Virus Encyclopedia
I-Worm/Mytob.LZ!CME-164
CME-164
(aka Zotob.B)
It`s internet worm that spreads using known security hole on "not updated" systems.
Installation:
When the worm is launched it copies itself as csm.exe to Windows System Directory and registers itself as csm Win Updates in HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run and \RunServices keys. Virus also modifies Hosts file to block access to (but not only) several AV pages.
Spreading:
Worm spreads using Windows Plug and Play vulnerability described in MS05-039.





