Sophos

W32/Mytob-JO

Aliases
  • W32/Mytob.io@MM
  • virus
Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Email messages
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 20 December 2006 02:53:23 (GMT)
Last updated 14 May 2007 22:44:09 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

More Information

W32/Mytob-JO is a mass-mailing worm for the Windows platform.

W32/Mytob-JO spreads by sending emails with the following characteristics:

From: abuse@<harvested domain>

Subject line: "Account Alert" or a randomly generated string.

Message text:

According to our terms of services, you will have to confirm your e-mail by the following link, or your account will be suspended within 24 hours for security reasons.

<spoofed link pointing to a copy of the worm>

After following the instructions in the sheet, your account will not be interrupted and will continue as normal.

Thanks for your attention to this request. We apologize for any inconvenience.

Sincerely, <harvested domain> Abuse Department

When first installed the worm copies itself to <System>\kernel_runtime.exe

The worm creates the following registry entries in an attempt to run itself on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KernelRuntime
<path to worm executable>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
KernelRuntime
<path to worm executable>

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer