Main > Security & Privacy > Anti-Virus Tools >

Win32.Mydoom.V@mm Free Removal tool 1.0

Win32.Mydoom.V@mm Free Removal tool 1.0

Sponsored Links

Win32.Mydoom.V@mm Free Removal tool 1.0 Ranking & Summary

RankingClick at the star to rank
Ranking Level
User Review: 0 (0 times)
File size: 58 KB
Platform: Windows 9X/ME/NT/2K/2003/XP/Vista
License: Freeware
Price:
Downloads: 1887
Date added: 2004-09-16
Publisher: SoftWin

Win32.Mydoom.V@mm Free Removal tool 1.0 description

Symptoms: Presence of files Documents and SettingsAdministratorStart MenuProgramsStartuprx32hh00.exe and %SYSTEM%winspf32.exe.
Presence of a file tmp*.tmp with a size of 234496 bytes.

Presence of registry key: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunWinSPF = %SYSTEM%winspf32.exe.

HKCUSOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsVersion = FrankenShteiN
HKLMSOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsVersion = FrankenShteiN

HKCUSOFTWAREMicrosoftWindowsCurrentVersionInternet Settings5.0User Agent
HKLMSOFTWAREMicrosoftWindowsCurrentVersionInternet Settings5.0User Agent

This is a mass-mailer that also drops a backdoor. The file is downloaded from one the following urls:

"http://www.llc.unibo.it"
"http://www.surrenderzeeland.nl"
"http://www.mercyships.de"
"http://www.hiw.kuleuven.ac.be"
"http://www.ach.ch"
"http://vugs.geog.uu.nl"
"http://www.planetboredom.net"

and is downloaded to a temporary file ( with a temporary name ). This files size is 234496 bytes.

It seems that there are more versions of this worm, which are just recompilations of the same source.

The worm creates a mutex called qwedefacedRDE. It uses threads for searching for e-mail addreses in the following file types: wab,xls,vbs,uin,txt,tbb,stm,sht,php,msg,mht,jsp,htm,eml,dht,dbx,cgi,cfg,asp.

It sends mail using its own SMTP engine.

Win32.Mydoom.V@mm Free Removal tool 1.0 Screenshot

Advertisements

Win32.Mydoom.V@mm Free Removal tool 1.0 Keywords

Bookmark Win32.Mydoom.V@mm Free Removal tool 1.0

Hyperlink code:
Link for forum:

Win32.Mydoom.V@mm Free Removal tool 1.0 Copyright

WareSeeker periodically updates pricing and software information of Win32.Mydoom.V@mm Free Removal tool 1.0 full version from the publisher, so some information may be slightly out-of-date. You should confirm all information before relying on it. Software piracy is theft, Using crack, password, serial numbers, registration codes, key generators is illegal and prevent future development of Win32.Mydoom.V@mm Free Removal tool 1.0 Edition. Download links are directly from our publisher sites, torrent files or links from rapidshare.com, yousendit.com or megaupload.com are not allowed

Allok Video Splitter 2.2.0 Review:

Name (Required)
Email(Required)
Captcha
Featured Software

Want to place your software product here?
Please contact us for consideration.

Contact WareSeeker.com
Related Software
Free removal for Win32.MyDoom.M@mm Free Download
Free removal tool for Win32.MyDoom.S@mm Free Download
Clean W32.Novarg.A@mm, W32.Mydoom@mm variants and Backdoor.Zincite.A and W32.Zindos.A infections Free Download
Free removal for Win32.Mabutu.A@mm Free Download
W32.Mytob.AR@mm Free Removal Tool was designed to remove the infections of W32.Mytob.AR@mm Free Download
Clean W32.Novarg.A@mm, W32.Mydoom@mm variants and Backdoor.Zincite.A and W32.Zindos.A infections Free Download
Win32.Bagle.AJ@mm Free Removal tool Free Download
Free removal tool for Win32.Bagle.AL@mm Free Download