wipe-deletion-erasure-purge


I-Worm.Mydoom.g

I-Worm.Mydoom.g

CyberScrub AntiVirus
Research Bank

I-Worm.Mydoom.g spreads via the Internet as an attachment to infected messages. The worm itself is a Windows PE EXE file of 32256 bytes, packed using UPX.

I-Worm.Mydoom.g will be launched only if the user opens the archive and executes the infected file. The worm will then install itself to the system and start propagating.

The worm includes a backdoor function, and is also coded to conduct a DoS attack on www.symantec.com and symantec.com

Once the file has been unpacked, the following text string is visible:

to netsky's creator(s): imho, skynet is a decentralized peer-to-peer neural network. we have seen P2P in Slapper in Sinit only. they may be called skynets, but not your shitty app.
Installation

Once the worm is launched, it may open Windows Notepad, which will display a random selection of characters.

When installing, the worm copies itself under a random name, with the extension .exe or .scr to the Windows system directory. It registers this file in the system registry to ensure that the worm is launched each time Windows is started:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
 "<random characters>"="%System%\<name of file>"

The worm creates a file with a random name and a .dll extension in the Windows system directory. This is the backdoor component. This file is also registered in the system registry:

[HKCR\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32]
 "<random characters>"="%System%\<name of file.dll>"

This ensures that the DLL is launched as an Explorer.exe child process.

To flag its presence in the system, the worm creates a mutex <name of computer>theta,. This ensures that only one copy of the worm can be launched at once.

The worm copies itself to all accessible hard disks under a random name; it also creates copies of itself in ZIP archives.

It searches all accessible hard drives for files with the extensions listed below. It then creates copies of itself under these file names, adding either an .exe or a .pif extension.

avi
doc
jpg
mp3
mp4
wav
wma
xls
Mass mailing

The mass mailing function is similar to the other versions of Mydoom, with a few insignificant differences.

Remote administration

The worm opens TCP ports 80 and 1080 to receive commands. The backdoor component can act as a proxy server, and also download and launch files.

Other

The worm is coded to detect and terminate the following processes in memory:



adaware.exe
alevir.exe
arr.exe
au.exe
avpupd
avwupd
backweb.exe
bargains.exe
beagle
belt.exe
blss.exe
bootconf.exe
bpc.exe
brasil.exe
bundle.exe
bvt.exe
cfd.exe
click
cmd32.exe
cmesys.exe
d3du
datemanager.exe
dcomx.exe
divx.exe
dllcache.exe
dllreg.exe
dpps2.exe
dssagent.exe
emsw.exe
explore.exe
fsg_4104.exe
fuck
gator.exe
gmt.exe
hbinst.exe
hbsrv.exe
hotactio
hotfix.exe
hotpatch.exe
htpatch.exe
hxdl.exe
hxiul.exe



idle.exe
iedll.exe
iedriver.exe
iexplorer.exe
inetlnfo.exe
infus.exe
infwin.exe
init.exe
intdel.exe
intren
isass.exe
istsvc.exe
jdbgmrg.exe
kazza.exe
keenvalue.exe
kernel32.exe
launcher.exe
lnetinfo.exe
loader.exe
mapisvc32.exe
md.exe
mfin32.exe
mmod.exe
mostat.exe
msapp.exe
msbb.exe
msblast.exe
mscache.exe
msccn32.exe
mscman.exe
msdm.exe
msdos.exe
msiexec16.exe
mslaugh.exe
msmgt.exe
msmsgri32.exe
msrexe.exe
mssys.exe
msvxd.exe
netd32.exe
nssys32.exe
nstask32.exe



nsupdate.exe
onsrvr.exe
optimize.exe
patch.exe
penis
pgmonitr.exe
porn
powerscan.exe
prizesurfer.exe
prmt.exe
prmvr.exe
pussy
ray.exe
rb32.exe
rcsync.exe
reged
run32dll.exe
rundll.exe
rundll16.exe
ruxdll32.exe
sahagent.exe
save.exe
savenow.exe
sc.exe
scam32.exe
scrsvr.exe
scvhost.exe
service.exe
servlce.exe
servlces.exe
showbehind.exe
sms.exe
smss32.exe
soap.exe
sperm
spoler.exe
spoolcv.exe
spoolsv32.exe
srng.exe
ssgrate.exe
start.exe
stcloader.exe



support.exe
svc.exe
svchostc.exe
svchosts.exe
svshost.exe
system.exe
system32.exe
sysupd.exe
taskmg
taskmo
teekids.exe
trickler.exe
tsadbot.exe
tvmd.exe
tvtmd.exe
updat
upgrad
utpost.
webdav.exe
win32.exe
win32us.exe
winactive.exe
win-bugsfix.exe
window.exe
windows.exe
wininetd.exe
wininit.exe
wininitx.exe
winlogin.exe
winmain.exe
winnet.exe
winppr32.exe
winservn.exe
winssk32.exe
winstart.exe
winstart001.exe
wintsk32.exe
winupdate.exe
wkufind
wnad.exe
wupdater.exe
wupdt.exe

DoS attacks

The worm searches the victim machine for the file C:\Feedlist. If it detects this file, it will attempt to conduct a DoS attack on www.symantec.com and symantec.com by sending looped multiple GET requests.

Check out if we have free removal tool for this virus


CyberScrub AntiVirus provides state of the art security protection for five years- at one low price. Our award winning technology ensures protection against viruses, worms and trojans backed by top customer support and value.

 
Five Year Cost Comparison
Product Initial Cost Yearly Subscription X Four Years Total
Norton 2004 AntiVirus $49.95* $29.95 $119.80 $169.75
McAfee VirusScan $49.95* $19.95 $79.80 $129.75
CyberScrub AntiVirus $49.95 Included No Additional Cost $49.95
*All prices MSRP as published on respective sites.




It is only a matter of time before a virus, worm or Trojan horse wrecks havoc on your important data. Important files, records, family pictures- all at risk. Some dangerous programs can even ruin your hard drive beyond repair.

CyberScrub AntiVirus offers the most effective protection from all known and unknown viruses.

CyberScrub AntiVirus is powered by a unique integrated technology for virus detection, based on principles of multi-generation heuristic analysis. This allows the program to protect you from suspect “viral behavior”. This highly effective methodology repelled all attacks of each “I LOVEYOU’ viral variation without any additional antivirus database updates. No other technology, including Norton, Trend, or McAfee was able to accomplish this.

CyberScrub AntiVirus is powerful, yet its exceptional ease of use and installation make it acceptable for beginner to pro



CyberScrub Antivirus constantly scans your hard drive and files to identify, clean and destroy infected objects. With updates available every three hours, 24 hours a day, 365 days a year, you can count on CyberScrub to protect your valued data.

CyberScrub AntiVirus
Lifetime Edition

"For the Life of Your Computer"

Save $10 Now!
Limited Time

 


I-Worm.Mydoom.g


Symantec Warns Of Flaw In Antivirus Program. More>>

CNN Legend Lynne Russell reports on CyberScrub AntiVirus for Tech Headline News.


















 
 

delete,deletion, file deletion, Internet clean up,privacy, HIPAA, Internet privacy, cookies, erase, erasure, shredder, wipe, overwrite, purge, deletion, security, file wipe, data destruction