Email-Worm.Win32.Mydoom.m

 

 

 

Email-Worm.Win32.Mydoom.m

Aliases

Email-Worm.Win32.Mydoom.m (Kaspersky Lab) is also known as:

Kaspersky Lab North America Free Trials

 

Technical details

I-Worm.Mydoom.m spreads via the Internet as an attachment to infected messages.

The worm itself is a Windows PE EXE file approximately 27KB in size, packed using UPX. The unpacked file is approximately 50KB in size.

The worm is only activated when a user opens the archive and launches the infected file by double-clicking on it. The worm will then install itself on the system and begin propagating.

The worm contains a backdoor function.

Part of the body of the worm is encrypted.

Trend Micro

Installation

When installing, the worm copies itself as ‘java.exe’ to the Windows root directory, and registers this file in the system registry. This ensures the worm will be launched each time the infected system is booted.

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
  JavaVM = %windir%\java.exe

This ensures the worm will be launched each time the infected system is booted.

The worm also creates a file named ’services.exe.’, which is 8192 bytes in size, in the Windows root directory. This file is an additional component, and is also added to the system registry:

[HKLM\Software\Microsoft\Windows\CurrentVersion\Run]
[HKCU\Software\Microsoft\Windows\CurrentVersion\Run]
  Services = %windir%\services.exe

Symantec's Norton AntiVirus 2009

Symantec - 10% off Store Coupon

10% off Store Coupon Offer Expires 01/12/09

Coupon Code: 10offsid

 

Mailing messages

The worm searches the victim machine for email addresses to harvest, and then sends itself to these addresses by directly connecting to the recipient’s SMTP server.

It also harvests addresses by using the following search engines:

Google
Lycos
Altavista
Yahoo

 

  Panda Antivirus Pro 2009

Infected messages

Sender’s address: (either chosen from the list below or spoofed):
MAILER-DAEMON
Mail Administrator
Automatic Email Delivery Software
Post Office
The Post Office
Bounced mail
Returned mail
Mail Delivery Subsystem
Message header (chosen at random from the list below):
Message could not be delivered
hello
Hi
error
status
test
report
delivery failed
Message could not be delivered
Mail System Error - Returned Mail
Delivery reports about your e-mail
Returned mail: see transcript for details
Returned mail: Data format error
{{The|Your} m|M}essage could not be delivered
instruction
Message body (chosen at random from the list below)

The message body will be altered to correspond to the user’s details.

Dear user {$t|of $T},{ {{M|m}ail {system|server} administrator|administration} of $T would like to {inform you{ that{:|,}|}|let you know {that|the following}{.|:|,}}|||||}

{We have {detected|found|received reports} that y|Y}our {e{-|}mail |}account {has been|was} used to send a {large|huge} amount of {{unsolicited{ commercial|}|junk} e{-|}mail|spam}{ messages|} during { this|the {last|recent}} week.

{We suspect that|Probably,|Most likely|Obviously,} your computer {had been|was} {compromised|infected{ by a recent v{iru}s|}} and now {run|contain}s a {trojan{ed|}|hidden} proxy server.

{Please|We recommend {that you|you to}} follow {our |the |}instruction{s|} {in the {attachment|attached {text |}file} |}in order to keep your computer safe.

{{Virtually|Sincerely} yours|Best {wishe|regard}s|Have a nice day}, {$T {user |technical |}support team.|The $T {support |}team.}

{The|This|Your} message was{ undeliverable| not delivered} due to the following reason{(s)|}:

Your message {was not|could not be} delivered because the destination {computer|server} was {not |un}reachable within the allowed queue period. The amount of time a message is queued before it is returned depends on local configuration parameters.

Most likely there is a network problem that prevented delivery, but it is also possible that the computer is turned off, or does not have a mail system running right now.

Your message {was not|could not be} delivered within $D days: {{{Mail s|S}erver}|Host} $i is not responding.

The following recipients {did|could} not receive this message: <$t>

Please reply to postmaster@{$F|$T} if you feel this message to be in error. The original message was received at $w{ | }from {$F [$i]|{$i|[$i]}}

—– The following addresses had permanent fatal errors —– {<$t>|$t}

{—– Transcript of {the ||}session follows —– … while talking to {host |{mail |}server ||||}{$T.|$i}: {>>> MAIL F{rom|ROM}:$f <<< 50$d {$f… |}{Refused|{Access d|D}enied|{User|Domain|Address} {unknown|blacklisted}}|554 <$t>..

. {Mail quota exceeded|Message is too large} 554 <$t>… Service unavailable|550 5.1.2 <$t>… Host unknown (Name server: host not found)|554 {5. 0.0 |}Service unavailable; [$i] blocked using {relays.osirusoft.com|bl.spamcop.net}{, reason: Blocked|} Session aborted{, reason: lost connection|}|>>> RCPT To:<$t> <<< 550 {MAILBOX NOT FOUND|5.1.1 <$t>… {User unknown|Invalid recipient|Not known here}}|>>> DATA {<<< 400-aturner; %MAIL-E-OPENOUT, error opening !AS as output|}{<<< 400-aturner; -RMS-E-CRE, ACP file create failed|}{<<< 400-aturner; -SYSTEM-F-EXDISKQUOTA, disk quota exceeded|}<<< 400}|} The original message was included as attachment {{The|Your} m|M}essage could not be delivered

Attachment name:

The attachment name is generated at random.

