MyDoom: Prevention and cure

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

COMMENT

MyDoom is a mass-mailing worm that masquerades as a test message. MyDoom (w32.mydoom@mm, also known as Novarg, Shimgapi, Shimg, and MiMail.r) takes advantage of the ZIP file format's ability to pass through email filters. It also uses Kazaa to spread. Within the first few hours, MyDoom spread quickly around the world. It affects only Windows users, not those using Macintosh, Linux, or Unix. Much of the worm's code is itself encrypted, and antivirus firms are still studying it. Because MyDoom spreads via email and could severely slow or shut down email servers with excess traffic, this worm rates a 7/10 on the ZDNet Virus Meter.

How it works
MyDoom arrives as email with the subject line "Mail Delivery System," "Test," or "Mail Transaction Failed". The body text reads: "The message contains Unicode characters and has been sent as a binary attachment." The attached files are one of the following:

document.zip
document.pif
doc.scr
message.pif
readme.exe
file.zip
message.zip
oia.zip
text.zip

When the worm is executed, MyDoom adds the following to the Windows/System subdirectory:

shimgapi.exe
taskmon.exe

If you are running the file-sharing program Kazaa, MyDoom will add a file named activation_crack.scr in this location: C:\Program files\Kazaa\My Shared Folder\.

The worm appears to install programs on infected computers, however, the programs themselves are encrypted. MyDoom is known to open Windows Notepad and display garbage text; it is also thought to be flooding Sco.com with a denial-of-service attack. In addition, the security company iDefense and McAfee are reporting that MyDoom opens port 3127 to listen for commands from a remote attacker.

Prevention
If you receive MyDoom, do not open the attached file. Delete the email.

Removal
Almost all antivirus software companies have updated their signature files to include this worm. This will stop the infection upon contact and in some cases will remove an active infection from your system. For more information, see Central Command, Computer Associates, F-Secure, McAfee, Norman, Sophos, Symantec or Trend Micro.

Talkback

I've just posted this a message on "The Scream" suggesting that taskmon.exe is a genuine Windows 98SE and should not be deleted. Maybe a genuine Me file too.

http://www.the-scream.co.uk/forums/showthread.php?s=&threadid=11765

via Facebook 29 January, 2004 10:47
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

SoapyTablet

'Cut Price' Data Roaming? The price has been cut, but it is certainly not 'cut price' in the sense of the phrase, and nowhere near local EU data...

22 minutes ago by SoapyTablet on Cut-price data roaming gets all-clear for July
apexwm

BrownieBoy: "Such crashes are normally down to the OS and/or a rogue application, which could be fixed by re-imaging. Everybody knows how Windows...

1 hour ago by apexwm on Using Windows XP is a waste of money, says IDC
Thomas Gellhaus

I've just started using it too, and like you I feel that Fedora is a fine GNOME 3 showcase distribution. I am torn, though, because I checked out...

1 hour ago by Thomas Gellhaus via Facebook on Fedora 17 - The "Beefy Miracle" Arrives
pjc158

Why is it that Newzealand has the guts to stand up to the USA and ask to see the evidence and we don't!

1 hour ago by pjc158 on Judge orders US to share MegaUpload evidence
Dean Talboys

What a farce! Hopefully the European court will see where this is leading.

3 hours ago by Dean Talboys via Facebook on Assange loses extradition battle in Supreme Court
SoapyTablet

Wouldn't surprise me if Samsung actually really had problems producing the white model (as Apple did - it would make more sense) and this non-story...

4 hours ago by SoapyTablet on Samsung Galaxy 'S3' delayed by special paint
Lonnie

those conformation letters are hard to figure out what is which letters it is a pain in the back side. Please make it more Ledge-able being better...

8 hours ago by Lonnie on Screenshots: Photoshop CS6 Beta
BrownieBoy

"cites" even. Ouch!

15 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
Horace Ontalhold

...... and PDP11s too

15 hours ago by Horace Ontalhold on Fusion-io lays minefield with a billion IOPS
BrownieBoy

I had a quick skim through the PDF. It seems to be that many of these so-called cost savings would be down to a hardware refresh. Although...

16 hours ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
bobandroid

496,999 BT Fon Hotspots lovingly situated in your next door neighbours garden, no matter how you dress that up its still a pup... Not where I need...

18 hours ago by bobandroid on London Olympics: BT needs 25,000 more Wi-Fi hotspots
apexwm

Jack : I was hoping you could provide us a summary since you are familiar with this report. I am not yet sure how much of my time I'd like to...

20 hours ago by apexwm on Using Windows XP is a waste of money, says IDC
Smilig Eddie

2 – 4 more weeks of waiting: how many buyers are going to decide instead to see what the iPhone 5 offers? Consumer trust in the brand has also...

20 hours ago by Smilig Eddie on Samsung Galaxy 'S3' delayed by special paint
SRist

So it looks like this was a complete red herring - Adobe are allowing upgrades from Photoshop CS3, CS4 and CS5 at the same price. When did this...

21 hours ago by SRist on Photoshop users attack Adobe upgrade policy change
Jack Schofield

@apexwm Have you considered either (a) reading the story above or (b) reading the PDF? There are answers in both.

23 hours ago by Jack Schofield on Using Windows XP is a waste of money, says IDC
apexwm

I would love to hear why Microsoft believes that "upgrading from Windows XP to Windows 7 pays for itself in a year, in increased productivity and...

23 hours ago by apexwm on Using Windows XP is a waste of money, says IDC
debsmk

I have just changed mine to white they said 3 to 5 days

1 day ago by debsmk on Samsung Galaxy 'S3' delayed by special paint
Atangana

I would like a job for me and do good to their tackiness vellent my help I will do my best to help you mercie for all

1 day ago by Atangana on UK's 15-year-old World Excel champion offered £100k job
BrownieBoy

Well done to IDC for producing a report that says using XP is a waste of money. Only 11 years too late with it is all....

1 day ago by BrownieBoy on Using Windows XP is a waste of money, says IDC
Jack Schofield

@Burn-IT ...which doesn't mean it isn't true ;-) I'll be interested if you can find any properly-researched, independent data from any of the...

1 day ago by Jack Schofield on Using Windows XP is a waste of money, says IDC