Win32.Mydoom.BA@mm( Mytob )
SYMPTOMS: - Internet Firewall in XP SP2 disabled. TECHNICAL DESCRIPTION: This virus is another variant of the (now very large) Mytob/Mydoom family. This is possible because the sources of a previous variant have been leaked on the Internet.At startup the virus copies itself in the %sysdir% directory under the name “scrigz.exe”. It adds itself in the HKLM\Software\Microsoft\Windows\CurrentVersion\Run and Runservices keys to ensure start at every system startup. It then lowers the IE security settings and disables shared access in the Windows Firewall. With the system security compromised, the virus will then create several threads, each with various functions:
- Monitor the virus entries in the system registry, restoring them as needed periodically. The virus will overwrite the %sysdir%\Drivers\Etc\hosts file, disabling the updates of certain AV programs and access to various security related web-sites. E-mail format is chosen at random from various templates: From: (spoofed).
Notice of account limitation Email Account Suspension Security measures Members 1. A recent change in your personal information (i.e. change of address). 2. Submiting invalid information during the initial sign up process. 3. An innability to accurately verify your selected option of subscription due to an internal error within our processors. See the details to reactivate your (random) account. Sincerely, You have successfully updated the password of your (random) account. Thank you for using (random)! Attachment: No Virus (Clean) 3. Dear user (random), It has come to our attention that your (random) User Profile ( x ) records are out of date. For further details see the attached document. +++ Attachment: No Virus (Clean) 4. Dear (random) Member, Your e-mail account was used to send a huge amount of unsolicited spam messages during the recent week. If you could please take 5-10 minutes out of your online experience and confirm the attached document so you will not run into any future problems with the online service. If you choose to ignore our request, you leave us no choice but to cancel your membership. Attachement name: (one of the following) account-report The virus will monitor and kill all processes that have these names: TASKMGR.EXE CMD.EXE _AVPM.EXE _AVPCC.EXE _AVP32.EXE ZONEALARM.EXE ZONALM2601.EXE