a-squared Anti-Malware and Mamutu behavior blocker - Malware scanner, remover and protection against new infections of Viruses, Spyware, Trojan Horses, Bots, Backdoors.
a-squared Malware-Info
Name: Worm.Win32.MyDoom
Description:
Aliases: Novarg.A, Mydoom.A, WORM_MIMAIL.R
Symptoms:
The following files in the %sysdir% folder:
taskmon.exe
shimgapi.dll
The following registry key:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\TaskMon with value %sysdir%\taskmon.exe
Technical description:
This is an internet worm that spreads trough e-mail and has backdoor capabilities.
It arrives in the following format:
From
%rand%@%domains%
where %domains% can be one of the following
aol.com
msn.com
yahoo.com
hotmail.com
or a random string.
Subject:
Randomly chosen from the following list:
test
hi
hello
Mail Delivery System
Mail Transaction Failed
Server Report
Status
Error
Body:
Can be:
- Random characters
or one of the following strings:
test
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
The message contains Unicode characters and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.
Attachment:
Randomly chosen from the following strings:
document
readme
doc
text
file
data
test
message
body
with one of the following extensions:
exe, pif, scr, bat, com
htm.%one of the above%
txt.%one of the above%
doc.%one of the above%
When the user opens the attachment the worm creates an mutex with name
SwebSipcSmtxS0
It opens the notepad with a random binary content.
If the date is 12 February or after, the worm stops the spreading rutine.
It drops a dll in %sysdir%\shimgapi.dll. This dll is a backdoor component.
It copies itself to %sysdir%\taskmon.exe and it adds the following registry key
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\TaskMon with value %sysdir%\taskmon.exe
It the date is 1 February or after it make DoS attack at www.sco.com
It will copies itself to kazaa shared folder under the following names:
nuke2004
office_crack
rootkitXP
strip-girl-2.0bdcom_patches
activation_crack
icq2004-final
winamp5
with extensions randomly chosen from the following list:
exe, scr, pif, bat
It scans for e-mails in the files with the following extension:
htm
sht
php
asp
dbx
tbb
adb
wab
txt
The search is initially done in Temporary Internet Files for ensuring a fast
initial spreading, and after that on all fixed drives it finds.
It skips all e-mails that contains the following strings:
.edu,
abuse,
fcnz,
spm,
www,
secur
avp
syma
icrosof
msn.
hotmail
panda
sopho
borlan
inpris
example
mydomai
nodomai
ruslis
.gov
gov.
.mil
foo.
berkeley
unix
math
bsd
mit.e
gnu
fsf.
ibm.com
google
kernel
linux
fido
usenet
iana
ietf
rfc-ed
sendmail
arin.
ripe.
isi.e
isc.o
secur
acketst
pgp
tanford.e
utgers.ed
mozilla
root
info
samples
postmaster
webmaster
noone
nobody
nothing
anyone
someone
your
you
me
bugs
rating
site
contact
soft
no
somebody
privacy
service
help
not
submit
feste
ca
gold-certs
the.bat
page
admin
icrosoft
support
ntivi
unix
bsd
linux
listserv
certific
google
accoun
It waits for connections on TCP port 3127.
Source: BitDefender Virus-Info
Removal instructions for Worm MyDoom:
To delete this malware infection, please download and install a-squared Anti-Malware. Run a full scan on all drives and move all detected items to the quarantine.
More details about this danger:
Additional information might be found here:
Search
at Google for
Worm MyDoom
Search at Bing for
Worm MyDoom
Search
at Yahoo for
Worm MyDoom
How can I protect myself from Worm MyDoom?
Important!
You essentially need an antivirus product, that is not only able to clean infections, but also protect your PC permanently from new dangers.
This is the only way to prevent data loss and unnecessary hassle and costs of new installations of your operating system.
Take your chance and buy the multiple awarded protection software a-squared Anti-Malware today!
Only $40 for the security of your computer.
Buy a-squared Anti-Malware online:
Trust only on the best protection software!











