Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 20 December 2006 02:53:23 (GMT) |
| Last updated | 14 May 2007 22:44:09 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Mytob-JO is a mass-mailing worm for the Windows platform.
W32/Mytob-JO spreads by sending emails with the following characteristics:
From: abuse@<harvested domain>
Subject line: "Account Alert" or a randomly generated string.
Message text:
According to our terms of services, you will have to confirm your e-mail by the following link, or your account will be suspended within 24 hours for security reasons.
<spoofed link pointing to a copy of the worm>
After following the instructions in the sheet, your account will not be interrupted and will continue as normal.
Thanks for your attention to this request. We apologize for any inconvenience.
Sincerely, <harvested domain> Abuse Department
When first installed the worm copies itself to <System>\kernel_runtime.exe
The worm creates the following registry entries in an attempt to run itself on startup:
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
KernelRuntime
<path to worm executable>
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
KernelRuntime
<path to worm executable>
