Virus Encyclopedia
I-Worm/Mytob.LY!CME-243
CME-243
(aka Zotob.A)
It`s internet worm that spreads using known security hole on "not updated" systems.
Installation:
When the worm is launched it copies itself as botzor.exe to Windows System Directory and registers itself as WINDOWS SYSTEM in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and \RunServices keys. Virus also modifies Hosts file to block access to (but not only) several AV pages.
Spreading:
Worm spreads using Windows Plug and Play vulnerability described in MS05-039.





