Malware

Win32:Mydoom-BJ [Wrm] removal tips

Malware Removal

The Win32:Mydoom-BJ [Wrm] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Mydoom-BJ [Wrm] virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Starts servers listening on 0.0.0.0:3159
  • Drops a binary and executes it
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself
  • Makes SMTP requests, possibly sending spam or exfiltrating data.
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
shwpehrprn.biz
rwereqhssn.org
ma1-aaemail-dr-lapp01.apple.com
ma1-aaemail-dr-lapp02.apple.com
ma1-aaemail-dr-lapp03.apple.com
rn-mailsvcp-ppex-lapp14.apple.com
mx01.oxsus-vadesecure.net
rn-mailsvcp-ppex-lapp15.apple.com
spephnhrpa.biz
mxa-00377f03.gslb.pphosted.com
mxb-00377f03.gslb.pphosted.com
mx02.oxsus-vadesecure.net
rn-mailsvcp-ppex-lapp24.apple.com
mxb-00377f01.gslb.pphosted.com
rn-mailsvcp-ppex-lapp34.apple.com
rn-mailsvcp-ppex-lapp35.apple.com
mx03.oxsus-vadesecure.net
rrwwweemqs.org
rn-mailsvcp-ppex-lapp44.apple.com
rn-mailsvcp-ppex-lapp45.apple.com
mx04.oxsus-vadesecure.net
mx.cam.ac.uk
ismtp.sitestar.everyone.net
onlineconnections.com.au

How to determine Win32:Mydoom-BJ [Wrm]?


File Info:

crc32: 53561B65
md5: d2d0810fa6f942c316339a48c865d41b
name: D2D0810FA6F942C316339A48C865D41B.mlw
sha1: d5adefd42699b367307639e1a298f07a56513e6c
sha256: f81d2b083548afd9b722626a4d2d94ff9f180b9fbb57e66c42036a4317bca1cb
sha512: b679711faf592c9aac2c10dd438974e2a52300c38ff4e647ce26de62e9c0f7c8fb70c6ebfab4dd11fe776dfd86159a41c61bb895d9877f1eed6168eed509c613
ssdeep: 3072:COjWuyt0ZsqsXOKofHfHTXQLzgvnzHPowYbvrjD/L7QPbg/Dr0T3rnXLHf7zjPPB:CIs9OKofHfHTXQLzgvnzHPowYbvrjD/4
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Win32:Mydoom-BJ [Wrm] also known as:

BkavW32.AIDetectVM.malware1
K7AntiVirusTrojan ( 004d7c651 )
DrWebTrojan.DownLoader8.56532
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Small.S5091480
ALYacTrojan.GenericKDZ.66635
CylanceUnsafe
ZillyaDropper.Mudrop.Win32.4765
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanDropper:Win32/Small.cb29f013
K7GWTrojan ( 004d7c651 )
Cybereasonmalicious.fa6f94
TrendMicroTROJ_GEN.R002C0DE620
CyrenW32/S-e4365596!Eldorado
SymantecW32.Mydoom.B@mm
ESET-NOD32a variant of Win32/Agent.NHB
APEXMalicious
AvastWin32:Mydoom-BJ [Wrm]
ClamAVWin.Trojan.Agent-7778003-0
GDataTrojan.GenericKDZ.66635
KasperskyTrojan.Win32.Small.acli
BitDefenderTrojan.GenericKDZ.66635
NANO-AntivirusTrojan.Win32.Mudrop.ijmve
SUPERAntiSpywareTrojan.Agent/Gen-MalPE
MicroWorld-eScanTrojan.GenericKDZ.66635
TencentMalware.Win32.Gencirc.10b0c1b8
Ad-AwareTrojan.GenericKDZ.66635
SophosMal/Behav-104
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureTrojan.TR/Proxy.Gen
BitDefenderThetaAI:Packer.013F267C1D
VIPREBehavesLike.Win32.Malware.ssc (mx-v)
Invinceaheuristic
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.d2d0810fa6f942c3
EmsisoftTrojan.GenericKDZ.66635 (B)
SentinelOneDFI – Malicious PE
F-ProtW32/S-e4365596!Eldorado
Endgamemalicious (high confidence)
WebrootW32.Downloader.Gen
AviraTR/Proxy.Gen
Antiy-AVLTrojan[Dropper]/Win32.Mudrop
MicrosoftTrojan:Win32/Mydoom
JiangminTrojanDropper.Mudrop.bpo
ArcabitTrojan.Generic.D1044B
AegisLabTrojan.Win32.Small.tpLR
ZoneAlarmTrojan.Win32.Small.acli
AhnLab-V3Dropper/Win32.Mudrop.C84237
Acronissuspicious
McAfeeW32/Mytob.gen@MM.i
MAXmalware (ai score=86)
VBA32BScope.Trojan-Spy.Zbot
MalwarebytesWorm.MyDoom
PandaW32/MyDoom.IC.worm
TrendMicro-HouseCallTROJ_GEN.R002C0DE620
RisingTrojan.Agent!1.C364 (CLOUD)
YandexTrojan.Small!o/MVpJjYbYA
IkarusTrojan.Win32.Mydoom
eGambitUnsafe.AI_Score_100%
FortinetW32/Agent.NHB!worm
AVGWin32:Mydoom-BJ [Wrm]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.8e6

How to remove Win32:Mydoom-BJ [Wrm]?

Win32:Mydoom-BJ [Wrm] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment