Win32.Mydoom.Z@mm

Propagación : alto
Daño : medio
Tamaño: 69632 bytes, packed
Detectado : 2005 May 31

SINTOMAS:

Presence of the file file %WINDIR%\\services.exe.

Presence of registry keys:
HKEY_LOCAL_MACHINE\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\RPCserv
HKEY_LOCAL_MACHINE\\SYSTEM\\ControlSet\\Services\\NetBios Ext\\ImagePath = %WINDIR%\\services.exe.

DESCRIPCIÓN TÉCNICA:

This looks like a recompile with minor modifications of the Win32.Mydoom.Y@mm worm, with the same
names for files, the same urls for downloading the backdoor and the same e-mails.
Please read its description for more information.

INSTRUCCIONES DE LIMPIEZA:

Automatic removal: let BitDefender disinfect infected files.

ANALIZADO POR:

Alexandru Carp,
BitDefender Virus Researcher