PC Security Shield Virus Alert:
I-Worm.Win32.Mydoom.18200
Also Known As
Type
I-worm
Systems Affected
Win32
Resident in System Memory
No
Origin
others
Encryption
No
Discovered on
09/09/2007
How it spread
Email
Infection symptoms
Analyzing
Specific date of infections
None
Destructivity/ Distribution Potential
** / ***
ViRobot version able to
detect/repair
Able to detect/repair
[ViRobot version: 09/9/2007
Technical Description
Summary
This worm spreads via email and was found on Sep.9, 2007. Hauri Mail server has
received the tens of mails sent by worm and the
variant of this worm is spreadig.
Upon infection, worm downlowds and executes several URL defined inside worm, and creates winspf32.exe(18,200bytes) in thw Wondow
system folder. Worm retrieves email addresses from infected system and mass-mailing.
Infection method
Worm spreads itself with its own SMTP engine, the spreading object is searched and retrieved from the files that have the following
extentions in the infected system.