Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Nov 09, 2007 | Updated Sep 15, 2017

Worm:Win32/Mytob.CG@mm

Detected by Microsoft Defender Antivirus

Aliases: W32/Mytob.cf@MM (Command) I-Worm/Mytob.BT (AVG) Win32.Worm.Mytob.AJ (BitDefender) Win32/Mytob.BT!Worm (CA) Win32/Mytob.BH (ESET) Net-Worm.Win32.Mytob.x (Kaspersky) W32/Mytob.AG@mm (McAfee) W32/Mytob.BY (Norman) W32/Mytob.BT.worm (Panda) W32/Mytob-AK (Sophos) Net-Worm.Win32.Mytob.bx (Sunbelt Software) W32.Mytob.AH@mm (Symantec) WORM_MYTOB.BT (Trend Micro) I-Worm.Mytob.BS (VirusBuster) Worm:Win32/Hellim.B (Microsoft)

Summary

Worm:Win32/Mytob.CG@mm is a mass-mailing and network worm that targets computers running certain
versions of Microsoft Windows. The worm can spread through e-mail, MSN/Windows Messenger, and by targeting randomly generated IP addresses and exploiting Windows vulnerabilities described in Microsoft Security Bulletins MS04-011 and MS03-026. The worm also contains backdoor functionality and connects to an IRC server to receive commands from attackers.
Worm:Win32/Mytob.CG@mm may download and install additional malicious software, thus manual removal is not recommended. To detect and remove this worm and other malicious software that may have been installed, run a full-system scan with an up-to-date antivirus product such as the Microsoft Safety Scanner (http://go.microsoft.com/fwlink/?LinkId=212742). For more information, visit http://www.microsoft.com/athome/security/downloads/default.mspx
Follow us