Remove W32.Mydoom. Removal instructions
Severity scale: (60 / 100)
W32.Mydoom is a mass-mailing worm, sending messages with the following
subjects: Status, test, Test, TEST, hello, HELLO, Server Report, hi, HI, Error.
The email contains an attachment named: message.exe, body.zip, ogp.zip, document.zip, text.zip, message.zip, ymplf.zip, readme.zip, file.zip, body.zip, text.pif, document.pif, doc.pif, data.zip, doc.zip, raun.zip, etwblf.zip, etc.
When a computer is infected, the worm sets up a backdoor into the system by opening TCP ports 3127 through 3198, which can potentially allow an attacker to connect to the computer and use it as a proxy to gain access to its network resources.
W32.Mydoom properties: • Allows remote user connection • Hides from the user • Stays resident in background
Automatic W32.Mydoom removal:
We are testing STOPzilla's efficiency at removing W32.Mydoom
(2004-04-09 07:54:40)
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing W32.Mydoom
(2004-04-09 07:54:40)
We are testing Spyware Doctor's efficiency at removing W32.Mydoom
(2004-04-09 07:54:40)
W32.Mydoom manual removal:
Delete registry values:Browse to the key: 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Delete the value 'TaskMon'
Browse to the key: 'HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run'
Delete the value 'TaskMon'
Delete files:shimgapi.dll, askmon.exe
Information added: 2004-03-19 10:00:00
Information updated: 2004-04-09 05:17:25
Additional resources related to W32.Mydoom:
Attention: If you
know or you have a website or page about W32.Mydoom removal, feel free
to add a link to this list: add
url
more resources
|
Latest spyware news:
Subscribe to news
Similar parasites:
|
Post Comment: