| Name : | MyDoom.X |
| Category: | Malware |
| Type: | Email-Worm |
| Platform: | Win32 |
Automatic Disinfection
Allow F-Secure Anti-Virus to disinfect the relevant files.
For more general information on disinfection, please see Removal Instructions.
Eliminating a Local Network Outbreak
If the infection is in a local network, please follow the instructions on this webpage:
The worm is a PE executable file 18432 bytes long packed with UPX file compressor. The unpacked file's size is over 44 kilobytes.
Installation to system
When run, the worm creates a mutex 'LLLf54fxrDLLL', copies itself as WIN32S.EXE to Windows System Directory and creates a startup key for that file in System Registry:
where "%WinSysDir%" represents Windows System directory.
Additionally, the worm copies itself to the 'Start Menu\Programs\Startup\' folder of a current user as AUTORUN.EXE file.
Spreading in e-mails
The worm spreads by sending its infected attachment to all e-mail addresses found on an infected computer. The worm looks for e-mail addresses in Windows Address Book (WAB) and in the files with the following extensions:
The worm avoids sending e-mails to e-mail addresses that contain any of the following substrings:
The subject of infected e-mails is selected from the following variants:
The body text of infected e-mails is selected from the following variants:
-----Original Message----- From: Jeny K. Sent: Tuesday, September 7, 2004 8:57 PM To: Morpheus check my new photos :)) miss you, jeny k
-----Original Message----- From: Jena K. Sent: Tuesday, September 7, 2004 5:23 AM To: friends Check Out Archive.. So.. What Do You Think... Am I Hot? :) Waining For Your Answer Jena Key
-----Original Message----- From: jenny k. Sent: Tuesday, September 7, 2004 10:23 AM To: My Tiger (e-mail) new fotos(archived) you asked jenny k
-----Original Message----- From: jenna k. (e-mail) Sent: Tuesday, September 7, 2004 11:38 AM To: Cat my new fotos archived )) kiss, jenna k
-----Original Message----- From: Jeny Sent: Tuesday, September 7, 2004 8:57 PM To: Neo see the photos in attached archive :)) kiss you, jeny
-----Original Message----- From: Jena Sent: Tuesday, September 7, 2004 5:23 AM To: friend Photos in archive.. So.. Am I Hot? :) Waining For Your Answer Jena
-----Original Message----- From: Jenna Knukles Sent: Tuesday, September 7, 2004 9:05 AM To: Friends Group in self-extracting archive my photos Jenna :)
-----Original Message----- From: jenna (e-mail) Sent: Tuesday, September 7, 2004 11:38 AM To: ma kittie my photos archived )) kiss, jenna
-----Original Message----- From: Jeny K. Sent: Tuesday, September 7, 2004 8:57 PM To: Morpheus check out the new photos :)) miss you, jeny k
-----Original Message----- From: Jena K. Sent: Tuesday, September 7, 2004 5:23 AM To: friends So.. What Do You Think... Am I Hot? :) Waining For Your Answer Jena Key
-----Original Message----- From: Jenna Knukles Sent: Tuesday, September 7, 2004 9:05 AM in archive my new fotos Jenna K :)
-----Original Message----- From: jenny k. Sent: Tuesday, September 7, 2004 10:23 AM To: My Tiger (e-mail) new fotos you asked jenny k
-----Original Message----- From: jenna k. (e-mail) Sent: Tuesday, September 7, 2004 11:38 AM To: Cat my new fotos zipped )) kiss, jenna k
-----Original Message----- From: Jeny Sent: Tuesday, September 7, 2004 8:57 PM To: Neo see the photos :)) kiss you, jeny
-----Original Message----- From: Jena Sent: Tuesday, September 7, 2004 5:23 AM To: friend So.. Am I Hot? :) Waining For Your Answer Jena
-----Original Message----- From: Jenna Knukles Sent: Tuesday, September 7, 2004 9:05 AM To: Friends Group in archive my photos Jenna :)
-----Original Message----- From: jenny Sent: Tuesday, September 7, 2004 10:23 AM To: Mr.X (e-mail) photos you asked jenny
-----Original Message----- From: jenna (e-mail) Sent: Tuesday, September 7, 2004 11:38 AM To: ma kittie my photos zipped )) kiss, jenna
The worm can send itself as an executable attachment or in a ZIP archive with one of the following names:
Also the worm can attach a fake virus scan report to its message:
where it can be any of the following:
The worm fakes the sender's address. It uses the following list of first names to compose the fake address:
It uses the following list of last names to compose the fake address:
It uses the following list of domain names to compose these fake addresses:
Downloading a backdoor
The worm downloads a backdoor from one of websites and activates it. The backdoor is known as 'Surila.J' and is downloaded from the following websites:
Limited lifecycle
After September 17th, 2004, 01:18:31 the worm stops working and deletes its file from a hard drive.