CRIME FW: New virus alert: Mydoom!!!

From: George Heuston (GeorgeH@private)
Date: Mon Jan 26 2004 - 15:00:38 PST

  • Next message: Kuo, Jimmy: "CRIME RE: New virus alert: Mydoom!!!"

    Serious stuff going on right now!!!
    This is a mass-mailing worm that arrives in an email message as follows:
    From: (spoofed)
    Subject: (Random)
    Body:  (Varies, such as) 
    The message cannot be represented in 7-bit ASCII encoding and has been
    sent as a binary attachment. 
    Attachment: (varies [.exe, .pif, .cmd, .scr] - often arrives in a ZIP
    archive) (22,528 bytes)
    The icon used by the file tries to make it appear as if the attachment
    is a text file
    When this file is run it copies itself to the local system with the
    following filenames:
     c:\Program Files\KaZaA\My Shared Folder\activation_crack.scr 
    It also uses a DLL that it creates in the Windows System directory:
     c:\WINDOWS\SYSTEM\shimgapi.dll (4,096 bytes) 
    It creates the following registry entry to hook Windows startup:
    CurrentVersion\Run "TaskMon" = %SysDir%\taskmon.exe
    The worm opens a connection on TCP port 3127 suggesting remote access

