MSN Home  |  My MSN  |  Hotmail
Sign in to Windows Live ID Web Search:   
go to MSNGroups 
Free Forum Hosting
 
Important Announcement Important Announcement
The MSN Groups service will close in February 2009. You can move your group to Multiply, MSN’s partner for online groups. Learn More
Illinois Kinfolk Konnection[email protected] 
  
What's New
  
  Welcome  
  Happy Birthday IKK  
  Tutorials  
  Computer Help  
  Computer Tips  
  Helpful Hints  
  Message Board  
  
  General  
  
  Jim's Gems  
  
  Brick Walls Bd.  
  
  Brick Walls List  
  
  Illinois Links  
  
  Cemeteries Board  
  
  Suggestion Box  
  
  Virus Alerts  
  
  Subscriptions  
  Lookups List  
  Yearbook List  
  Surnames List A-J  
  Surnames List K-Z  
  Pictures  
  IL Links List  
  Genealogy Links  
  Chat Reviews  
  Member Profiles  
  Meet Our Members  
  Headstone Finders  
  IL Obituaries Index  
  IL Obituaries  
  Obits on File  
  Lost and Found  
  In Memorium.....  
  IL Biographies Index  
  Biography Bits  
  ISTG Article  
  Questions to Ask  
  Kuzzins Konnect  
  Oddities  
  Memories  
  Recipes  
  Poetry  
  This and That  
  Kritters Korner  
  Hobby Lobby  
  Site Awards  
  Documents  
  Recommendations  
  
  
  Tools  
 
Virus Alerts : MydoomVirus Alert.....
Choose another message board
 
     
Reply
Recommend  Message 1 of 2 in Discussion 
From: MSN NicknameJanie·  (Original Message)Sent: 1/28/2004 12:20 AM
 
From: Gordon  (Original Message) Sent: 1/27/2004 4:34 PM
It's called mydoom a worm type virus. 
 
Virus Profile
Virus Information
Name: W32/Mydoom@MM
Risk Assessment  
  - Home Users: High-Outbreak
  - Corporate Users: High-Outbreak
Date Discovered: 1/26/2004
Date Added: 1/26/2004
Origin: Unknown
Length: 22,528 bytes
Type: Virus
SubType: E-mail
DAT Required: 4319
Quick Links
Virus Characteristics
Indications of Infection
Method of Infection
Removal Instructions
Aliases
Buy or Update
<NOBR>New Users Get Protected Now:
Buy VirusScan</NOBR>
<NOBR>Update VirusScan</NOBR>
Virus Characteristics Back to Top

This is a mass-mailing worm that arrives in an email message as follows:

From: (spoofed)
Subject: (Random)
Body:  (Varies, such as) 

  • The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
  • The message contains Unicode characters and has been sent as a binary attachment.
  • Mail transaction failed. Partial message is available.

Attachment: (varies [.exe, .pif, .cmd, .scr] - often arrives in a ZIP archive) (22,528 bytes)

The icon used by the file tries to make it appear as if the attachment is a text file

When this file is run it copies itself to the local system with the following filenames:

  •  c:\Program Files\KaZaA\My Shared Folder\activation_crack.scr
  •  %SysDir%\taskmon.exe

(Where %Sysdir% is the Windows System directory, for example C:\WINDOWS\SYSTEM)

It also uses a DLL that it creates in the Windows System directory:

It also uses a DLL that it creates in the Windows System directory:

  •  %SysDir%\shimgapi.dll (4,096 bytes)

It creates the following registry entry to hook Windows startup:

  • HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
    CurrentVersion\Run "TaskMon" = %SysDir%\taskmon.exe

The worm opens a connection on TCP port 3127 suggesting remote access capabilities.

AVERT is currently analyzing this the threat.  Details will be posted, as they are available.

Indications of Infection Back to Top
  • Upon executing the virus, Notepad is opened, filled with nonsense characters.
  • Existence of the files and registry entry listed above
Method of Infection Back to Top

This file tries to spread via email and by copying itself to the shared directory for Kazaa clients if they are present.

The mailing component harvests address from the local system.  Files with the following extensions are targeted:

  • wab
  • adb
  • tbb
  • dbx
  • asp
  • php
  • sht
  • htm
  • txt

Additionally, the worm contains strings, which it uses to randomly generate, or guess, addresses.



First  Previous  2 of 2  Next  Last 
Reply
The number of members that recommended this message. 0 recommendations  Message 2 of 2 in Discussion 
Sent: 1/29/2004 7:39 PM
This message has been deleted by the manager or assistant manager.