The W32/Whybo.worm virus will infect any available network share as well as removable device with a copy of itself renamed "setup.exe" and an "Autorun.inf."

It will also download and install on infected systems additional Trojan components from the web.

Upon execution it will kill any instance of the "Task Manager" as well as other process monitoring utility.


The worm copies itself as "C:\WINDOWS\SYSTEM32\IME/svchost.exe" and will also create copies as:

  • C:\WINDOWS\SYSTEM32\internt.exe
  • C:\WINDOWS\SYSTEM32\progmon.exe
  • More information can be found at this McAfee page.