Trend Micro Virus Alert - WORM_MYTOB.AR

Discussion in 'malware problems & news' started by Randy_Bell, May 30, 2005.

Thread Status:
Not open for further replies.
  1. Randy_Bell

    Randy_Bell Registered Member

    May 24, 2002
    Santa Clara, CA
    Dear Trend Micro customer,

    This is an update of the earlier sent email message for the alert declaration of WORM_MYTOB.AR.

    As of May 30, 2005 3:12 AM YEAR TIME PST (PDT/GMT -7:00), TrendLabs has declared a Medium Risk Virus Alert to control the spread of WORM_MYTOB.AR. TrendLabs has received several infection reports indicating that this malware is spreading in Australia, China, Hongkong, India, Japan, Korea, Philippines, Taiwan, United States.

    The following is a brief summary of what this worm is capable of doing:

    This memory-resident worm propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

    This email message has the following details:

    Subject: (any of the following)
    • {Random}
    • *DETECTED* Online User Violation
    • *IMPORTANT* Please Validate Your Email Account
    • *IMPORTANT* Your Account Has Been Locked
    • *WARNING* Your Email Account Will Be Closed
    • Account Alert
    • Email Account Suspension
    • Important Notification
    • Notice of account limitation
    • Notice: **Last Warning**
    • Notice:***Your email account will be suspended***
    • Security measures
    • Your email account access is restricted
    • Your Email Account is Suspended For Security Reasons

    Message body: (any of the following)
    • Once you have completed the form in the attached file , your account records will not be interrupted and will continue as normal.
    • please look at attached document.
    • Please read the attached document and follow it's instructions.
    • Please see the attachement.
    • The original message has been included as an attachment.
    • To safeguard your email account from possible termination, please see the attached file.
    • To unblock your email account acces, please see the attachement.
    • We attached some important information regarding your account.
    • We have suspended some of your email services, to resolve the problem you should read the attached document.
    • We regret to inform you that your account has been suspended due to the violation of our site policy, more info is attached.

    Attachment: (any combination of the following file names and extension names)

    File name:

    • {random}
    • account-details
    • document
    • document_full
    • email-doc
    • email-info
    • information
    • info
    • info-text
    • instructions
    • your_details

    Extension name:

    • EXE
    • PIF
    • SCR
    • ZIP

    This worm also takes advantage of the LSASS vulnerability to propagate.

    This worm also has backdoor capabilities. It comes with a built-in Internet Relay Chat (IRC) bot that allows it to connect to a specific IRC server. It then waits for commands from a remote user.

    It also terminates processes, some of which are related to antivirus and security programs.

    TrendLabs will be releasing the following EPS deliverables:

    TMCM Outbreak Prevention Policy 177 (already available)
    Official Pattern Release 2.649.00
    Damage Cleanup Template 622

    For more information on WORM_MYTOB.AR, you can visit our Web site at:
  2. JimIT

    JimIT Registered Member

    Jan 22, 2003
    Denton, Texas
    Looks like these are already coming through Hotmail servers. Heads-up. ;)
  3. Ohhh darn, looks like I was stupid enough to download to darn virus.

    And viola, my main computer's infected. Haha. The internet connection and firewalls are all disabled. *sigh*

    Anybody know of a cure for this?
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.