Explorer patch now!
There are dangerous virus in the Internet now!
More than 500.000 already infected!

Attachment:
patch.exe

Once run, the virus does the following:

1. Creates the aforementioned files and registry keys/entries.

2. Attempts to terminate processes:

ZAUINST.EXE
ZAPRO.EXE
ZONEALARM.EXE
ZATUTOR.EXE
MINILOG.EXE
VSMON.EXE
LOCKDOWN.EXE
ANTS.EXE
FAST.EXE
GUARD.EXE
TC.EXE
SPYXX.EXE
PVIEW95.EXE
REGEDIT.EXE
DRWATSON.EXE
SYSEDIT.EXE
NSCHED32.EXE
MOOLIVE.EXE
TCA.EXE
TCM.EXE
TDS-3.EXE
SS3EDIT.EXE
UPDATE.EXE
ATCON.EXE
ATUPDATER.EXE
ATWATCH.EXE W
GFE95.EXE
POPROXY.EXE
NPROTECT.EXE
VSSTAT.EXE
VSHWIN32.EXE
NDD32.EXE
MCAGENT.EXE
MCUPDATE.EXE
WATCHDOG.EXE
TAUMON.EXE
IAMAPP.EXE
IAMSERV.EXE
LOCKDOWN2000.EXE
SPHINX.EXE
WEBSCANX.EXE
VSECOMR.EXE
PCCIOMON.EXE
ICLOAD95.EXE
ICMON.EXE
ICSUPP95.EXE
ICLOADNT.EXE
ICSUPPNT.EXE
FRW.EXE
BLACKICE.EXE
BLACKD.EXE
WRCTRL.EXE
WRADMIN.EXE
WRCTRL.EXE
PCFWALLICON.EXE
APLICA32.EXE
CFIADMIN.EXE
CFIAUDIT.EXE
CFINET32.EXE
CFINET.EXE
TDS2-98.EXE
TDS2-NT.EXE
SAFEWEB.EXE
NVARCH16.EXE
MSSMMC32.EXE
PERSFW.EXE
VSMAIN.EXE
LUALL.EXE
LUCOMSERVER.EXE
AVSYNMGR.EXE
DEFWATCH.EXE
RTVSCN95.EXE
VPC42.EXE
VPTRAY.EXE
PAVPROXY.EXE
APVXDWIN.EXE
AGENTSVR.EXE
NETSTAT.EXE
MGUI.EXE
MSCONFIG.EXE
NMAIN.EXE
NISUM.EXE
NISSERV.EXE

3. On Windows 9x/Me systems, alters win.ini and system.ini in order to run at startup.

[windows]
run=%WINDOWS%dllreg.exe

[boot]
shell=explorer.exe %SYSTEM%vxdmgr32.exe

4. Harvests e-mail addresses by searching inside:

.htm
.wab
.html
.dbx
.tbb
.abd

and attempts to send itself using the e-mail format described above, using it's own SMTP engine and the default SMTP address.

5. Attempts to infect .exe files on NTFS partitions, but due to a bug in the search, it will only infect .exe file on the root of drives.

6. Connects to an IRC server, and joins a channel, listens on ports 1001, 10000 (TCP) for commands from an attacker. Also, port 2283 (TCP) is used as a send through (like a proxy).

Dumaru Removal Tool download tags

Windows 7 free download

Bookmark Dumaru Removal Tool

copy windows 7 bookmark
copy windows 7 bookmark
copy windows 7 bookmark

Dumaru Removal Tool for Windows 7 - Copyright information

All Dumaru Removal Tool reviews, submitted ratings and written comments become the sole property of Windows 7 download. You acknowledge that you, not windows7download, are responsible for the contents of your submission. However, windows7download reserves the right to remove or refuse to post any submission for any reason.

Windows 7 Download periodically updates pricing and software information of Dumaru Removal Tool full version from the publisher, but some information may be out-of-date. You should confirm all information.
Using warez version, crack, warez passwords, patches, serial numbers, registration codes, key generator, pirate key, keymaker or keygen for Dumaru Removal Tool license key is illegal and prevent future development of Dumaru Removal Tool. Download links are directly from our mirrors or publisher's website, Dumaru Removal Tool torrent or shared files from free file sharing and free upload services, including Rapidshare, MegaUpload, YouSendIt, SendSpace, DepositFiles, DivShare, HellShare, HotFile, FileServe or MediaFire, are not used.

Post Dumaru Removal Tool review

Your Name:
Product Version:
Rating:
Review:
Security Code:

Windows 7 Dumaru Removal Tool related downloads

Brief Description This tool checks your computer for infection by specific, prevalent ... Microsoft will release an updated version of this tool on the second Tuesday of each month. ...
Valhalla Removal Tool is a lightweight application that was created in ...
Jeefo Removal Tool is a lightweight utility that can help you ...
Brief Description This tool checks your computer for infection by specific, prevalent ... Microsoft will release an updated version of this tool on the second Tuesday of each month. ...
... by the Gromozon Rootkit please download our standalone removal tool by clicking the link below. It ...
My Account
My Saved Stuff
CyberLink YouCam 5.0
Download   Remove

CS 80V 2.0
Download   Remove

HelpCruiser 2.2
Download   Remove

HDR PhotoStudio 2.15.28
Download   Remove

GdsViewer 2.1.9.390
Download   Remove

gDoc Fusion 2.5
Download   Remove

GameDay Payoff 1.0.0.121
Download   Remove

Cross Fire 1080
Download   Remove

Cool Barcode Maker 4.0
Download   Remove

ContaCam 3.9.9
Download   Remove

Free Large Android Icons 2011.2
Download   Remove

FlashCapture 3.0.3.1317
Download   Remove

Daytrader Companion 1.4.0
Download   Remove

Dator 2.7.0
Download   Remove

Azureus 4.0.0.4
Download   Remove

AVS Video Converter 8.1.2.510
Download   Remove

AutoScreenRecorder Pro 3.1.375
Download   Remove

AnyToJpeg 3.3
Download   Remove

Any DVD Cloner Express 1.2.2
Download   Remove

Free YouTube to MP3 Converter 3.10.11
Download   Remove

Fix IE Utility 1.0
Download   Remove

DDE server plugin 3.7.4.1130
Download   Remove

Codice Fiscale 5.1.1
Download   Remove

Encode360 2.03
Download   Remove

ChemDoodle 2.0.3
Download   Remove

BrushO! 1.05
Download   Remove

EVVAddressBook 3.0
Download   Remove

Evolution 2.28.1-1
Download   Remove

ECrawl 2.63
Download   Remove

Audio Sound Editor for .NET 2.2.1.0
Download   Remove

123FTP-Free 3.9.1
Download   Remove

Amphis Customer 3.0
Download   Remove

AIMP Classic 3.10 B1040 Beta
Download   Remove

ABC Roster 1.5.0
Download   Remove

A-one iPod PSP 3GP Video Converter 7.6.3
Download   Remove

Acoolsoft PPT to Video Free 3.2.3
Download   Remove


Would you like to receive announcements of new versions of your software by email or by RSS reader? Register for FREE!
Windows 7 Downloads Picks
Popular Tags
Popular Windows 7 Software
© 2012 Windows7Download.com - All logos, trademarks, art and other creative works are and remain copyright and property of their respective owners. Microsoft Windows is a registered trademarks of Microsoft Corporation. Microsoft Corporation in no way endorses or is affiliated with windows7download.com.