Skip to main content

Slew Of Mytob Worms Strike

posted onMarch 29, 2005
by hitbsecnews

Eight variations of the Mytob worm have appeared in the last five days, said Symantec Monday, all of them able to plant a backdoor on infected machines and prevent them from updating security software.

The eight -- dubbed Mytob.j through Mytob.s with some final letter designations skipped -- are mass-mailed worms that spread by sending themselves to addresses they find on the target Windows PC. They can also spread, said Symantec, by exploiting the LSASS vulnerability in Windows. That bug, first disclosed in an April 2004 security bulletin, http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx has been patched by Microsoft. Still, it remains a favorite target of hackers, who continue to find unpatched systems.

Mytob also tries to prevent infected machines from reaching security update sites -- such as those operated by Symantec, Sophos, McAfee, and Microsoft -- by changing the PC's Hosts file.

The worm comes with a variety of subject headings and attached file names and formats, but it often appears with the subjects of "Mail Transaction Failed" and "Error."

Source

Tags

Viruses & Malware

You May Also Like

Recent News

Friday, November 29th

Tuesday, November 19th

Friday, November 8th

Friday, November 1st

Tuesday, July 9th

Wednesday, July 3rd

Friday, June 28th

Thursday, June 27th

Thursday, June 13th

Wednesday, June 12th

Tuesday, June 11th