You are here: Home > Security & Privacy > Anti-Spam & Anti-Spy Tools > Resolve for Bdoor-CHR/W32/MyDoom

Resolve for Bdoor-CHR/W32/MyDoom 1.07

Resolve for Bdoor-CHR/W32/MyDoom is a Anti-Spam & Anti-Spy Tools tool for Security & Privacy, by Sophos Plc. Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.

Publisher:
Sophos Plc
Language:
Version:
1.07
Run on OS:
Windows All
License:
Freeware
Price:
$0
File type:
Unknow
File size:
113 KB
Updated on:
Mar 24, 2014
Reviews:
Check Reviews
Rating:
Softmenu rating: 4/10

Resolve for Bdoor-CHR/W32/MyDoom 1.07 Reviews - by Softmenu Editor

It is one of the best Anti-Spam & Anti-Spy Tools software that I have ever used for Security & Privacy.

Advertisement

Software Description - by Publisher

This software description is given by Sophos Plc - the software publisher/developer, and almost no changes made by softmenu.

Full Description see below:

Resolve is the name for a set of small, downloadable Sophos utilities designed to remove and undo the changes made by certain viruses, Trojans and worms.

They terminate any virus processes and reset any registry keys that the virus changed. Existing infections can be cleaned up quickly and easily, both on individual workstations and over networks with large numbers of computers.

W32/MyDoom-A is a worm which spreads by email. When the infected
attachment is launched, the worm harvests email addresses from address
books and from files with the following extensions: WAB, TXT, HTM, SHT, PHP,
ASP, DBX, TBB, ADB and PL.

W32/MyDoom-A creates a file called Message in the temp folder and runs Notepad to display the contents, which displays random characters.

W32/MyDoom-A 'spoofs', using randomly chosen email addresses in the "To:" and "From:" fields as well as a randomly chosen subject line. The emails distributing this worm have the following characteristics.

Subject lines
error
hello
hi
mail delivery system
mail transaction failed
server report
status
test
[random collection of characters]

Message texts
test
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment
The message contains Unicode characters and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.

Attachment filenames
body
data
doc
document
file
message
readme
test
[random collection of characters]

Attached files will have an extension of BAT, CMD, EXE, PIF, SCR or ZIP.



W32/MyDoom-A is programmed to not forward itself via email if the recipient email address satisfies various conditions:

The worm will not send itself to email addresses belonging to domains containing the following strings: acketst, arin., avp, berkeley, borlan, bsd, example, fido, foo., fsf., gnu, google, .gov, gov., hotmail, iana, ibm.com, icrosof, ietf, inpris, isc.o, isi.e, kernel, linux, math, .mil, mit.e, mozilla, msn., mydomai, nodomai, panda, pgp, rfc-ed, ripe., ruslis, secur, sendmail, sopho, syma, tanford.e, unix, usenet, utgers.ed As a consequence the worm does not forward itself to a number of email domains, including several anti-virus companies and Microsoft.
The worm will not send itself to email addresses in which the username contains the following strings: abuse, anyone, bugs, ca, contact, feste, gold-certs, help, info, me, no, noone, nobody, not, nothing, page, postmaster, privacy, rating, root, samples, secur, service, site, spm, soft, somebody, someone, submit, the.bat, webmaster, you, your, www
The worm will not send itself to email addresses which contain the the following strings: admin, accoun, bsd, certific, google, icrosoft, linux, listserv, ntivi, spam, support, unix

The worm can also copy itself into the shared folder of the KaZaA peer-to-peer application with one of the following filenames and a PIF, EXE, SCR or BAT extension:
activation_crack
icq2004-final
nuke2004
office_crack
rootkitXP
strip-girl-2.0bdcom_patches
winamp5

Further reading: MyDoom worm spreads widely across internet, Sophos warns users to be wary of viral email and hacker attack W32/MyDoom-A is a worm which spreads by email. When the infected
attachment is launched, the worm harvests email addresses from address
books and from files with the following extensions: WAB, TXT, HTM, SHT, PHP,
ASP, DBX, TBB, ADB and PL.

W32/MyDoom-A creates a file called Message in the temp folder and runs Notepad to display the contents, which displays random characters.

W32/MyDoom-A 'spoofs', using randomly chosen email addresses in the "To:" and "From:" fields as well as a randomly chosen subject line. The emails distributing this worm have the following characteristics.

Subject lines
error
hello
hi
mail delivery system
mail transaction failed
server report
status
test
[random collection of characters]

Message texts
test
The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment
The message contains Unicode characters and has been sent as a binary attachment.
Mail transaction failed. Partial message is available.

Attachment filenames
body
data
doc
document
file
message
readme
test
[random collection of characters]

Attached files will have an extension of BAT, CMD, EXE, PIF, SCR or ZIP.



W32/MyDoom-A is programmed to not forward itself via email if the recipient email address satisfies various conditions:

The worm will not send itself to email addresses belonging to domains containing the following strings: acketst, arin., avp, berkeley, borlan, bsd, example, fido, foo., fsf., gnu, google, .gov, gov., hotmail, iana, ibm.com, icrosof, ietf, inpris, isc.o, isi.e, kernel, linux, math, .mil, mit.e, mozilla, msn., mydomai, nodomai, panda, pgp, rfc-ed, ripe., ruslis, secur, sendmail, sopho, syma, tanford.e, unix, usenet, utgers.ed As a consequence the worm does not forward itself to a number of email domains, including several anti-virus companies and Microsoft.
The worm will not send itself to email addresses in which the username contains the following strings: abuse, anyone, bugs, ca, contact, feste, gold-certs, help, info, me, no, noone, nobody, not, nothing, page, postmaster, privacy, rating, root, samples, secur, service, site, spm, soft, somebody, someone, submit, the.bat, webmaster, you, your, www
The worm will not send itself to email addresses which contain the the following strings: admin, accoun, bsd, certific, google, icrosoft, linux, listserv, ntivi, spam, support, unix

The worm can also copy itself into the shared folder of the KaZaA peer-to-peer application with one of the following filenames and a PIF, EXE, SCR or BAT extension:
activation_crack
icq2004-final
nuke2004
office_crack
rootkitXP
strip-girl-2.0bdcom_patches
winamp5

W32/MyDoom-A creates a file called taskmon.exe in the system or temp folder and adds the following registry entry to run this file every time Windows starts up:

HKLMSoftwareMicrosoftWindowsCurrentVersionRunTaskmon = taskmon.exe

Please note that on Windows 95/98/Me, there is a legitimate file called taskmon.exe in the Windows folder.

W32/MyDoom-A also drops a file named shimgapi.dll to the temp or system folder. This is a backdoor program loaded by the worm that allows outsiders to connect to TCP port 3127. The DLL adds the following registry entry so that it is run on startup:

HKCRCLSID{E6FB5E20-DE35-11CF-9C87-00AA005127ED}InProcServer32
Default= ""

The worm will also add the following entries to the registry:

HKLMSoftwareMicrosoftWindowsCurrentVersionExplorerComDlg32
HKCUSoftwareMicrosoftWindowsCurrentVersionExplorerComDlg32

W32/MyDoom-A, W32/MyDoom-AJ, W32/MyDoom-B, W32/MyDoom-F, W32/MyDoom-N, W32/MyDoom-O, W32/MyDoom-S and Troj/Bdoor-CHR can be removed from Windows computers automatically with the following Resolve tools:

Windows disinfector
BDLAAGUI is a disinfector for standalone Windows computers. To use it you have to do the following:

Supported Operating System:

Windows All

Running requirements

Need not extra requirement except the OS environments mentioned above.

Limitations

Please check the license above, if this is a freeware, it will be no limitation, else it may have the days or times limitation, please read the specifications attached with the download file carefully.

Tested virus free - Resolve for Bdoor-CHR/W32/MyDoom has been tested to be a safe software on Mar 24, 2014.

Softwares Searches Related to Resolve for Bdoor-CHR/W32/MyDoom

Bookmark or share this page to your friends

copy softmenu.org bookmark
copy softmenu.org bookmark
copy softmenu.org bookmark

Resolve for Bdoor-CHR/W32/MyDoom Related Softwares

Forfeit Fun

Hours of side-splitting fun as you, your friends and family are challenged to complete our hilarious forfeits, mini-games and quiz questions. Choose a character, input your name, sit ...

iThinkOfYou

The must-have app for all lovebirds."No facebook, no Google+, just privacy - iThinkOfYou is the premium social network for two..." ++ Number 2 of the best-selling Social Networking ...

Super Fortune Cookie!

Super Fortune Cookie! is a super happy fun time for everyone!Do you want to know what the future has in store for you? How about how to handle a big upcoming meeting, or introduce yourself ...

Force Lightning

Force Lightningtags: lightning, force lightning, thunder, thunderstorm, palpatine, emperor, sith, jedi, Lightsaber, Light Saber, Lightsabre, Light Sabre, Star Wars, Luke Skywalker, Obi-Wan Kenobi, ...

Coins for Kids

Teach your child the basics of coins and how to make change!Multiple levels are suitable for ages 2-7, your child can grow into this app -- with five levels to progress through, they'll ...

Chinese Numbers for Kids

Your kids can learn chinese today! This is a comprehensive, fun and interactive learning app to teach children chinese numbers from 1-100. Five interactive modules include: - learning ...

Latest Software Topic