W32/MyTob.FL@mm - Released Jun 13, 2005 - Last Updated Mar 13, 2007
|
Alias/esW32/MyTob.FL@mm, W32/MyTob.ZIP.FL-mm |
Visible Symptoms |
Detailed AnalysisThis variant of the MyTob family varies slightly among
its family. All MyTob viruses follow a similar scheme:
- copy itself to the local system
- search for email addresses in files
- send itself by SMTP [self contained engine]
- connect with an IRC server to receive instructions
or await commands from a malicious user
- prevent the infected system from connecting to update
servers and various other security related web pages
- this is done by hacking the local "hosts"
file and adding entries redirecting the call to specific
web sites by domain name to the local host
The variants will differ slightly with regard to packed
file size and actual file names created on the host
however the functionality of the viruses remain the
same. |
Recommended Action
FortiGate systems:
- check the main screen using the web interface to
ensure the latest AV/NIDS database has been downloaded
and installed -- if required, enable the "Allow
Push Update" option
|