Symptoms:
Presence of "winpsd.exe" in %system% (e.g. C:WindowsSystem32) folder, in processes list and presence in start-up registry key "HKLMSoftwareMicrosoftWindowsCurrentVersionRun" under the string "winpsd".
Presence of "rasor38a.dll" in %windir% (e.g. C:Windows) folder, which is a copy of the worm.
Spreads via email, attatched with the name "photos_arc.exe"; the subject of the email is "Photos"; the body is "LOL!;))))" while the sender is spoofed.
IMPORTANT! The tool must be run in Safe Mode in order to detect and clean one or more stealth components of MyDoom worm.