
KAVFIND.EXE
PROCESS INFORMATION
Process
Name :
Kavfind.exe
Process
Path : %SYSTEM%\kavfind.exe
[ C:\Windows\System32\kavind.exe ]
Process
type : Internet
Worm
Malware
Name :
W32.Mumu.B.Worm
Alias : Mumu.B,
WORM_MUMU.A, W32.Mumu-C
Threat
level : Low
Process
Details :
Kavfind.exe is dropped by
Mumu.B. It is a modified variant of Mumu worm,
spreads using network shares. It is a
network worm and it will not spread using e-mail
attachments. The worm infects systems with weak
password or no password.
When executed, Mumu.B
drops the file bboy.exe in Windows folder
and bboy.dll, kavfind.exe, mumu.exe in
Windows system folder. It also drops few
legitimate files in the infected system. Mumu.B
modifies the registry RUN section to load
automatically. The registry modification is given
below.
[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
Kernel ="%Windows%\bboy.exe"
Mumu worm uses weak
password list and brute force methods to infect
the target systems. It can infect all Windows
systems but replicates in Windows NT, 2000 and XP
systems only.
How can I protect my
system?
Solo has incorporated
kavfind.exe in its signature file to protect
users from this worm attack. Solo antivirus
registered users are already protected from this
worm. Make sure that you have installed
registered version of Solo Antivirus to protect
your system from all virus threats.
How
to remove this worm?
If you are already
infected with kavfind.exe process, run Solo anti-virus
and choose Delete option to remove the worm
components.
Solo
antivirus can detect and remove W32.Mumu.B worm
safely. Use the following link to Download
30 day trial version of Solo antivirus
to remove viruses from your computer.

Solo anti-virus not only
scans for all viruses, it contains a unique System
Integrity Checker to protect you from
New Internet Worms, Backdoors and
malicious VB, Java Scripts. It also
effectively removes all existing Internet Worms,
File viruses, malicious VB, Java scripts, Trojans,
Backdoors, boot sector, partition table and macro
viruses.
You can
purchase Solo antivirus using the link 

|