What's the Mydoom (aka Novarg) virus?

A. Mydoom is a new email virus that spoofs the sender so that the message appears to have come from a friend or respected source. The email message can carry any of several subjects, including

  • hi
  • hello
  • HELLO
  • error
  • Mail Delivery System
  • Mail Transaction Failed
  • Server Report
  • status
  • test
  • Test
  • Server Request

The body of the message contains various phrases, including

  • The message cannot be represented in 7-bit ASCII encoding and has been sent as a binary attachment.
  • The message contains Unicode characters and has been sent as a binary attachment.
  • Mail transaction failed. Partial message is available.

The message always contains an attachment (e.g., a .zip, .exe, or .bat file). If the recipient opens the attachment, the virus creates some registry keys to ensure that it autostarts at reboot, then harvests email addresses so that it can mail itself to other people.

The virus includes a Denial of Service (DoS) attack on Microsoft and SCO that's scheduled to run on set dates. In addition, the virus opens port 3127 on the local machine to let the virus writers access and control infected machines. To avoid the spread of this virus, download up-to-date virus definition files and, as always, never open an unsolicited email attachment.

Discuss this Article 4

doug mckee (not verified)
on Feb 4, 2004
hi i encountered this virus after i reformatted my PC and reinstalled windows. a day afterwards the virus appears and i was wondering if there is any chance to get rid of it or do i have to reformat. right now my pc is on XP but i may just downgrade back to 2000
Prabhakaran (not verified)
on Feb 3, 2004
I removed the virus using antivirus patch from norton but i dont know about virus details which is in the page http://www.winnetmag.com/windowsnt20002003faq/Article/ArticleID/41615/windowsnt20002003faq_41615.html Thank you and requesting to update new techie info. Rgds

Please or Register to post comments.

IT/Dev Connections

Las Vegas
September 30th - October 4th

Paul ThurottYou'll have the opportunity to experience:
• The Microsoft
Technology Roadmap
• Office 365 Implementation
• Hyper-V Optimizing
• Windows 8 Deployment
and much more!

Come See Paul Thurrott & Rod Trent in Person!

Early Registration Now Open

Upcoming Training

Mastering System Center 2012

During over 6 hours of training you can join John Savill from your computer as he will walk you through the key components and capabilities of System Center 2012, what’s involved in using the components, and the benefit they can bring to your environment.

Register Now

Current Issue

May 2013 - The NameTranslate object is useful when you need to translate Active Directory object names between different formats, but it's awkward to use from PowerShell. Here's a PowerShell script that eliminates the awkwardness.

CURRENT ISSUE / ARCHIVE / SUBSCRIBE

Windows Forums

Get answers to questions, share tips, and engage with the Windows Community in our Forums.