wipe-deletion-erasure-purge


I-Worm.Mydoom.l

I-Worm.Mydoom.l

CyberScrub AntiVirus
Research Bank

This worm spreads via the Internet as an attachment to infected messages, via file sharing networks and open network resources. The worm sends itself to email addresses harvested from infected machines. The worm also contains a backdoor function.

The worm itself is a Windows PE EXE file approximately 21 KB in size.

Installation

During installation the worm copies itself as "lsass.exe" to the Windows root directory, for example:

C:\WINDOWS\lsass.exe

The worm then registers this file in the system registry as a key to enable autorun:

[HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run]
Traybar = %WinDir% \LSASS.EXE

This ensures that the worm will be launched each time the system is rebooted.

The worm searches the computer for folders where the name contains the following words:

download
ftproot
incoming
Share

and copies itself several times to each folder found, under the following names:

Harry Potter
ICQ 4 Lite
index
Kazaa Lite
Winamp 5.0 (en)
Winamp 5.0 (en) Crack
WinRAR.v.3.2.and.key

The files will have one of the following extensions:

com
exe
scr
ShareReactor.com
Propagation

In order to find email addresses to send infected messages to, Mydoom.l searches for files with the following extensions:

doc
htm
html
txt

and harvests email addresses found in these files. The worm uses the recipient's SMTP server to send email messages to all of the harvested addresses.

Infected messages Sender's address

The sender's address is spoofed, using one of the email addresses harvested from the system.

Subject (chosen at random from the following list):
click me baby, one more time
delivery failed
Delivery reports about your e-mail
error
hello
hi
Mail System Error - Returned Mail
Message could not be delivered
report
Returned mail: Data format error
Returned mail: see transcript for details
say helo to my litl friend
status
test
Message body (chosen at random from the following list):
  • The original message was included as attachment
  • This Message was undeliverable due to the following reason:
    Your message was not delivered because the destination computer was
    not reachable within the allowed queue period. The amount of time
    a message is queued before it is returned depends on local configuration parameters.
    Most likely there is a network problem that prevented delivery, but
    it is also possible that the computer is turned off, or does not
    have a mail system running right now.
  • Your message was not delivered within [ ] days:
    Host $i is not responding.
  • The following recipients did not receive this message:
    <[ ]>
    Please reply to postmaster@[ ]
    if you feel this message to be in error.
  • The original message was received at [ ]
    from [ ]
    ----- The following addresses had permanent fatal errors -----
    <[ ]>
    ----- Transcript of session follows -----
    while talking to [ ].:
    >>> MAIL From:[ ]
    <<< 501 [ ]... Refused
  • The original message was received at $w
    from [ ]
    ----- The following addresses had permanent fatal errors -----
    <[ ]>
Attachment name (chosen at random from the list below):
<blank>
attachment
document
file
letter
mail
message
readme
text
transcript

with one of the following extensions:

bat
cmd
com
exe
pif
scr
zip
Remote Administration

The backdoor in Mydoom.l opens and then monitors TCP port 1042 in order to receive remote commands.

Check out if we have free removal tool for this virus


CyberScrub AntiVirus provides state of the art security protection for five years- at one low price. Our award winning technology ensures protection against viruses, worms and trojans backed by top customer support and value.

 
Five Year Cost Comparison
Product Initial Cost Yearly Subscription X Four Years Total
Norton 2004 AntiVirus $49.95* $29.95 $119.80 $169.75
McAfee VirusScan $49.95* $19.95 $79.80 $129.75
CyberScrub AntiVirus $49.95 Included No Additional Cost $49.95
*All prices MSRP as published on respective sites.




It is only a matter of time before a virus, worm or Trojan horse wrecks havoc on your important data. Important files, records, family pictures- all at risk. Some dangerous programs can even ruin your hard drive beyond repair.

CyberScrub AntiVirus offers the most effective protection from all known and unknown viruses.

CyberScrub AntiVirus is powered by a unique integrated technology for virus detection, based on principles of multi-generation heuristic analysis. This allows the program to protect you from suspect “viral behavior”. This highly effective methodology repelled all attacks of each “I LOVEYOU’ viral variation without any additional antivirus database updates. No other technology, including Norton, Trend, or McAfee was able to accomplish this.

CyberScrub AntiVirus is powerful, yet its exceptional ease of use and installation make it acceptable for beginner to pro



CyberScrub Antivirus constantly scans your hard drive and files to identify, clean and destroy infected objects. With updates available every three hours, 24 hours a day, 365 days a year, you can count on CyberScrub to protect your valued data.

CyberScrub AntiVirus
Lifetime Edition

"For the Life of Your Computer"

Save $10 Now!
Limited Time

 


I-Worm.Mydoom.l


Symantec Warns Of Flaw In Antivirus Program. More>>

CNN Legend Lynne Russell reports on CyberScrub AntiVirus for Tech Headline News.


















 
 

delete,deletion, file deletion, Internet clean up,privacy, HIPAA, Internet privacy, cookies, erase, erasure, shredder, wipe, overwrite, purge, deletion, security, file wipe, data destruction