x
48h OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
SPECIAL OFFER
If you're already a customer of
our homeusers protection,
renew now with a 50% off
RENEW NOW
x
HALLOWEEN OFFER
take advantage of our
terrific discounts
BUY NOW AND GET A 50% OFF
x
CHRISTMAS OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 40% OFF
x
SPECIAL OFFER
Buy the best antivirus
at the best price
BUY NOW AND GET A 50% OFF
x
BLACKFRIDAY OFFER
Buy the best antivirus
at the best price
TODAY ONLY UP TO 70% OFF
x
CYBERMONDAY OFFER
Buy the best antivirus
at the best price
(Only for homeusers)
TODAY ONLY UP TO 70% OFF
Active Scan. Scan your PC free
Panda Protection

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Mydoom.E

Threat LevelModerate threatDamageHighDistributionNot widespread
Common name:Mydoom.E
Technical name:W32/Mydoom.E.worm
Threat level:Low
Alias:I-Worm.MyDoom.d, W32/Mydoom.e.dll, W32/MyDoom-E
Type:Worm
Effects:  

It launches Distributed Denial of Service attacks against the website www.sco.com. It opens a port, allowing a hacker to gain remote access to network resources.

Affected platforms:

Windows 2003/XP/2000/NT/ME/98/95

Detection updated on:Feb. 16, 2004
StatisticsNo

Brief Description 

    

Mydoom.E is a worm that spreads via e-mail in a message with variable characteristics and through the peer-to-peer (P2P) file sharing program KaZaA.

Mydoom.E launches DDoS (Distributed Denial of Service) attacks against the website www.sco.com if the system date is between February 1 and February 14, 2004. It does this by launching GET/ HTTP/ 1.1 requests every 1,024 milliseconds. On February 14, 2004, the worm finishes its payload, ending its execution whenever it is activated.

Mydoom.E drops the DLL (Dynamic Link Library) SHIMGAPI.DLL, which creates a backdoor, opening the first available TCP port in the range from 3127 to 3198. This backdoor component allows to download and run an executable file, and acts as a TCP proxy server, allowing a hacker to gain remote access to network resources.

Visible Symptoms 

    

Mydoom.E is easy to recognize once it has affected the computer, as it opens the Windows Notepad and shows junk data: