Virus Encyclopedia
I-Worm/Mytob.WP
CME-637
It`s internet worm that spreads using known security hole on "not updated" systems.
Installation:
When the worm is launched it creates \wbew directory in Windows System Directory and copies itself into as windrg32.exe. Virus registers itself as WinDrg32 in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run key.
Spreading:
Worm spreads using Windows Plug and Play vulnerability described in MS05-039.





