To propagate itself, the worm scans the files having the following
extensions and collects all the available email addresses from the infected
system.
adb, asp, dbx, htm, php, pl, sht, tbb, wab.
The worm attempts to locate SMTP server by appending the following
prefixes to the domain names collected from the infected system. On successful
SMTP server access it mails itself to the collected email addresses.
mx.
ns.
relay.
mail1.
mxs.
mx1.
smtp.
mail.
gate.
This worm first appeared on 3rd April,
2005.
Other
names of W32/Mytob.V Worm:
This Worm is also known as W32.Mytob.V@mm,
WORM_MYTOB.V
Protector Plus range of antivirus products
offer on-line virus detection and removal. All the packages have the ability
to detect and isolate all types of viruses, trojans, worms and other types
of malware.
These products are updated on a continuous basis and the latest upgrades
for all the platforms are made available for downloading from this site.