Encyclopedia

Mydoom.A

 
PeligrosidadPeligrosidad altaDañoMuy dañinoPropagaciónPoco extendido
Nombre común:Mydoom.A
Nombre técnico:W32/Mydoom.A.worm
Peligrosidad:Media
Alias:I-Worm/Novarg, WORM_MIMAIL.R W32/Mydoom@MM I-Worm/Novarg@MM
Tipo:Gusano
Efectos:  

It launches Distributed Denial of Service attacks against the website www.sco.com. It opens a port, allowing a hacker to gain remote access to network resources.

Plataformas que infecta:

Windows 2003/XP/2000/NT/ME/98/95

Fecha de detección:27/01/2004
Detección actualizada:25/06/2007
EstadísticasNo
Sí, mediante las Tecnologías TruPrevent
Utilidad de reparación: Panda QuickRemover

Descripción Breve 

    

Mydoom.A is a worm that spreads via e-mail in a message with variable characteristics and through the peer-to-peer (P2P) file sharing program KaZaA.

Mydoom.A launches DDoS (Distributed Denial of Service) attacks against the website www.sco.com if the system date is between February 1 and February 12, 2004. It does this by launching GET/ HTTP/ 1.1 requests every 1,024 milliseconds. On February 12, 2004, the worm finishes its payload, ending its execution whenever it is activated.

Mydoom.A drops the DLL (Dynamic Link Library) SHIMGAPI.DLL, which creates a backdoor, opening the first available TCP port in the range from 3127 to 3198. This backdoor component allows to download and run an executable file, and acts as a TCP proxy server, allowing a hacker to gain remote access to network resources.

Note: on February 10, 2004, a new variant of this worm was detected by PandaLabs. This new variant carries out the same actions as the original, but it is compressedUPX.

Visible Symptoms 

    

Mydoom.A is easy to recognize once it has affected the computer, as it opens the Windows Notepad and shows junk data.

Last updated:  25/06/2007 

Virus News

3/10/09.-More than 10 Million Worldwide Were Actively Exposed to Identity Theft in 2008

3/5/09.-Cyber-crooks manipulate Internet searches to sell fake antivirus products

3/2/09.-VideoPlay adware infections grew 400% in February through malicious use of Web 2.0 pages

[+ Noticias]