Encyclopedia

Panda Internet Security 2010

Panda Internet Security 2010

Full protectión for complete peace of mind on the Internet.

* Includes 3 months' services FREE

Mydoom.AO

 
Threat LevelHigh threatDamageSevereDistributionNot widespread
Common name:Mydoom.AO
Technical name:W32/Mydoom.AO.worm
Threat level:High
Alias:W32/Mydoom.bb@MM, W32.Mydoom.AX@mm, W32/MyDoom-O, W32/Mydoom, Win32.Mydoom.AU, Email-Worm.Win32.Mydoom.m
Type:Worm
Effects:  

It opens the TCP port 1034, acting as a backdoor. It downloads and installs the backdoor Bck/Surila.J and spreads via e-mail in a message with variable characteristics.

Affected platforms:

Windows 2003/XP/2000/NT

First detected on:Feb. 17, 2005
Detection updated on:Aug. 13, 2006
StatisticsNo
Yes, using TruPrevent Technologies

Brief Description 

    

Mydoom.AO is a worm that affects Windows 2003/XP/2000/NT computers only. It opens the TCP port 1034 and listens to it, acting as a backdoor.

Mydoom.AO downloads a file called MODULELOG.PNG from the Internet. In fact, this file is not a PNG image, but an executable file belonging to the backdoor Bck/Surila.J.

Mydoom.AO spreads via e-mail, in a message with variable characteristics that passes itself off as a mail delivery error. In order to harvest e-mail addresses to send itself to, this worm looks for files on the affected computer, but it also uses intensive searches on web searchers.

Mydoom.AO uses popular web searchers, such as Google, Altavista, Yahoo and Lycos.

Additionally, Mydoom.AO is able to surpass certain anti-spam techniques commonly used when noting down e-mail addresses.

Visible Symptoms 

    

Mydoom.AO is difficult to recognize, as it does not display any messages or warnings that indicate it has reached the computer.

Last updated:  13/08/2006 

Thanks to Collective Intelligence, Panda's exclusive cloud-computing technology, the company's 2010 solutions leverage the knowledge gathered from the community of millions of Panda users around the world. Each new file received is automatically classified within six minutes and the Collective Intelligence servers classify more than 50,000 new malware samples every day. These technologies correlate information on malware received from each computer to continuously improve the protection level for the worldwide community of users. Panda's 2010 solutions have continuous, real-time contact with this vast knowledge base allowing the company to offer users the fastest response against the new malware that appears every day.

Virus News

Help your friends against viruses: share, save and subscribe to our security content. Thank you.

Share/Bookmark

Panda Security and Defence Intelligence Coordinate Massive Botnet Shutdown with ...

New FTLog.A worm spreads through Fotolog social networking website, reports Pand...

Spybot.AKB spreads across P2P networks and email using Google, Twitter, Amazon, ...

[+ News ]