Trojan

Trojan:Win32/Mydoom (file analysis)

Malware Removal

The Trojan:Win32/Mydoom is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Mydoom virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Starts servers listening on 0.0.0.0:3159
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Creates a slightly modified copy of itself

Related domains:

qanrmqnprn.info
ma1-aaemail-dr-lapp02.apple.com
ma1-aaemail-dr-lapp03.apple.com
rn-mailsvcp-ppex-lapp14.apple.com
rn-mailsvcp-ppex-lapp15.apple.com
rn-mailsvcp-ppex-lapp24.apple.com
mx02.oxsus-vadesecure.net
mqprparnws.in
mxa-00377f01.gslb.pphosted.com
rn-mailsvcp-ppex-lapp34.apple.com
mx03.oxsus-vadesecure.net

How to determine Trojan:Win32/Mydoom?


File Info:

crc32: 3AB554FC
md5: b4d22b58cd80b7ffc930a76ca9f9fa71
name: B4D22B58CD80B7FFC930A76CA9F9FA71.mlw
sha1: 3931f09d3d36e714eade19bab13a2ac5c5db1a6c
sha256: 804acd2d212ff0dbdc4670b07862c19f275fc746b19d431bf6b31f78d7a63ec6
sha512: fa990e0799500dfef650648d06f7226a5c697b71c587ff32dbabe957a3e0425bd4f3d2f05990af787d3f2b223aa3097a88c2d018d79eadf4776f1742706e9b5e
ssdeep: 3072:iOjWuyt0ZsqsXOKofHfHTXQLzgvnzHPowYbvrjD/L7QPbg/Dr0T3rnXLHf7zjPPX:iIs9OKofHfHTXQLzgvnzHPowYbvrjD/M
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Mydoom also known as:

BkavW32.AIDetectVM.malware1
K7AntiVirusTrojan ( 004d7c651 )
DrWebTrojan.DownLoader8.56532
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Small.S5091480
McAfeeW32/Mytob.gen@MM.i
CylanceUnsafe
ZillyaDropper.Mudrop.Win32.4765
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Small.b0c0eaeb
K7GWTrojan ( 004d7c651 )
Cybereasonmalicious.8cd80b
TrendMicroTROJ_GEN.R002C0DE620
CyrenW32/S-e4365596!Eldorado
SymantecW32.Mydoom.B@mm
ESET-NOD32a variant of Win32/Agent.NHB
APEXMalicious
AvastWin32:Mydoom-BJ [Wrm]
ClamAVWin.Dropper.Mudrop-6801241-0
GDataTrojan.GenericKDZ.66635
KasperskyTrojan.Win32.Small.acli
BitDefenderTrojan.GenericKDZ.66635
NANO-AntivirusTrojan.Win32.Mudrop.ijmve
SUPERAntiSpywareTrojan.Agent/Gen-MalPE
MicroWorld-eScanTrojan.GenericKDZ.66635
TencentMalware.Win32.Gencirc.10b0c1b8
Ad-AwareTrojan.GenericKDZ.66635
SophosMal/Behav-104
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Proxy.Gen
BitDefenderThetaAI:Packer.B67639FC1D
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
Invinceaheuristic
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.b4d22b58cd80b7ff
EmsisoftTrojan.GenericKDZ.66635 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/S-e4365596!Eldorado
Endgamemalicious (high confidence)
WebrootW32.Downloader.Gen
AviraTR/Proxy.Gen
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan[Dropper]/Win32.Mudrop
MicrosoftTrojan:Win32/Mydoom
JiangminTrojanDropper.Mudrop.bpo
ArcabitTrojan.Generic.D1044B
AegisLabTrojan.Win32.Small.tpLR
ZoneAlarmTrojan.Win32.Small.acli
AhnLab-V3Dropper/Win32.Mudrop.C84237
Acronissuspicious
VBA32BScope.Trojan-Spy.Zbot
MAXmalware (ai score=83)
MalwarebytesWorm.MyDoom
PandaW32/MyDoom.IC.worm
TrendMicro-HouseCallTROJ_GEN.R002C0DE620
RisingTrojan.Agent!1.C364 (CLOUD)
YandexTrojan.Small!jVJIbeDcYBw
IkarusTrojan.Win32.Mydoom
MaxSecureTrojan.Win32.Small.acli
FortinetW32/Agent.NHB!worm
AVGWin32:Mydoom-BJ [Wrm]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.8e6

How to remove Trojan:Win32/Mydoom?

Trojan:Win32/Mydoom removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment