VIRUS WARNING !
- FcUK_J
- Topic Author
- Offline
- FcUK Co Founder
Less
More
- Posts: 710
- Thank you received: 0
20 years 9 months ago #2953
by FcUK_J
VIRUS WARNING ! was created by FcUK_J
Brief Description
Mydoom.A is a worm that spreads via e-mail in a message with
variable characteristics and through the peer-to-peer (P2P )
file sharing program KaZaA.
Mydoom.A launches DDoS (Distributed Denial of Service) attacks
against the website <!-- w --> www.sco.com <!-- w --> if the system date is between
February 1 and February 12, 2004. It does this by launching
GET/ HTTP/ 1.1 requests every 1,024 milliseconds. On February
12, 2004, the worm finishes its payload, ending its execution
whenever it is activated.
Mydoom.A drops the DLL (Dynamic Link Library) SHIMGAPI.DLL,
which creates a backdoor, opening the first available TCP port
in the range from 3127 to 3198. This backdoor component allows
to download and run an executable file, and acts as a TCP proxy
server, allowing a hacker to gain remote access to network
resources.
Visible Symptoms
Mydoom.A is easy to recognize once it has affected the
computer, as it opens the Windows Notepad and shows junk data.
For more information and ways to Prevent and Cure your infected
computer please visit:
http://www.virusportal.com/com/
Good luck and be very careful when dealing with email from
unknown sources.
_J
Mydoom.A is a worm that spreads via e-mail in a message with
variable characteristics and through the peer-to-peer (P2P )
file sharing program KaZaA.
Mydoom.A launches DDoS (Distributed Denial of Service) attacks
against the website <!-- w --> www.sco.com <!-- w --> if the system date is between
February 1 and February 12, 2004. It does this by launching
GET/ HTTP/ 1.1 requests every 1,024 milliseconds. On February
12, 2004, the worm finishes its payload, ending its execution
whenever it is activated.
Mydoom.A drops the DLL (Dynamic Link Library) SHIMGAPI.DLL,
which creates a backdoor, opening the first available TCP port
in the range from 3127 to 3198. This backdoor component allows
to download and run an executable file, and acts as a TCP proxy
server, allowing a hacker to gain remote access to network
resources.
Visible Symptoms
Mydoom.A is easy to recognize once it has affected the
computer, as it opens the Windows Notepad and shows junk data.
For more information and ways to Prevent and Cure your infected
computer please visit:
http://www.virusportal.com/com/
Good luck and be very careful when dealing with email from
unknown sources.
_J
Please Log in or Create an account to join the conversation.
- fireblade
- Offline
- Full Member
Less
More
- Posts: 205
- Thank you received: 0
20 years 9 months ago #2954
by fireblade
Replied by fireblade on topic VIRUS WARNING !
IT WOULD BE CALLED MYDOOM A WUNNIT <!-- s:lol: --><img src="{SMILIES_PATH}/icon_lol.gif" alt="" title="Laughing" /><!-- s:lol: --> <!-- s:lol: --><img src="{SMILIES_PATH}/icon_lol.gif" alt="" title="Laughing" /><!-- s:lol: -->
Please Log in or Create an account to join the conversation.
Time to create page: 0.037 seconds