|
Win32.HLLW.MyBot.based Virus |
malware Type: virus
Discovered: 2006-08-21
Added: 2006-08-22
Threat ID: 147382 |
MyBot displays a message that the computer needs to shut down. The virus then shows a countdown and shuts down the computer. To spread, MyBot blindly looks for other computers on the same network. This virus harvests computer information and transmits it to remote computers.
|
Risk Description:
Ease of Removing Win32.HLLW.MyBot.based
Uses running processes
Runs as a service
Consistent file contents
Consistently named
Creates new registry entries with consistent data
Privacy Risks/Security Changes of Win32.HLLW.MyBot.based
Transmits personal data to remote computers
Opens backdoors [VIRUS ONLY]
Harvests nonspecific personal data
Damage/Intrusion/Annoyance of Win32.HLLW.MyBot.based
Autoruns at startup without an option to be disabled
Propagation/Saturation of Win32.HLLW.MyBot.based
Infects through a blind IP address attack [VIRUS ONLY]
Creates new files
Mimics legitimate file names
Displays fake error messages
Spreads from embedded code in an email [VIRUS ONLY]
Spreads from a link in an email |
alias(s) of Win32.HLLW.MyBot.based
worm/Rbot.172032.10
Win32:Trojano-352
IRC/backdoor.SdBot2.EZC
Backdoor.SDBot.7F4521A2
DNAScan
Win32/RBot.variant!Worm
Backdoor.Win32.Agobot.AAF
Backdoor.Win32.Rbot.adf
W32/Sdbot.worm.gen.bh
Win32/Rbot
W32/Sdbot.HNZ.worm
W32.Spybot.Worm
trojan-PSW.LdPinch.39 |
Further details about Win32.HLLW.MyBot.based may be available at our Malware Research Center
|