Skip to main content
Skip to main content
Published Jan 25, 2007 | Updated Sep 15, 2017

Worm:Win32/Mywife.E.dam

Detected by Microsoft Defender Antivirus

Aliases: W32/MyWife.d@MM (McAfee) Win32.Blackmal.F (CA)

Summary

Win32/Mywife.E@mm is a mass-mailing network worm that targets certain versions of Microsoft Windows. The worm spreads through e-mail attachments and writeable network shares. It is expected to corrupt the content of specific files on the third day of every month.
 
This threat has been assigned CME identifier CME-24. It will be detected as Win32/Mywife.E@mm!CME-24.
To manually recover from infection by Win32/Mywife.E@mm, perform the following steps:
 
First, reboot your computer.  This will force the worm into a known configuration where it can be stopped.
 
Using task manager, look for any of the following process names and kill them if present:
  Update.exe
  Winzip.exe
  scanregw.exe
  WINZIP_TMP.exe
  "Winzip Quick Pick.exe"
 
Delete the following files if present on your system:
  C:\WINZIP_TMP.exe
  %windir%\WINZIP_TMP.exe
  %windir%\system32\Winzip.exe
  %windir%\system32\Update.exe
  %windir%\system32\scanregw.exe
  "C:\Documents and Settings\All Users\Start Menu\Programs\Winzip Quick Pick.exe"
 
Note that the files under %windir%\system32 will be marked read-only and hidden.  To delete these from the command prompt, use (for example):
  del /f /a:h %windir%\system32\Winzip.exe
 
 
Using regedit, delete the following registry value:
  'ScanRegistry' under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run (Contents will look like: scanregw.exe /scan)
 
Reboot your computer, and using Task Manager, verify that none of the processes mentioned above are running.
 
Take steps to prevent re-infection
Do not reconnect your computer to the Internet until the computer is protected from re-infection. See the Preventing Infection section for more information.
 
Follow us