New HIGH threat e-mail virus!!!

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
Carries the attachement "dscgnoxolw.exe"
which is:
"W32.Beagle.A@mm"
 
Last edited:

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
Virus Name
Risk Assessment
W32/Mydoom@MM
Corporate User
:
High-Outbreak
Home User
:
High-Outbreak

Virus Information
Discovery Date:
01/26/2004
Origin:
Unknown
Length:
22,528 bytes
Type:
Virus
SubType:
E-mail
Minimum DAT:
Release Date:
4319
01/26/2004
Minimum Engine:
4.2.40
Description Added:
01/26/2004
Description Modified:
01/26/2004 2:44 PM (PT)

Description Menu
Virus Characteristics
Symptoms
Method Of Infection
Removal Instructions
Variants / Aliases
Rate This page
Print This Page
Email This Page
Legend


Virus Characteristics:
This is a mass-mailing worm that arrives in an email message as follows:

From: (spoofed)
Subject: (Random)
Body: (Varies, such as)

The message cannot be represented in 7-bit ASCII encoding and has been
sent as a binary attachment.
The message contains Unicode characters and has been sent as a binary
attachment.
Mail transaction failed. Partial message is available.

Attachment: (varies [.exe, .pif, .cmd, .scr] - often arrives in a ZIP archive) (22,528
bytes)

The icon used by the file tries to make it appear as if the attachment is a text file


When this file is run it copies itself to the local system with the following filenames:

c:\Program Files\KaZaA\My Shared Folder\activation_crack.scr
%SysDir%\taskmon.exe

(Where %Sysdir% is the Windows System directory, for example C:\WINDOWS\SYSTEM)

It also uses a DLL that it creates in the Windows System directory:

It also uses a DLL that it creates in the Windows System directory:

%SysDir%\shimgapi.dll (4,096 bytes)

It creates the following registry entry to hook Windows startup:

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\
CurrentVersion\Run "TaskMon" = %SysDir%\taskmon.exe

The worm opens a connection on TCP port 3127 suggesting remote access
capabilities.

AVERT is currently analyzing this the threat. Details will be posted, as they are
available.

Top of Page

Symptoms
Upon executing the virus, Notepad is opened, filled with nonsense characters.
Existence of the files and registry entry listed above

Top of Page

Method Of Infection
This file tries to spread via email and by copying itself to the shared directory for
Kazaa clients if they are present.

The mailing component harvests address from the local system. Files with the
following extensions are targeted:

wab
adb
tbb
dbx
asp
php
sht
htm
txt

Additionally, the worm contains strings, which it uses to randomly generate, or
guess, addresses.

Top of Page

Removal Instructions
The following EXTRA.DAT packages are available.

EXTRA.DAT
SUPER EXTRA.DAT

Top of Page

Variants
Name
Type
Sub Type
Differences

Top of Page

Aliases
Name
Novarg (F-Secure)
W32.Novarg.A@mm (Symantec)
Win32/Shimg (CA)
WORM_MIMAIL.R (Trend)
 

MadJack

Administrator
Staff member
Forum Admin
Super Moderators
Channel Owner
Jul 13, 1999
105,812
2,101
113
70
home
i'm getting a ton of these things sent to me now. 45 in the last 40 minutes and picking up steam.
 

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
Install a firewall ( free from Lavasoft.com) and update your virus protection right away.
 

MadJack

Administrator
Staff member
Forum Admin
Super Moderators
Channel Owner
Jul 13, 1999
105,812
2,101
113
70
home
KMA, i'm away for 2 weeks and using my laptop without virus protection and no firewall. i don't open the attachments so not really worried about it. should i be?

i ran the removal tool 2x's and it said i didn't have the virus.
 

KMA

Registered User
Forum Member
May 25, 2003
745
2
0
You should have some protection even on the laptop. You could, at any time get an e-mail, even from a friend with no attachments at all. These viruses carry attachments that are not always detected, they can also at times hide them and they will not only crash pc's and laptops, but they also are able to damage the hard drive. They can get through if you aren't updated. The firewall is free, no harm in installing it!!!
 
Bet on MyBookie
Top