Virus Encyclopedia
I-Worm/Mytob.MA!CME-581
CME-581
It`s internet worm that spreads using known security hole on "not updated" systems.
Installation:
When the worm is launched it copies itself as per.exe to Windows System Directory and registers itself as WINDOWS SYSTEM in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and \RunServices keys. Virus also modifies Hosts file to block access to (but not only) several AV pages.
Spreading:
Worm spreads using Windows Plug and Play vulnerability described in MS05-039.





