|
|
 |
Win32.HLLW.MyBot Spreads Over Networks!Win32.HLLW.MyBot.based
What It Does:
Adds itself to the Windows system directory.Modifies the computer's registry so that it starts when Windows starts.Displays a message that the computer needs to shut down. Shows a countdown and shuts down the computer.Blindly looks for other computers on the same network and silently spreads.Harvests computer information and transmits it to remote computers.
How It Infects: Win32.HLLW.MyBot can be distributed by any means, including but not limited to: Email attachmentsInstant message attachmentsInfected websitesHyperlinks to infected websites from email or instant messagesDownloading by other malwareThrough peer-to-peer networks Once one computer on a network is infected, MyBot broadcasts to other local IP addresses.
How To Avoid Infection: Do not click any unexpected links in instant messages. Do not download email attachments from unexpected sources. Do not download unknown files or files from unknown sources. Scan all downloaded files with StopSign and ensure that all updates are installed from Microsoft Update.
Vulnerable Operating Systems: Windows 95/98/Me/NT/2000/XP
Type: Worm
Technical Name: Win32.HLLW.MyBot.based
Aliases: m/Rbot.172032.10Win32:Trojano-352IRC/BackDoor.SdBot2.EZCBackdoor.SDBot.7F4521A2DNAScanWin32/RBot.Variant!WormBackdoor.Win32.Agobot.AAFBackdoor.Win32.Rbot.adfW32/Sdbot.worm.gen.bhWin32/RbotW32/Sdbot.HNZ.wormW32.Spybot.WormTrojan-PSW.LdPinch.39
|