Attachment extension (chosen at random from the list below):
cmd
bat
com
pif
scr
doc
exe

The worm may also be sent in the form of a ZIP archive.

Other

The worm opens TCP port 1034 in order to receive remote commands.

 

 

 

dogione.blogspot.com

Panda Antivirus Pro 2009

Panda Antivirus Pro 2009

Panda Antivirus Pro 2009 is easy to install and set up and there are fewer options to confuse the user. The software has a clean, consistent appearance throughout the different screens that looks great and makes sense.

Panda Antivirus Pro 2009 has fewer options than many antivirus programs to help keep confusion at a minimum. The program also scans for antispyware to help better protect your machine and identity.

System performance does not suffer too much and the scanning time is similar to other antivirus software programs.

Panda Antivirus Pro 2009 has an automatic update function, but a full service scheduler would allow the user to define how often and when scans would occur.

An online database features answers to frequently asked questions. This is a good place to start if you have a question about the product.

 

tursun.blogsome.com

Panda Global Protection 2009

 

Panda Global Protection 2009

 

Enjoy total security and ensure information integrity.

Enjoy optimum security and safeguard your valuable data with Panda Global Protection 2009. It protects you from viruses, spyware, rootkits, hackers, online fraud, identity theft and all other Internet threats. The anti-spam engine will keep your inbox free from junk mail while the Parental Control feature ensures your children can use the Web safely. You can also back up important files (documents, music, photos, etc.) to a CD/DVD or online and restore them in case of accidental loss or damage.

 

 

Anti-Malware Protection
Anti-Malware Engine

Automatically detects and eliminates viruses, spyware, Trojans, rootkits, bots and other malware before they infect your computer.

  • Scans files in real-time and on-demand.
  • Scans emails before they reach your inbox, regardless of your email program.
  • Scans Internet traffic regardless of your browser type.
  • Scans Instant Messaging traffic in MSN Messenger, Windows Live Messenger, Yahoo Messenger and AOL.
  • Removes all traces of clutter left by spyware on your PC.
Advanced Proactive Protection

Technologies from Panda Security are widely recognized as the most effective against new and unknown malware.

  • Genetic Heuristic Engine combines advanced algorithms to detect new variants of the most dangerous malware families.
  • TruPrevent Technologies 2.0 silently analyze the behavior of programs, blocking those that try to damage your PC. This last line of defence blocks zero-day targeted attacks and terminates any malicious activity that has evaded traditional protection systems.
Personal Firewall

Protects you against Internet-borne worms and hacker attacks.

  • Smart auto-configuration allows good programs to run while blocking malicious ones.
  • Shields your PC from hackers on the Web.
  • Wireless Monitor protects your wireless network from intruders.
  • Intrusion prevention blocks known and unknown hacker attacks and vulnerability exploits.
Identity Theft Protection
Anti-Phishing Filter

Recognizes fraudulent email and protects you from scams while you shop, bank or pay bills online.

 

Anti-Banking Trojan Engine

Detects the most dangerous identity theft malware used by cyber-criminals to steal banking credentials. Specialized heuristics and generic detection techniques ensure maximum protection for online transactions.

 

Anti-Rootkit Technology

Detects and removes silently-installed rootkits used by malware or hackers to evade traditional antivirus products. The free Panda Anti-Rootkit, used by millions of people around the world, recently won the Editor’s Choice award from PC Magazine.

 

Safe Internet Browsing
Anti-Spam Filter

Keeps your inbox free from junk mail. With the new spam engine detection rates are now over 97%, ensuring uninterrupted service and delivering the emails you really need.

Parental Control

Lets your children browse the Internet safely by blocking access to violent, adult, or racist content, as well as other inappropriate websites. From the solution’s control panel –and regardless of the browser type- you can assign predefined filters (child, adolescent, employee…) to users or customize filter rules according to your specific needs

 

Web Filter

Lets you use the Internet safely without the risk of infections, vulnerability exploits, browser hijacking or phishing websites.By analyzing website content, links and Web reputation scores, Panda Security provides protection against all types of Web-based malware and scams.

Personal Information Filter

Prevents theft from your PC of credit card numbers, social security numbers and any other personal information you define.

 

PC Optimization
Backup & Restore

Safeguards your most important files against accidental loss or damage. It prevents loss of important documents either unintentionally, or through hard disk problems or other accidents. Backup and restoration from hard drive, CD, DVD, other external media or online are both extremely simple and easy.

 

Premium Online Backup

To safeguard your most important files and have access to them anytime, anywhere. Backing up your most important files online ensures the integrity of your information regardless of what happens to your PC. This ultimate safety layer provides 2 gigabytes of free, secure storage for one year. 

Tune Up

Automatically finds and fixes problems in your PC and keeps your system running smoothly. It optimizes your PC performance by removing unnecessary registry entries, deleting temporary files and speeding up your hard disk.

 

 

Panda Security 2009

 

culfulas.blogspot.com