Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 21 March 2005 07:13:59 (GMT) |
| Detected by | All Sophos products |
- Endpoint Security and Control 9.0
- Small business solutions 4.0
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Windows NT/2000/XP/2003
In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.
At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.
Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.
Locate the HKEY_LOCAL_MACHINE entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DebugMonitor
%SYSTEM%\debugmonitor.exe
and delete it if it exists.
Close the registry editor.
More Information
W32/MyDoom-BH is a mass-mailing and peer-to-peer worm.
W32/MyDoom-BH may also attempt do download and execute components from remote webistes. W32/MyDoom-BH is a mass-mailing and peer-to-peer worm.
When first run the worm will display a dialog box with the title "AVToolKitPro" and message of "Operation completed". The worm will then copy itself to the Windows system folder as debugmonitor.exe and create the following registry entry so as to auto-start:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DebugMonitor
%SYSTEM%\debugmonitor.exe
The worm will also attempt to copy itself to the KaZaa share folder if it exists using one of the following filenames and an extension chosen from PIF, SCR, EXE or BAT:
nuke2004
office_crack
rootkitXP
strip-girl-2.0bdcom_patches
activation_crack
icq2004-final
winamp5
W32/MyDoom-BH will harvest email address from files on the local drives with the following extensions:
WAB PL ADB TBB DBX ASP PHP SHT HTM TXT
Emails sent by the worm are in HTML and may take the following form:
Subject:
Virus Alert id: <random number>
Message text:
You received this message as a valuable
Symantec.com member since September 23, 2003.
************************************************************
WARNING! Your computer was infected by VIRUS:
Worm.SomeFool.P
You can install this utility to remove virus
************************************************************
http://securityresponse.symantec.com/avcenter/FxAgentB.exe
W32/MyDoom-BH may also attempt do download and execute components from remote webistes.
