Microsoft has released a tool to remove Mydoom, Zindos, and Doomjuice worm variants and associated back door components from computers that are running any products that are listed in the "Applies to" section.
ImportantWe also recommend that you use an Internet firewall and a current antivirus program, and that you keep both Windows and your programs up-to-date. Do not open file attachments in e-mail messages unless you can confirm with the sender that the attachment is safe.
For additional information about how to prevent viruses and recover from virus infections, click the following article number to view the article in the Microsoft Knowledge Base:
129972 Computer viruses: description, prevention, and recovery
NoteBecause Mydoom.B can block access to some Web sites, including Microsoft.com and the Web sites of some antivirus vendors, you may have to download the Mydoom Worm Removal Tool from a computer that is not infected, and then transfer the tool to your infected computer by using a floppy disk or other removable media, such as a recordable CD-RW.
Download and setup information
If your computer is infected with a variant of the Mydoom, Zindos.A, Doomjuice.A, or Doomjuice.B worms, use Automatic Updates to download and install version 4.0 of the Mydoom Worm Removal Tool. Or, visit the following Microsoft Windows Update Web site, and then install the 836528 critical update:
Release Date: August 4, 2004
For additional information about Automatic Updates, click the following article number to view the article in the Microsoft Knowledge Base:
294871 Description of the Automatic Updates feature in Windows
Release Date: July 30, 2004
For additional information about how to download Microsoft Support files, click the following article number to view the article in the Microsoft Knowledge Base:
119591 How to Obtain Microsoft Support Files from Online Services
Microsoft scanned this file for viruses. Microsoft used the most current virus-detection software that was available on the date that the file was posted. The file is stored on security-enhanced servers that help to prevent any unauthorized changes to the file.
The Mydoom Worm Removal Tool does not work on computers that run Microsoft Windows NT 4.0.
The Mydoom Worm Removal Tool is only available for English (US) versions of Windows. However, you can run the English (US) tool on any language version of Windows.
The Mydoom Worm Removal Tool does not perform the following actions:
- Delete any e-mail messages that contain the Mydoom variants.
- Protect you from future reinfection. Reinfection may occur if you run another infected e-mail attachment.
- Detect or remove malicious programs, except for Zindos.A and Doomjuice variants A and B, that are on your computer because of the back door components that are created by Mydoom variants.
Many antivirus companies have written tools to remove these worms. Most up-to-date antivirus programs will also remove these worms.
Prerequisites
The Mydoom Worm Removal Tool has the following prerequisites:
- Your computer must run Windows 98, Windows 98 Second Edition, Windows Millennium Edition, Microsoft Windows 2000, or a 32-bit version of Windows Server 2003 or Windows XP.
- You must log on as a computer administrator or as a member of the Administrators group.
For more information about how to determine whether a computer is running a 32-bit version of Windows XP or a 64-bit version of Windows XP, click the following article number to view the article in the Microsoft Knowledge Base:
827218 How to determine whether your computer is running a 32-bit version or a 64-bit version of the Windows operating system
If these prerequisites are not met, the installation will not work, and you will receive an error message. For more information about the error message, view the following log file:
Windows Server 2003, Windows XP, or Windows 2000
%WINDIR%\Debug\Doomcln.log
Windows 98, Windows 98 Second Edition, Windows Millennium Edition
%WINDIR%\Doomcln.log
Usage information
NoteBefore you continue with the following steps, make sure that you back up all your important data.
When you install the Mydoom Worm Removal Tool version 4.0 and accept the end-user license agreement (EULA), the installation package extracts Doomcln.exe to a temporary folder, and then Doomcln.exe runs. Doomcln.exe checks your computer for the prerequisites that are listed in the "Prerequisites" section. If these prerequisites are met, Doomcln.exe performs the following steps:
- It checks for evidence of the Mydoom.A (Taskmon.exe), Mydoom.B (Explorer.exe), Mydoom.E (Taskmon.exe), Mydoom.F (random_file.exe), Mydoom.G (random_file.exe or
random_file.scr), Mydoom.J (Taskmon.exe), Mydoom.L (Taskmon.exe), Mydoom.O (Java.exe, Services.exe), Zindos.A (random_file.exe), Doomjuice.A (Intrenat.exe), and Doomjuice.B worms in memory. If Doomcln.exe finds an infection, the worm process is ended.
