Home Malware Programs Worms W32.Mydoom

W32.Mydoom

Posted: March 28, 2006

Threat Metric

Ranking: 10,862
Threat Level: 9/10
Infected PCs: 2,101
First Seen: July 24, 2009
Last Seen: October 13, 2023
OS(es) Affected: Windows

W32.Mydoom is a mass-mailing and peer-to-peer file-sharing worm. W32.Mydoom worm spreads by sending email messages to addresses found on the local system, as well as addresses constructed by the virus. Usually there is no attachment to the message; it contains only a hyperlink. The homepage or link hyperlink points to the infected system which sent the email message and by clicking on the link the worm is automatically installed onto the system. W32.Mydoom usually sends messages with the following subjects:
Status,
test,
Test,
TEST,
hello,
HELLO,
Server Report,
hi,
HI,
Error.

W32.Mydoom

Aliases

W32/Mydoom.M!dam [Fortinet]Worm.Win32.Mydoom [Ikarus]Worm:Win32/Mydoom.O@mm [Microsoft]Trojan/win32.agent [Antiy-AVL]TR/Agent.JH.17 [AntiVir]Win32.HLLM.MyDoom.54464 [DrWeb]UnclassifiedMalware [Comodo]Worm.Generic.24461 [BitDefender]Email-Worm.Win32.Mydoom.m [Kaspersky]Worm.Mydoom-25 [ClamAV]W32/Mydoom.o@MM!zip [McAfee]Win32.HLLM.MyDoom.Log [DrWeb]Email-Worm.Win32.Mydoom.m.log [Kaspersky]Generic Trojan [Panda]Generic14.AVJ [AVG]
More aliases (81)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



svhost.exe File name: svhost.exe
Size: 38.4 KB (38400 bytes)
MD5: ac193d0ce40eeaa99a2130689435ce0f
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
windres.exe File name: windres.exe
Size: 46.08 KB (46080 bytes)
MD5: ee1df61226033d18d0ed64820b41fe15
Detection count: 64
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
trayicons.exe File name: trayicons.exe
Size: 12.54 KB (12545 bytes)
MD5: 00921cc0537807a4352d5fcd01aee633
Detection count: 32
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
taskmon.exe File name: taskmon.exe
Size: 50.68 KB (50688 bytes)
MD5: 977ecf802eafab1c9139988dd6797ec0
Detection count: 31
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 11, 2009
services.exe File name: services.exe
Size: 8.19 KB (8192 bytes)
MD5: b0fe74719b1b647e2056641931907f4a
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 17, 2020
win29121.dll, win54856.dll File name: win29121.dll, win54856.dll
Size: 1.38 MB (1388032 bytes)
MD5: b17c4ee26a76ee2e755fd6f40241d1d1
Detection count: 15
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
mffbu.dll File name: mffbu.dll
Size: 22.09 KB (22098 bytes)
MD5: a0cfcf9f65d12affe86294461638af43
Detection count: 10
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
ALOTOFFILES File name: ALOTOFFILES
Size: 32.25 KB (32256 bytes)
MD5: 47cc271e765e6cdf0562e692ce805b35
Detection count: 9
Group: Malware file
Last Updated: January 10, 2022
ctfmon.dll File name: ctfmon.dll
Size: 6.14 KB (6144 bytes)
MD5: 1a6b3aef25226861245adc1a93ce161c
Detection count: 3
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009
yornxytw.dll File name: yornxytw.dll
Size: 10.91 KB (10912 bytes)
MD5: 9f2fa2d26c952714adbd9ff0536f6b61
Detection count: 0
File type: Dynamic link library
Mime Type: unknown/dll
Group: Malware file
Last Updated: December 11, 2009

Registry Modifications

The following newly produced Registry Values are:

File name without pathhelper.dllRun keyssvhostsvhost.exe

Additional Information

The following directories were created:
%WINDIR%\win32dc
Loading...