The Mytob authors have been busy at work
The Mytob authors have been "very busy," releasing multiple variants a day. While the distribution of each variant is low, combined there is a lot of activity around them. Over 50 percent of the reported problems coming into Researchers over the last 24 hours have been about Mytob worms. Recent versions, include Mytob.bi which poses as a message from an IT administrator, warning that the recipient’s e-mail account is about to be suspended.
It scans the hard drive of an infected machine and sends copies of itself to e-mail addresses it finds in the Windows Address Book. It also prevents the machine from accessing several antivirus and security Web sites, and can open a random port, allowing a hacker to gain remote access.
While antivirus companies would normally have to update their software to guard against each new variant, the Mytob family is so close that multiple variants can be caught using generic definitions of the worm.
Updated On: 05.06.04