Your antivirus software and other programs may use the term “W32.Mytob.AR@mm” to refer to a malware program. W32.Mytob.AR@mm, also known as Mytob, Mytob.A, tbu, Vtrp, W32.Mytob.AR@mm, or W32.Mytob.AR@mm.b is a destructive worm that spreads by using the network. The worm hijacks the execution of programs in order to download and run a series of scripts that load additional infections on the infected computer. The Mytob infection is similar to the Vundo worm, but it uses fewer commands, which makes it less difficult to remove. Symantec AntiVirus Corporate Edition users can use the following actions to remove the infections: ■ Run the removal tool ■ Run the anti-virus product ■ Disable System Restore and reboot the system ■ Run the anti-virus product again, and restart the computer. The removal tool includes all the fixes that we developed for an earlier version of the worm. Mytob.A can also install a back door on the computer so that the attacker can come back after the infection is removed. To make sure the anti-virus product catches all the infections you can exclude the Mytob.AR@mm folder from scanning with the /EXCLUDE switch. Additionally, you can use the switch /FIXREG to scan the registry and remove the values that are added by the worm. Symantec AntiVirus Corporate Edition Versions Affected: ■ All versions of the following products: ■ Symantec AntiVirus Corporate Edition ■ Symantec VirusScan Enterprise Edition ■ Symantec AntiVirus Corporate Edition for Windows and Mac The vtyawebrowser.exe file is created by the tbu program. Many Windows operating systems are susceptible to infection by the tbu worm. Symantec AntiVirus Corporate Edition Versions Not Affected: ■ Windows 98, Windows NT 4.0, and Windows 2000 are not affected by the tbu worm. ■ Norton AntiVirus, McAfee VirusScan Enterprise, and F-Secure Anti-Virus (NAS) are not affected by the tbu worm. Symantec AntiVirus Corporate Edition Versions Affected

■ This tool displays the following help message: ■ W32.Mytob.AR@mm is a virus that targets Internet Explorer by modifying the files that are typically located on your desktop. ■ The worm creates itself as a binary file with the name: ■ “C:\Documents and Settingsuser1Desktopwlm.exe.C32.Mytob.AR@mm”. ■ This file will then be used to load the virus and run the virus. ■ By deleting the “wlm.exe” file, you can prevent the worm from running. ■ Once the worm deletes itself, it will still attempt to infect the computer and delete the “wlm.exe” file. ■ The worm can also delete the “Path” and “ProtectedView” keys from the registry to stop infected browsers from displaying a virus protection page. ■ These changes can be restored by using the registry repair tool in the MS-DOS environment, by using the /FIXREG switch. ■ The worm modifies your Windows Hosts file. ■ This worm is classified as a worm/virus, which is not detected by most standard antivirus programs. ■ The virus is mainly distributed on dial-up connections through the use of online games and or Internet mail. ■ You can prevent the worm from deleting your Hosts file by replacing it with a clean version. Disclaimer: ■ This tool is designed to provide root access to W32.Mytob.AR@mm and removes it from the infected computer only. ■ If you are unsure whether you have the W32.Mytob.AR@mm virus, then you should scan your computer with an antivirus program before trying to remove it with this tool. ■ Do not run this tool if you are unsure whether you have W32.Mytob.AR@mm. ■ Do not use this tool if you are unsure how to use it. We do not provide technical support for this tool. Warning: ■ The W32.Mytob.AR@mm virus can delete files or corrupt them, or change them in such a way that they cause damage or render your computer inoperable. In addition, this malware often attempts to delete or overwrite important files that are important to your 7ef3115324

W32.Mytob.AR@mm is a rogue anti-virus program which displays the following in the task bar: ■ ‘It discovered virus on C:\Documents and Settings\user1\Desktop’ ■ ‘Cleaned by the Windows Anti-Virus’ ■ ‘Your real anti-virus program is Microsoft Anti-Virus (MS-AV) which protects you against a great many viruses. ■ ‘You need to update your anti-virus definitions with those of MS-AV’ In addition to the above, there are other indicators of this infection, such as: ■ ‘The system has received information about a new virus. This virus could potentially disable this computer or make it unusable’ ■ ‘The system must restart to clean this virus’ ■ ‘I have to update my RealAnti-Virus or there is no protection. Restart in 30 seconds’ ■ ‘Antivirus not found. Please check you have a current virus definition for your real antivirus program’ ■ ‘Antivirus found’ ■ ‘Antivirus found’ ■ ‘The taskbar is displaying a green icon’ W32.Mytob.AR@mm Free Removal Tool Removal: You can remove the W32.Mytob.AR@mm from the computer using this tool by following these steps: ■ If you are on a network or have a full-time connection to the Internet, disconnect the computer from the network and Internet. ■ If you are running Windows Me or XP, turn off System Restore. ■ Locate the file that you just downloaded. ■ Double-click the fxmytbar.exe file to start the removal tool. ■ Click Start to begin the process, and then allow the tool to run. ■ Restart the computer. ■ Run the removal tool again to ensure that the system is clean. How to learn more about removal tools ■ Run the following command (note that the command may vary based on your version of Windows): “C:\Windows\system32\msiexec.exe” /help The following are links that will help you learn more about virus removers and removal tools: ■ Microsoft Knowledge Base: –

W32.Mytob.AR@mm is a worm that propagates through a computer’s shared files. W32.Mytob.AR@mm includes the following actions: ■ Modifies the Windows Fax/Modem configuration to send advertising faxes when a computer is infected. ■ Modifies the Hosts file on all the infected computers so that any requests for the infected computer’s web page are redirected to this web page: ■ Writes the registry values that communicate with the website. The W32.Mytob.AR@mm worm is the latest variant of the Mytob virus. While the earlier Mytob virus was able to infect over 10 million computers, W32.Mytob.AR@mm only infected fewer than 100,000 computers. The lesser numbers of infected computers make this virus an easier target for removal. Unlike the earlier Mytob virus, the W32.Mytob.AR@mm worm does not propagate through email messages or PDF files. Why this is a dangerous virus The W32.Mytob.AR@mm worm may change the settings of the Windows Fax/Modem service to send faxes and send advertising to send emails to the web addresses listed in the worm’s host file. We do not recommend that you delete the Fax/Modem service. Deleting this service could prevent you from sending important faxes. An infected computer could redirect all of its requests for web pages to the web page: Therefore, if your computer forwards all of its requests to the infected computer, it could become infected with the W32.Mytob.AR@mm worm. Note: The W32.Mytob.AR@mm worm’s Web address, is based on a variation of the Microsoft Windows operating system. This is a poorly chosen location for a malicious site. Characteristics of W32.Mytob.AR@mm: ■ W32.Mytob.AR@mm is a dynamic-link library (.dll) file. ■ W32.Mytob.AR@mm was detected in 2003, June, and November. ■ W32.Mytob.AR@mm is written in Java. ■ W32.Myt

