Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 10 April 2006 03:28:16 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Mytob-HE is a mass-mailing worm and IRC backdoor Trojan for the Windows platform.
When run the worm attempts to copy itself to <System>\0.exe as well as to various P2P shared folders using various filenames.
In order to run automatically when Windows starts up W32/Mytob-HE creates the following registry entry:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
begins
<System>\0.exe
W32/Mytob-HE will harvest email addresses from the infected computer and then mail itself to those addresses as an attachment.
W32/Mytob-HE also attempts to terminate various anti-virus and security related applications and processes.