NoteLegitimate processes that are named Taskmon.exe, Services.exe, and Explorer.exe exist. These legitimate processes are not removed.
- It checks for the known Mydoom variants A, B, E, F, G, J, L, and O, Doomjuice variants A and B, and Zindos.A files on the hard disk and in the
Runkeys in the registry. If Doomcln.exe finds worm files, it deletes the worm files and removes the registry entries.
- It checks for evidence of the back door components that the Mydoom variants leave. If Doomcln.exe finds these components, it removes them from memory and from the registry, and then deletes them from the hard disk. The worm removes the Webcheck.dll and Stobject.dll entries in the registry, and Doomcln.exe replaces these entries.
NoteTo remove these components immediately, Doomcln.exe must restart Windows Explorer (Explorer.exe). Therefore, the taskbar disappears and reappears. This action should not affect any running applications.
- It checks for evidence that the Mydoom.B worm overwrote the Hosts file. If the worm overwrote the file, Doomcln.exe removes this version of the file and replaces it with the default Hosts file. The new Hosts file is marked as read-only.
- It checks for and removes a marker that the worm puts in the registry to indicate that it has already run.
- It displays a Windows message box that describes the outcome of the detection or removal. You may receive any one of the following messages:
- No infection detected– Mydoom variants A, B, E, F, G, J, L, or O, Doomjuice variants A and B, and Zindos.A were not detected on this computer.
- Successfully removed Mydoom.
variant-letter– The variant of Mydoom worm was removed, and you do not have to do anything else. The
variant-lettercould be A, B, E, F, G, J, L, or O.
- Successfully removed Zindos.A– Zindos.A was removed, and you do not have to do anything else.
- Successfully removed Doomjuice.A- Doomjuice.A was removed, and you do not have to do anything else.
- Successfully removed Doomjuice.B- Doomjuice.B was removed, and you do not have to do anything else.
- This tool must be run by an administrator– To run the tool, you must log off and log back on using an account with administrator credentials.
- Fatal error, please review log file– Review the log file for errors, and then contact Microsoft Product Support Services (PSS) if you must.
- Mydoom.
variant-letterwas detected, but could not be removed
– Try to reexecute the tool, and check the log file for errors.
- Mydoom.B was detected, but could not be removed– Try to reexecute the tool, and check the log file for errors.
- Doomjuice.A was detected, but could not be removed– Try to reexecute the tool, and check the log file for errors.
- Doomjuice.B was detected, but could not be removed– Try to reexecute the tool, and check the log file for errors.
- Incorrect Windows version (Win32s)– This tool is not supported in Windows 3.1 with Win32s.
Restart requirement
You do not have to restart your computer after you install this tool.
Removal information
Doomcln.exe is automatically deleted from its temporary location after the Mydoom Worm Removal Tool runs. You can delete the tool’s installer after you install the Mydoom Worm Removal Tool.
The Mydoom Worm Removal Tool creates a log file that is named Doomcln.log in the %WINDIR%\debug folder in Windows Server 2003, Windows XP, and Windows 2000. The log file is created in the %WINDIR% folder in Windows 98, Windows 98 Second Edition, and Windows Millennium Edition.
NoteAfter you install the Mydoom Worm Removal Tool (KB 836528), it does not appear in the
Add or Remove Programslist.
Command-line switches
The Mydoom Worm Removal Tool installer supports the following command-line switches:
- /Q– Use Quiet mode or suppress messages when the files are being extracted.
- /Q:U- Use User-Quiet mode. User-Quiet mode presents some dialog boxes to the user.
- /Q:A- Use Administrator-Quiet mode. Administrator-Quiet mode does not present any dialog boxes to the user.
- /T:
path– Specify the location of the temporary folder that is used by Setup or the target folder for extracting files, when you use the /c switch.
- /C– Extract the files without installing them. If /t: path is not specified, you are prompted for a target folder.
- /C:
cmd– Specify the path and the name of an alternative Setup .inf file or an .exe file to use to install the tool.
- /R:N- Never restart the computer after installation.
- /R:I- Prompt the user to restart the computer if a restart is required, except when this switch is used with the /q:a switch.
- /R:A- Always restart the computer after installation.
- /R:S- Restart the computer after installation without prompting the user
Doomcln.exe supports the following command line switch:
- /S– Enables silent mode for the tool. Therefore, this switch suppresses the infection status dialog box that you receive after the tool has run.