mydoom
MyDoom Scanner 1.0
MyDoom Scanner - a free, standalone scanner that detects hosts infected with eihter variant of MyDoom Virus more>>
MyDoom Scanner alows users to enter a range of IP addresses to scan for infected computers.
Mydoom.F Remover 0.92
Clean the Mydoom.F virus from your computer more>> Clean the Mydoom.F virus from your computer
Mydoom.F Remover will enable you to easily get rid of the virus infection. All you need to do is download and run the application on the infected PC.
<<less
Webroot MyDoom Remover 1.1
Webroot MyDoom Remover - detect and remove MyDoom worm more>>
The program scans your system and passes and launches the results in your web browser (requires internet connection).
Mydoom.N Remover 3.5.1.11
This tool will erase the Mydoom.N virus from your PC more>> This tool will erase the Mydoom.N virus from your PC
Mydoom.N installs a file that behaves as a backdoor by opening the TCP port 1034 and listens to it. By doing so, it allows hackers to remotely access the affected computer in order to carry out actions that would compromise users confidentiality or impede normal work.
Mydoom.N spreads via e-mail in a message with variable characteristics. The Mydoom.N Remover will allow you to get rid of the virus infection in nos time.
MyDoom Worm Cleaner 1.0.0.0
Detect and remove the Mydoom from from an infected system more>> Detect and remove the Mydoom from from an infected system
MyDoom Worm Cleaner cleans a computer infected by the Win32.Mydoom worm. Rebooting your system may be necessary after the cleaning process has been completed.
Mydoom.A Remover 3.5.1.11
A useful tool that enbales you to erase the Mydoom.A virus more>> A useful tool that enbales you to erase the Mydoom.A virus
Mydoom.A is a worm that spreads via e-mail in a message with variable characteristics and through the peer-to-peer (P2P) file sharing program KaZaA.
Mydoom.A launches DDoS (Distributed Denial of Service) attacks against the website www.sco.com if the system date is between February 1 and February 12, 2004. It does this by launching GET/ HTTP/ 1.1 requests every 1,024 milliseconds. On February 12, 2004, the worm finishes its payload, ending its execution whenever it is activated.
Mydoom.A drops the DLL (Dynamic Link Library) SHIMGAPI.DLL, which creates a backdoor, opening the first available TCP port in the range from 3127 to 3198. This backdoor component allows to download and run an executable file, and acts as a TCP proxy server, allowing a hacker to gain remote access to network resources.
The Mydoom.A Remover will help you easily clean the virus from your computer.
Mydoom.AO Remover 3.5.1.11
A useful tool for cleaning the Mydoom.AO virus from your computer more>> A useful tool for cleaning the Mydoom.AO virus from your computer
Mydoom.AO is a worm that opens the TCP port 1034 and listens to it, acting as a backdoor.
Mydoom.AO downloads a file called MODULELOG.PNG from the Internet. In fact, this file is not a PNG image, but an executable file belonging to the backdoor Bck/Surila.J.
Mydoom.AO spreads via e-mail, in a message with variable characteristics that passes itself off as a mail delivery error. In order to harvest e-mail addresses to send itself to, this worm looks for files on the affected computer, but it also uses intensive searches on web searchers.
Mydoom.AO uses popular web searchers, such as Google, Altavista, Yahoo and Lycos.
Additionally, Mydoom.AO is able to surpass certain anti-spam techniques commonly used when noting down e-mail addresses.
The Mydoom.AO Remover will allow you to get rid of the pesky virus in no time!
Remover for I-Worm.Mydoom.A-H 2.0
A tool which removes I-Worm.Mydoom.A-H more>> A tool which removes I-Worm.Mydoom.A-H
This virus removal tool was designed to help users disinfect their computers when infected with I-Worm.Mydoom.A-H (I-Worm.Mydoom.A).
<<lessW32.Mydoom@mm Removal Tool 1.11.0
Clean W32.Novarg.A@mm, W32.Mydoom@mm variants and Backdoor.Zincite.A and W32.Zindos.A infections more>> Clean W32.Novarg.A@mm, W32.Mydoom@mm variants and Backdoor.Zincite.A and W32.Zindos.A infections
Symantec Security Response has developed a removal tool to clean the following infections:
W32.Mydoom.A@mm
W32.Mydoom.B@mm
W32.Mydoom.F@mm
W32.Mydoom.G@mm
W32.Mydoom.H@mm
W32.Mydoom.L@mm
W32.Mydoom.M@mm
W32.Mydoom.Q@mm
W32.Mydoom.AM@mm
W32.Mydoom.AX@mm
W32.Mydoom.AZ@mm
W32.Mydoom.BA@mm
W32.Mydoom.BN@mm
W32.Mydoom.BO@mm
W32.Mydoom.BQ@mm
W32.Mydoom.BT@mm
Backdoor.Zincite.A
W32.Zindos.A
Backdoor.Nemog
Backdoor.Nemog.D
The W32.Mydoom@mm Removal Tool does the following:
- Terminates W32.Mydoom@mm, Backdoor.Zincite.A, W32.Zindos.A, and Backdoor.Nemog viral processes.
- Terminates the viral thread running under Explorer.exe.
- Deletes W32.Mydoom@mm, Backdoor.Zincite.A, W32.Zindos.A, and Backdoor.Nemog files.
Reverses the changes made to the registry by all aforementioned threats. Repairs the Hosts file, if the computer infected with Backdoor.Nemog.
Enhancements:
- Version 1.11.0 release to support W32.Mydoom.BT@mm
W32.Mydoom.A Cleaning Utility 1.0.1
W32.Mydoom.A Cleaning Utility - utility to remove the Win32/Shimg.Worm (W32/Mydoom@MM,W32.Novarg.A@mm) more>>
This utility is for cleaning a local machine from the Win32/Shimg.Worm. The tool will search for and terminate any worm processes found in memory.
It will then scan all drives on the local machine and, if the worm is found, will fix any modified registry keys. It will also remove datafiles dropped by the worm.
NOTE: Certain files may be renamed by the cleaning utility. In addition, files may be "locked" by Windows and a reboot may be required to completely clean the system. To prevent data loss, all applications should be closed before running the utility.
W32.Mydoom@mm Free Removal Tool 1.11.0
Clean W32.Novarg.A@mm, W32.Mydoom@mm variants and Backdoor.Zincite.A and W32.Zindos.A infections more>>
W32.Mydoom.A@mm
W32.Mydoom.B@mm
W32.Mydoom.F@mm
W32.Mydoom.G@mm
W32.Mydoom.H@mm
W32.Mydoom.L@mm
W32.Mydoom.M@mm
W32.Mydoom.Q@mm
W32.Mydoom.AM@mm
W32.Mydoom.AX@mm
W32.Mydoom.AZ@mm
W32.Mydoom.BA@mm
W32.Mydoom.BN@mm
W32.Mydoom.BO@mm
W32.Mydoom.BQ@mm
W32.Mydoom.BT@mm
Backdoor.Zincite.A
W32.Zindos.A
Backdoor.Nemog
Backdoor.Nemog.D
The W32.Mydoom@mm Removal Tool does the following:
- Terminates W32.Mydoom@mm, Backdoor.Zincite.A, W32.Zindos.A, and Backdoor.Nemog viral processes.
- Terminates the viral thread running under Explorer.exe.
- Deletes W32.Mydoom@mm, Backdoor.Zincite.A, W32.Zindos.A, and Backdoor.Nemog files.
Reverses the changes made to the registry by all aforementioned threats. Repairs the Hosts file, if the computer infected with Backdoor.Nemog.
Enhancements:
- Version 1.11.0 release to support W32.Mydoom.BT@mm
Resolve for Bdoor-CHR/W32/MyDoom 1.07
A tool that removes Bdoor-CHR/W32/MyDoom trojan more>> A tool that removes Bdoor-CHR/W32/MyDoom trojan
Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.
They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.
W32/MyDoom-A is a worm which spreads by email. When the infected
attachment is launched, the worm harvests email addresses from address
books and from files with the following extensions: WAB, TXT, HTM, SHT, PHP,
ASP, DBX, TBB, ADB and PL.
W32/MyDoom-A creates a file called Message in the temp folder and runs Notepad to display the contents, which displays random characters.
W32/MyDoom-A spoofs, using randomly chosen email addresses in the "To:" and "From:" fields as well as a randomly chosen subject line. The emails distributing this worm have the following characteristics.
Subject lines
error
hello
hi
mail delivery system
mail transaction failed
server report
status
test
[random collection of characters]
Message texts
test
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment
The message contains Unicode characters and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.
Attachment filenames
body
data
doc
document
file
message
readme
test
[random collection of characters]
Attached files will have an extension of BAT, CMD, EXE, PIF, SCR or ZIP.
W32/MyDoom-A is programmed to not forward itself via email if the recipient email address satisfies various conditions:
The worm will not send itself to email addresses belonging to domains containing the following strings: acketst, arin., avp, berkeley, borlan, bsd, example, fido, foo., fsf., gnu, google, .gov, gov., hotmail, iana, ibm.com, icrosof, ietf, inpris, isc.o, isi.e, kernel, linux, math, .mil, mit.e, mozilla, msn., mydomai, nodomai, panda, pgp, rfc-ed, ripe., ruslis, secur, sendmail, sopho, syma, tanford.e, unix, usenet, utgers.ed As a consequence the worm does not forward itself to a number of email domains, including several anti-virus companies and Microsoft.
The worm will not send itself to email addresses in which the username contains the following strings: abuse, anyone, bugs, ca, contact, feste, gold-certs, help, info, me, no, noone, nobody, not, nothing, page, postmaster, privacy, rating, root, samples, secur, service, site, spm, soft, somebody, someone, submit, the.bat, webmaster, you, your, www
The worm will not send itself to email addresses which contain the the following strings: admin, accoun, bsd, certific, google, icrosoft, linux, listserv, ntivi, spam, support, unix
The worm can also copy itself into the shared folder of the KaZaA peer-to-peer application with one of the following filenames and a PIF, EXE, SCR or BAT extension:
activation_crack
icq2004-final
nuke2004
office_crack
rootkitXP
strip-girl-2.0bdcom_patches
winamp5
Further reading: MyDoom worm spreads widely across internet, Sophos warns users to be wary of viral email and hacker attack W32/MyDoom-A is a worm which spreads by email. When the infected
attachment is launched, the worm harvests email addresses from address
books and from files with the following extensions: WAB, TXT, HTM, SHT, PHP,
ASP, DBX, TBB, ADB and PL.
W32/MyDoom-A creates a file called Message in the temp folder and runs Notepad to display the contents, which displays random characters.
W32/MyDoom-A spoofs, using randomly chosen email addresses in the "To:" and "From:" fields as well as a randomly chosen subject line. The emails distributing this worm have the following characteristics.
Subject lines
error
hello
hi
mail delivery system
mail transaction failed
server report
status
test
[random collection of characters]
Message texts
test
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment
The message contains Unicode characters and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.
Attachment filenames
body
data
doc
document
file
message
readme
test
[random collection of characters]
Attached files will have an extension of BAT, CMD, EXE, PIF, SCR or ZIP.
W32/MyDoom-A is programmed to not forward itself via email if the recipient email address satisfies various conditions:
The worm will not send itself to email addresses belonging to domains containing the following strings: acketst, arin., avp, berkeley, borlan, bsd, example, fido, foo., fsf., gnu, google, .gov, gov., hotmail, iana, ibm.com, icrosof, ietf, inpris, isc.o, isi.e, kernel, linux, math, .mil, mit.e, mozilla, msn., mydomai, nodomai, panda, pgp, rfc-ed, ripe., ruslis, secur, sendmail, sopho, syma, tanford.e, unix, usenet, utgers.ed As a consequence the worm does not forward itself to a number of email domains, including several anti-virus companies and Microsoft.
The worm will not send itself to email addresses in which the username contains the following strings: abuse, anyone, bugs, ca, contact, feste, gold-certs, help, info, me, no, noone, nobody, not, nothing, page, postmaster, privacy, rating, root, samples, secur, service, site, spm, soft, somebody, someone, submit, the.bat, webmaster, you, your, www
The worm will not send itself to email addresses which contain the the following strings: admin, accoun, bsd, certific, google, icrosoft, linux, listserv, ntivi, spam, support, unix
The worm can also copy itself into the shared folder of the KaZaA peer-to-peer application with one of the following filenames and a PIF, EXE, SCR or BAT extension:
activation_crack
icq2004-final
nuke2004
office_crack
rootkitXP
strip-girl-2.0bdcom_patches
winamp5
W32/MyDoom-A creates a file called taskmon.exe in the system or temp folder and adds the following registry entry to run this file every time Windows starts up:
HKLMSoftwareMicrosoftWindowsCurrentVersionRunTaskmon = taskmon.exe
Please note that on Windows 95/98/Me, there is a legitimate file called taskmon.exe in the Windows folder.
W32/MyDoom-A also drops a file named shimgapi.dll to the temp or system folder. This is a backdoor program loaded by the worm that allows outsiders to connect to TCP port 3127. The DLL adds the following registry entry so that it is run on startup:
HKCRCLSID{E6FB5E20-DE35-11CF-9C87-00AA005127ED}InProcServer32
Default= ""
The worm will also add the following entries to the registry:
HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerComDlg32
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerComDlg32
W32/MyDoom-A, W32/MyDoom-AJ, W32/MyDoom-B, W32/MyDoom-F, W32/MyDoom-N, W32/MyDoom-O, W32/MyDoom-S and Troj/Bdoor-CHR can be removed from Windows computers automatically with the following Resolve tools:
Windows disinfector
BDLAAGUI is a disinfector for standalone Windows computers. To use it you have to do the following:
- Open MYDOOGUI.com file from your desktop after downloading it.
- Click on the Start Scan Button.
- Wait for the process to complete.
Command line disinfector
MYDOOSFX.EXE is a self-extracting archive containing MYDOOCLI, a Resolve command line disinfector for use on Windows networks. Read the notes enclosed in the self-extractor for details on running this program.
For Troj/Bdoor-CHR, you should replace the HOSTS file from backup, or open it in Notepad and remove any of the entries listed in the virus description.
Win32.MyDoom.S@mm Free Removal tool 1.0
Free removal tool for Win32.MyDoom.S@mm more>>
Presence of "winpsd.exe" in %system% (e.g. C:WindowsSystem32) folder, in processes list and presence in start-up registry key "HKLMSoftwareMicrosoftWindowsCurrentVersionRun" under the string "winpsd".
Presence of "rasor38a.dll" in %windir% (e.g. C:Windows) folder, which is a copy of the worm.
Spreads via email, attatched with the name "photos_arc.exe"; the subject of the email is "Photos"; the body is "LOL!;))))" while the sender is spoofed.
IMPORTANT! The tool must be run in Safe Mode in order to detect and clean one or more stealth components of MyDoom worm.
Win32.MyDoom.M@mm Free Removal tool 1.0
Free removal for Win32.MyDoom.M@mm more>>
- Presence of the following registry key:
- HKLMSoftwareMicrosoftWindowsCurrentVersionRunJavaVM
with the following value:
- %WINDIR%java.exe
Presence of the following files:
- %WINDIR%java.exe
- %WINDIR%services.exe
The port 1034 is listening for incoming connections.
Technical description: This is an internet worm that spreads trough e-mail. When it is run it adds the following registry key:
HKLMSoftwareMicrosoftWindowsCurrentVersionRunJavaVM
with the following value: %WINDIR%java.exe
It copies itself to %WINDIR%java.exe
where %WINDIR% is a variable representing the Windows directory.
It drops the following file: %WINDIR%services.exe, that is detected by BitDefender as Backdoor.Mydoom.M
It tries to terminate some programs that have windows with the following names: rctrl_renwnd32, ATH_Note, IEFrame.
Win32.Mydoom.V@mm Free Removal tool 1.0
Free Removal tool for Win32.Mydoom.V@mm virus more>>
Presence of a file tmp*.tmp with a size of 234496 bytes.
Presence of registry key: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunWinSPF = %SYSTEM%winspf32.exe.
HKCUSOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsVersion = FrankenShteiN
HKLMSOFTWAREMicrosoftWindowsCurrentVersionInternet SettingsVersion = FrankenShteiN
HKCUSOFTWAREMicrosoftWindowsCurrentVersionInternet Settings5.0User Agent
HKLMSOFTWAREMicrosoftWindowsCurrentVersionInternet Settings5.0User Agent
This is a mass-mailer that also drops a backdoor. The file is downloaded from one the following urls:
"http://www.llc.unibo.it"
"http://www.surrenderzeeland.nl"
"http://www.mercyships.de"
"http://www.hiw.kuleuven.ac.be"
"http://www.ach.ch"
"http://vugs.geog.uu.nl"
"http://www.planetboredom.net"
and is downloaded to a temporary file ( with a temporary name ). This files size is 234496 bytes.
It seems that there are more versions of this worm, which are just recompilations of the same source.
The worm creates a mutex called qwedefacedRDE. It uses threads for searching for e-mail addreses in the following file types: wab,xls,vbs,uin,txt,tbb,stm,sht,php,msg,mht,jsp,htm,eml,dht,dbx,cgi,cfg,asp.
It sends mail using its own SMTP engine.
