Sophos

W32/MyDoom-BH

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email messages
  • Peer-to-peer
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 21 March 2005 07:13:59 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

Please follow the instructions for removing worms.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DebugMonitor
%SYSTEM%\debugmonitor.exe

and delete it if it exists.

Close the registry editor.

More Information

W32/MyDoom-BH is a mass-mailing and peer-to-peer worm.

W32/MyDoom-BH may also attempt do download and execute components from remote webistes. W32/MyDoom-BH is a mass-mailing and peer-to-peer worm.

When first run the worm will display a dialog box with the title "AVToolKitPro" and message of "Operation completed". The worm will then copy itself to the Windows system folder as debugmonitor.exe and create the following registry entry so as to auto-start:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run
DebugMonitor
%SYSTEM%\debugmonitor.exe

The worm will also attempt to copy itself to the KaZaa share folder if it exists using one of the following filenames and an extension chosen from PIF, SCR, EXE or BAT:

nuke2004
office_crack
rootkitXP
strip-girl-2.0bdcom_patches
activation_crack
icq2004-final
winamp5

W32/MyDoom-BH will harvest email address from files on the local drives with the following extensions:

WAB PL ADB TBB DBX ASP PHP SHT HTM TXT

Emails sent by the worm are in HTML and may take the following form:

Subject:

Virus Alert id: <random number>

Message text:

You received this message as a valuable
Symantec.com member since September 23, 2003.
************************************************************
WARNING! Your computer was infected by VIRUS:
Worm.SomeFool.P
You can install this utility to remove virus
************************************************************
http://securityresponse.symantec.com/avcenter/FxAgentB.exe

W32/MyDoom-BH may also attempt do download and execute components from remote webistes.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer