|
Description
Free removal for Win32.MyDoom.M@mm
Features
- Presence of the following registry key:
- HKLMSoftwareMicrosoftWindowsCurrentVersionRunJavaVM
with the following value:
- %WINDIR%java.exe
Presence of the following files:
- %WINDIR%java.exe
- %WINDIR%services.exe
The port 1034 is listening for incoming connections.
Technical description: This is an internet worm that spreads trough e-mail. When it is run it adds the following registry key:
HKLMSoftwareMicrosoftWindowsCurrentVersionRunJavaVM
with the following value: %WINDIR%java.exe
It copies itself to %WINDIR%java.exe
where %WINDIR% is a variable representing the Windows directory.
It drops the following file: %WINDIR%services.exe, that is detected by BitDefender as Backdoor.Mydoom.M
It tries to terminate some programs that have windows with the following names: rctrl_renwnd32, ATH_Note, IEFrame.
|