name: MyDoom
aka: W32/Mydoom@MM,
W32.Novarg@mm
type: Worm
host platform: Windows
first incidence: 1/26/2004
level of incidence: High
damage capacity: High
links:
Symantec-MyDoom.A,
McAfee-MyDoom.A
Symantec-MyDoom.B,
McAfee-MyDoom.B
Symantec-MyDoom.C,
McAfee-MyDoom.C
Symantec-MyDoom.F,
McAfee-MyDoom.F
Symantec-MyDoom.G,
MyAfee-MyDoom.G
Symantec-MyDoom.H,
McAfee-MyDoom.H
look for emails with the following characteristics:
Subject:
Message:
- Mail transaction failed. Partial message
is available.
- The message contains Unicode characters
and has been sent as a binary attachment.
- The message cannot be represented in 7-bit
ASCII encoding and has been sent as a binary attachment.
- test
- sendmail daemon reported:
- Error #804 occured during SMTP session.
Partial message has been received.
- The message contains MIME-encoded graphics
and has been sent as a binary attachment.
- You are bad
- Take it
- Reply
- Please, reply
- Information about you
- Greetings
- See you
- Here it is
- We have received this document from your
email.
- Kill the writer of this document!
- Something about you
- I have your password :)
|
- You are a bad writer
- Is that yours?
- Is that from you?
- I wait for your reply.
- Here is the document.
- Read the details.
- I'm waiting
- Okay
- OK
- Everything ok?
- Check the attached document.
- The document was sent in compressed
format.
- Please see the attached file for details
- See the attached file for details
- Details are in the attached document. You
need Microsoft Office to open it.
- Details are in the attached document
- Full message is in the attached documen
- Here is the document
- Here is the file
|
- Hi! Check the attachment for details
- Look at the attached file
- Look at the document
- Ok
- Open the document
- Please have a look at the attached file
- Please read the attached file
- Please, read and let me know what do yo
- Re:
- Read the attached message
- Read the document
- Read this
- See attachemnt
- See attachment
- See the attached document
- See the attached message
- Test
- Your document is attached
- Your file is attached
|
Attachment:
- document
- readme
- doc
- text
- file
- data
- test
- message
- body
- photo
- resume
- image
- your_document
- approved
- paypal
- disc
- misc
- part3
- part2
- part4
|
- part1
- mail2
- object
- website
- friend
- jokes
- joke
- list
- mail
- story
- about
- money
- check
- product
- notes
- note
- information
- textfile
- posting
- post
|
- stuff
- attachment
- creditcard
- details
- msg
- AttachedDocument
- AttachedFile
- Document
- Letter
- MoreInfo
- TextDocument
- TextFile
- account
- all_document
- application
- archive
- att
- attach
- bill
- description
|
- for_you
- found
- id
- important
- info
- letter
- message_details
- message_part2
- more
- msg2
- music
- news
- no
- payment
- pic
- price
- problem
- ps
- reply
- response
|
with the first potential extension of:
- htm
- txt
- doc
- rtf
- xls
- jpg
- gif
- png
|
and second potential extension of:
MyDoom is a mass-mailing worm that hides itself in the email attachment. Opening
the attachment will install a backdoor granting attackers full access to the
victim's computer.
MyDoom has mutated since its release. The latest
is MyDoom.H. As variants have differing capacities, hallmarks and removal
requirements, Norton (Symantec) has developed pages and removal tools for each.
Norton has made available the removal
instructions available at:
MyDoom:
Info,
Removal Tool
MyDoom.B:
Info,
Removal Tool
MyDoom.C:
Info,
Removal Instructions
MyDoom.F:
Info,
Removal Tool
MyDoom.G:
Info,
Removal Instruction
MyDoom.H:
Info,
Removal Instructions
For info on computer viruses and guidelines for
avoiding them, please see
http://www.greenapple.com/support/library/virus-faq.htm
If you believe you have become infected or have any questions regarding viruses,
please do not hesitate to
contact us. As always, as a Green Apple user you are welcome to bring in
your computer for us to examine and, where possible, fix.
|