COMPARTIR
ESTO EN

Facebook Twitter Google Plus

Herramientas de Eliminación de Virus Gratuitas

¿Tiene un PC infectado por un virus específico? ¡Elimínelo ahora mismo gratuitamente! ¡Simplemente navegue por nuestra base de datos de virus conocidos más abajo, y haga clic en el botón de descarga para iniciar el proceso de eliminación del virus!

Actividad de virus

Nivel de amenaza

Nivel de alerta: normal
Últimas noticias
Alleged Baidu Spyware Gathering User Data From Sony Xperia Smartphones; “Unexpected Behaviour” Sony Says
Sony Xperia Smartphones with Android 4.4.2 or 4.4.4 KitKat versions have been allegedly fo [...]
¡Más información
BlackEnergy Malware Compromises US SCADA Systems; US CERT Says
The BlackEnergy malware toolkit has been compromising US SCADA (Supervisory Control and Da [...]
¡Más información
Dyre Banking Trojan Still Phishing for Data, US-CERT Warns
A new phishing campaign employs the Dyre banking Trojan to steal account credentials from [...]
¡Más información
ASUS Wireless Routers RT Series Vulnerable to Man-in-the-Middle Attacks
The ASUS wireless routers from the RT-series have been found vulnerable to a Man-in-the-Mi [...]
¡Más información
FBI infected 15-year-old bomb threat twit with malware, by impersonating newspaper
The Seattle Times is furious, after discovering that the FBI stole its identity.   Do [...]
¡Más información
Adware Removal Tool Ready for Testing
The National Cyber Security Awareness Month may be over, but here at Bitdefender we take y [...]
¡Más información
From Ring3 to Ring0 – Xen emulator flaws
Bitdefender researcher Andrei Lutas published , a whitepaper detailing the exploitation o [...]
¡Más información
Russian Hackers Promise Anti-Government Software, Deliver Kelihos Trojan Instead
With the Ukrainian conflict in mind, an alleged hacker community from Russia installs data [...]
¡Más información
Gameover Zeus Variants Targeting Ukraine, US
Gameover Zeus has recently started to use Domain Generation Algorithms as OpenDNS security [...]
¡Más información
Pushdo Pushing Six Figures
Further sinkholing by the Bitdefender research team saw the Pushdo bots calling home from [...]
¡Más información
Herramienta de eliminación destacada

Win32.Worm.Mytob.BY

MEDIO
MEDIO
2.7 MB
05/29/05
This virus comes by e-mail, spoofing the sender address, and is packed with MEW, an executable file compressor. Once executed, the worm does the following: 1. Creates the mutex, in order to have only one instance of itself running in memory: H-3-1-1-B-0-T-3-F-1-X-3 2. Copies itself as %SYSTEM%\Lien Van de Kelder.exe 3. Creates/modifies the following registry keys: [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "http://www.lienvandekelder.be" = "%SYSTEM%\Lien Van de Kelder.exe" [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices] "http://www.lienvandekelder.be" = "%SYSTEM%\\Lien Van de Kelder.exe" [HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\SharedAccess] "Start" = "4" 4. Starts harvesting e-mail addresses, searchin in folder "Temporary Internet Files", the current outlook e-mail account files, and from files matching .txt .htm .sht .jsp .cgi .xml .php .asp .dbx .tbb .adb .pl .wab searching in drives C: to Y: it avoids certain e-mail addresses, by comparing the address with an internal list of substrings. 5. The worm uses its own SMTP engine to send itself to the harvested email addresses, attempts to use the default e-mail account settings also to reconstruct the smtp server by prepending the following strings to the harvested email's domain names: gate. mail. mail1. mx. mx1. mxs. ns. relay. smtp. The email format is: From (spoofed, has a big list of names) Subject (one of the following): %Random string% Notice: **Last Warning** *DETECTED* Online User Violation Your Email Account is Suspended For Security Reasons Account Alert Important Notification *WARNING* Your Email Account Will Be Closed Security measures Email Account Suspension Notice of account limitation Body (one of the following): Once you have completed the form in the attached file , your account records will not be interrupted and will continue as normal. The original message has been included as an attachment. We regret to inform you that your account has been suspended due to the violation of our site policy, more info is attached. We attached some important information regarding your account. Please read the attached document and follow it's instructions. Attachment (may begin with): mail-info email-doc information account-details document INFO instructions info-text information followed by double extension (.tmp .doc .htm .txt) .exe .src .pif .zip example: INFO.htm.scr 6. Prevents/terminates execution of many security related products (executables) 7. Blocks access to several security related sites, by modifying the system HOSTS file 8. Has backdoor capabilities (irc bot): Connects to the IRC server irc.blackcarder.net and joins channel ##hb3f1x3 Once connected, listens for commands issued by an possible attacker. The commands may allow the attacker to: download/execute/update files (including the worm itself) gain information about the operating system and computer configuration stop the worm [...] [...]
Mostrar más resultados