ZATUTOR.EXE ZAPSETUP3001.EXE ZAPRO.EXE XPF202EN.EXE WYVERNWORKSFIREWALL.EXE WUPDT.EXE WUPDATER.EXE WSBGATE.EXE WRCTRL.EXE WRADMIN.EXE WNT.EXE WNAD.EXE WKUFIND.EXE WINUPDATE.EXE WINTSK32.EXE WINSTART001.EXE WINSTART.EXE WINSSK32.EXE WINSERVN.EXE WINRECON.EXE WINPPR32.EXE WINNET.EXE WINMAIN.EXE WINLOGIN.EXE WININITX.EXE WININIT.EXE WININETD.EXE WINDOWS.EXE WINDOW.EXE WINACTIVE.EXE WIN32US.EXE WIN32.EXE WIN-BUGSFIX.EXE WIMMUN32.EXE WHOSWATCHINGME.EXE WFINDV32.EXE WEBTRAP.EXE WEBSCANX.EXE WEBDAV.EXE WATCHDOG.EXE W9X.EXE W32DSM89.EXE VSWINPERSE.EXE VSWINNTSE.EXE VSWIN9XE.EXE VSSTAT.EXE VSMON.EXE VSMAIN.EXE VSISETUP.EXE VSHWIN32.EXE VSECOMR.EXE VSCHED.EXE VSCENU6.02D30.EXE VSCAN40.EXE VPTRAY.EXE VPFW30S.EXE VPC42.EXE VPC32.EXE VNPC3000.EXE VNLAN300.EXE VIRUSMDPERSONALFIREWALL.EXE VIR-HELP.EXE VFSETUP.EXE VETTRAY.EXE VET95.EXE VET32.EXE VCSETUP.EXE VBWINNTW.EXE VBWIN9X.EXE VBUST.EXE VBCONS.EXE VBCMSERV.EXE UTPOST.EXE UPGRAD.EXE UPDATE.EXE UPDAT.EXE UNDOBOOT.EXE TVTMD.EXE TVMD.EXE TSADBOT.EXE TROJANTRAP3.EXE TRJSETUP.EXE TRJSCAN.EXE TRICKLER.EXE TRACERT.EXE TITANINXP.EXE TITANIN.EXE TGBOB.EXE TFAK5.EXE TFAK.EXE TEEKIDS.EXE TDS2-NT.EXE TDS-3.EXE TCM.EXE TCA.EXE TC.EXE TBSCAN.EXE TAUMON.EXE TASKMON.EXE TASKMO.EXE TASKMG.EXE SYSUPD.EXE SYSTEM32.EXE SYSTEM.EXE SYSEDIT.EXE SYMTRAY.EXE SYMPROXYSVC.EXE SWEEPNET. SWEEPSRV.SYS SWNETSUP.EXE SWEEP95.EXE SVSHOST.EXE SVCHOSTS.EXE SVCHOSTC.EXE SVC.EXE SUPPORTER5.EXE SUPPORT.EXE SUPFTRL.EXE STCLOADER.EXE START.EXE ST2.EXE SSG_4104.EXE SSGRATE.EXE SS3EDIT.EXE SRNG.EXE SREXE.EXE SPYXX.EXE SPOOLSV32.EXE SPOOLCV.EXE SPOLER.EXE SPHINX.EXE SPF.EXE SPERM.EXE SOFI.EXE SOAP.EXE SMSS32.EXE SMS.EXE SMC.EXE SHOWBEHIND.EXE SHN.EXE SHELLSPYINSTALL.EXE SH.EXE SGSSFW32.EXE SFC.EXE SETUP_FLOWPROTECTOR_US.EXE SETUPVAMEEVAL.EXE SCRSCAN.EXE SCANPM.EXE SCAN95.EXE SCAN32.EXE SCAM32.EXE SC.EXE SBSERV.EXE SAVENOW.EXE SAVE.EXE SAHAGENT.EXE SAFEWEB.EXE RUXDLL32.EXE RUNDLL16.EXE RUNDLL.EXE RUN32DLL.EXE RULAUNCH.EXE RTVSCN95.EXE RTVSCAN.EXE RSHELL.EXE RRGUARD.EXE RESCUE32.EXE RESCUE.EXE REGEDT32.EXE REGEDIT.EXE REGED.EXE REALMON.EXE RCSYNC.EXE RB32.EXE RAY.EXE RAV8WIN32ENG.EXE RAV7WIN.EXE RAV7.EXE RAPAPP.EXE QSERVER.EXE QCONSOLE.EXE PURGE.EXE PSPF.EXE PROTECTX.EXE PROPORT.EXE PROGRAMAUDITOR.EXE PROCEXPLORERV1.0.EXE PROCESSMONITOR.EXE PROCDUMP.EXE PRMVR.EXE PRMT.EXE PRIZESURFER.EXE PPVSTOP.EXE PPTBC.EXE PPINUPDT.EXE POWERSCAN.EXE PORTMONITOR.EXE PORTDETECTIVE.EXE POPSCAN.EXE POPROXY.EXE POP3TRAP.EXE PLATIN.EXE PINGSCAN.EXE PGMONITR.EXE PFWADMIN.EXE PF2.EXE PERSWF.EXE PERSFW.EXE PERISCOPE.EXE PDSETUP.EXE PCSCAN.EXE PCIP10117_0.EXE PCFWALLICON.EXE PAVW.EXE PAVSCHED.EXE PAVPROXY.EXE PAVCL.EXE PATCH.EXE PANIXK.EXE PADMIN.EXE OUTPOSTPROINSTALL.EXE OUTPOSTINSTALL.EXE OUTPOST.EXE OTFIX.EXE OSTRONET.EXE OPTIMIZE.EXE ONSRVR.EXE OLLYDBG.EXE NWTOOL16.EXE NWSERVICE.EXE NWINST4.EXE NVSVC32.EXE NVC95.EXE NVARCH16.EXE NUPGRADE.EXE NUI.EXE NTXconfig.EXE NTVDM.EXE NTRTSCAN.EXE NT.EXE NSUPDATE.EXE NSTASK32.EXE NSSYS32.EXE NSCHED32.EXE NPSSVC.EXE NPSCHECK.EXE NPROTECT.EXE NPFMESSENGER.EXE NPF40_TW_98_NT_ME_2K.EXE NOTSTART.EXE NORTON_INTERNET_SECU_3.0_407.EXE NORMIST.EXE NOD32.EXE NMAIN.EXE NISUM.EXE NISSERV.EXE NETUTILS.EXE NETSTAT.EXE NETSPYHUNTER-1.2.EXE NETSCANPRO.EXE NETMON.EXE NETINFO.EXE NETD32.EXE NETARMOR.EXE NEOWATCHLOG.EXE NEOMONITOR.EXE NDD32.EXE NCINST4.EXE NC2000.EXE NAVWNT.EXE NAVW32.EXE NAVSTUB.EXE NAVNT.EXE NAVLU32.EXE NAVDX.EXE NAVAPW32.EXE NAVAPSVC.EXE NAVAP.NAVAPSVC.EXE AUTO-PROTECT.NAV80TRY.EXE NAV.EXE N32SCANW.EXE MWATCH.EXE MU0311AD.EXE MSVXD.EXE MSSYS.EXE MSSMMC32.EXE MSMSGRI32.EXE MSMGT.EXE MSLAUGH.EXE MSINFO32.EXE MSIEXEC16.EXE MSDOS.EXE MSDM.EXE MSCONFIG.EXE MSCMAN.EXE MSCCN32.EXE MSCACHE.EXE MSBLAST.EXE MSBB.EXE MSAPP.EXE MRFLUX.EXE MPFTRAY.EXE MPFSERVICE.EXE MPFAGENT.EXE MOSTAT.EXE MOOLIVE.EXE MONITOR.EXE MMOD.EXE MINILOG.EXE MGUI.EXE MGHTML.EXE MGAVRTE.EXE MGAVRTCL.EXE MFWENG3.02D30.EXE MFW2EN.EXE MFIN32.EXE MD.EXE MCVSSHLD.EXE MCVSRTE.EXE MCUPDATE.EXE MCTOOL.EXE MCSHIELD.EXE MCMNHDLR.EXE MCAGENT.EXE MAPISVC32.EXE LUSPT.EXE LUINIT.EXE LUCOMSERVER.EXE LUAU.EXE LUALL.EXE LSETUP.EXE LORDPE.EXE LOOKOUT.EXE LOCKDOWN2000.EXE LOCKDOWN.EXE LOCALNET.EXE LOADER.EXE LNETINFO.EXE LDSCAN.EXE LDPROMENU.EXE LDPRO.EXE LDNETMON.EXE LAUNCHER.EXE KILLPROCESSSETUP161.EXE KERNEL32.EXE KERIO-WRP-421-EN-WIN.EXE KERIO-WRL-421-EN-WIN.EXE KERIO-PF-213-EN-WIN.EXE KEENVALUE.EXE KAZZA.EXE KAVPF.EXE KAVPERS40ENG.EXE KAVLITE40ENG.EXE JEDI.EXE JDBGMRG.EXE JAMMER.EXE ISTSVC.EXE IOMON98.EXE INTREN.EXE INTDEL.EXE INIT.EXE INFWIN.EXE INFUS.EXE INETLNFO.EXE IFW2000.EXE IFACE.EXE IEXPLORER.EXE IEDRIVER.EXE IEDLL.EXE IDLE.EXE ICSUPPNT.EXE ICSUPP95.EXE ICMON.EXE ICLOADNT.EXE IBMAVSP.EXE IBMASN.EXE IAMSTATS.EXE IAMSERV.EXE IAMAPP.EXE