W32.Mydoom.M@mm - Virus - Alert category 4

Devilfrank

Sehr aktiv
The W32.Mydoom.M@mm mass-mailing worm:

Uses its own SMTP engine to send itself to all the email addresses that it finds from an infected system.
The email has an attachment with a .bat, .cmd, .com, .exe, .pif, .scr, or .zip extension.
The attachment name may contain a randomly selected domain, which was found on the sender's system. For example, the attachment name could contain fakedomain.com if the address [email protected] was harvested.
The From field of the email is spoofed.
Downloads and executes a backdoor, detected as Backdoor.Zincite.A, on port 1034/tcp.
Is packed by UPX.


Also Known As: W32/Mydoom.o@MM [McAfee], W32/MyDoom-O [Sophos], WORM_MYDOOM.M [Trend], Win32.Mydoom.O [Computer Associates]

Type: Worm
Infection Length: varies



Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP
Systems Not Affected: DOS, Linux, Macintosh, Novell Netware, OS/2, UNIX

http://www.symantec.com/avcenter/venc/data/[email protected]
 
Devilfrank schrieb:
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP

Monokulturen waren auch schon in der Landwirtschaft immer schädlich. ;) Die not affected systems spielen leider keine wirkliche Rolle auf den Desktops. Obwohl Apple es fast verdient hätte.
 
Zurück
Oben