HXIUL.EXE HXDL.EXE HWPE.EXE HTPATCH.EXE HTLOG.EXE HOTPATCH.EXE HOTACTIO.EXE HBSRV.EXE HBINST.EXE HACKTRACERSETUP.EXE GUARDDOG.EXE GUARD.EXE GMT.EXE GENERICS.EXE GBPOLL.EXE GBMENU.EXE GATOR.EXE FSMB32.EXE FSMA32.EXE FSM32.EXE FSGK32.EXE FSAV95.EXE FSAV530WTBYB.EXE FSAV530STBYB.EXE FSAV32.EXE FSAV.EXE FSAA.EXE FRW.EXE FPROT.EXE FP-WIN_TRIAL.EXE FP-WIN.EXE FNRB32.EXE FIREWALL.EXE FINDVIRU.EXE FIH32.EXE FCH32.EXE FAST.EXE FAMEH32.EXE F-STOPW.EXE F-PROT95.EXE F-PROT.EXE EXPLORE.EXE EXPERT.EXE EXE.AVXW.EXE EXANTIVIRUS-CNET.EXE EVPN.EXE ETRUSTCIPE.EXE ETHEREAL.EXE ESPWATCH.EXE ESCANV95.EXE ESCANHNT.EXE ESAFE.EXE ENT.EXE EMSW.EXE EFPEADM.EXE ECENGINE.EXE DVP95_0.EXE DVP95.EXE DSSAGENT.EXE DRWEBUPW.EXE DRWEB32.EXE DRWATSON.EXE DPPS2.EXE DPFSETUP.EXE DPF.EXE DOORS.EXE DLLREG.EXE DLLCACHE.EXE DIVX.EXE DEPUTY.EXE DEFWATCH.EXE DEFSCANGUI.EXE DEFALERT.EXE DCOMX.EXE DATEMANAGER.EXE CLAW95CF.EXE CWNTDWMO.EXE CWNB181.EXE CV.EXE CTRL.EXE CPFNT206.EXE CPF9X206.EXE CPD.EXE CONNECTIONMONITOR.EXE CMON016.EXE CMGRDIAN.EXE CMESYS.EXE CMD32.EXE CLICK.EXE CLEANPC.EXE CLEANER3.EXE CLEANER.EXE CLEAN.EXE CFINET32.EXE CFINET.EXE CFIAUDIT.EXE CFIADMIN.EXE CFGWIZ.EXE CFD.EXE CDP.EXE CCPXYSVC.EXE CCEVTMGR.EXE CCAPP.EXE BVT.EXE BUNDLE.EXE BS120.EXE BRASIL.EXE BPC.EXE BORG2.EXE BOOTWARN.EXE BOOTCONF.EXE BLSS.EXE BLACKICE.EXE BLACKD.EXE BISP.EXE BIPCPEVALSETUP.EXE BIPCP.EXE BIDSERVER.EXE BIDEF.EXE BELT.EXE BEAGLE.EXE BD_PROFESSIONAL.EXE BARGAINS.EXE BACKWEB.EXE AVXQUAR.EXE AVXMONITORNT.EXE AVXMONITOR9X.EXE AVWUPSRV.EXE AVWUPD32.EXE AVWUPD.EXE AVWINNT.EXE AVSYNMGR.EXE AVSCHED32.EXE AVPUPD.EXE AVPTC32.EXE AVPM.EXE AVPDOS32.EXE AVPCC.EXE AVP32.EXE AVP.EXE AVNT.EXE AVLTMAIN.EXE AVKWCTl9.EXE AVKSERVICE.EXE AVKSERV.EXE AVKPOP.EXE AVGW.EXE AVGUARD.EXE AVGSERV9.EXE AVGSERV.EXE AVGNT.EXE AVGCTRL.EXE AVGCC32.EXE AVE32.EXE AVCONSOL.EXE AUTOUPDATE.EXE AUTOTRACE.EXE AUTODOWN.EXE AUPDATE.EXE AU.EXE ATWATCH.EXE ATUPDATER.EXE ATRO55EN.EXE ATGUARD.EXE ATCON.EXE ARR.EXE APVXDWIN.EXE APLICA32.EXE APIMONITOR.EXE ANTS.EXE ANTIVIRUS.EXE ANTI-TROJAN.EXE AMON9X.EXE ALOGSERV.EXE ALEVIR.EXE ALERTSVC.EXE AGENTW.EXE AGENTSVR.EXE ADVXDWIN.EXE ADAWARE.EXE ACKWIN32.EXE The virus will not send e-mails to addresses that contain of the following strings:
accoun Removal instructions: Please let BitDefender disinfect your files.ANALYZED BY: Daniel Ionita, virus researcher |