Tillbaka till svenska Fidonet
English   Information   Debug  
TRAPDOOR   0/19
TREK   0/755
TUB   0/290
UFO   0/40
UNIX   0/1316
USA_EURLINK   0/102
USR_MODEMS   0/1
VATICAN   0/2740
VIETNAM_VETS   0/14
VIRUS   0/378
VIRUS_INFO   0/201
VISUAL_BASIC   0/473
WHITEHOUSE   0/5187
WIN2000   0/101
WIN32   0/30
WIN95   0/4289
WIN95_OLD1   0/70272
WINDOWS   0/1517
WWB_SYSOP   0/419
WWB_TECH   0/810
ZCC-PUBLIC   0/1
ZEC   4

 
4DOS   0/134
ABORTION   0/7
ALASKA_CHAT   0/506
ALLFIX_FILE   0/1313
ALLFIX_FILE_OLD1   0/7997
ALT_DOS   0/152
AMATEUR_RADIO   0/1039
AMIGASALE   0/14
AMIGA   0/331
AMIGA_INT   0/1
AMIGA_PROG   0/20
AMIGA_SYSOP   0/26
ANIME   0/15
ARGUS   0/924
ASCII_ART   0/340
ASIAN_LINK   0/651
ASTRONOMY   0/417
AUDIO   0/92
AUTOMOBILE_RACING   0/105
BABYLON5   0/17862
BAG   135
BATPOWER   0/361
BBBS.ENGLISH   0/382
BBSLAW   0/109
BBS_ADS   0/5290
BBS_INTERNET   0/507
BIBLE   0/3563
BINKD   0/1119
BINKLEY   0/215
BLUEWAVE   0/2173
CABLE_MODEMS   0/25
CBM   0/46
CDRECORD   0/66
CDROM   0/20
CLASSIC_COMPUTER   0/378
COMICS   0/15
CONSPRCY   0/899
COOKING   33421
COOKING_OLD1   0/24719
COOKING_OLD2   0/40862
COOKING_OLD3   0/37489
COOKING_OLD4   0/35496
COOKING_OLD5   9370
C_ECHO   0/189
C_PLUSPLUS   0/31
DIRTY_DOZEN   0/201
DOORGAMES   0/2065
DOS_INTERNET   0/196
duplikat   6002
ECHOLIST   0/18295
EC_SUPPORT   0/318
ELECTRONICS   0/359
ELEKTRONIK.GER   1534
ENET.LINGUISTIC   0/13
ENET.POLITICS   0/4
ENET.SOFT   0/11701
ENET.SYSOP   33945
ENET.TALKS   0/32
ENGLISH_TUTOR   0/2000
EVOLUTION   0/1335
FDECHO   0/217
FDN_ANNOUNCE   0/7068
FIDONEWS   24159
FIDONEWS_OLD1   0/49742
FIDONEWS_OLD2   0/35949
FIDONEWS_OLD3   0/30874
FIDONEWS_OLD4   0/37224
FIDO_SYSOP   12852
FIDO_UTIL   0/180
FILEFIND   0/209
FILEGATE   0/212
FILM   0/18
FNEWS_PUBLISH   4436
FN_SYSOP   41706
FN_SYSOP_OLD1   71952
FTP_FIDO   0/2
FTSC_PUBLIC   0/13613
FUNNY   0/4886
GENEALOGY.EUR   0/71
GET_INFO   105
GOLDED   0/408
HAM   0/16074
HOLYSMOKE   0/6791
HOT_SITES   0/1
HTMLEDIT   0/71
HUB203   466
HUB_100   264
HUB_400   39
HUMOR   0/29
IC   0/2851
INTERNET   0/424
INTERUSER   0/3
IP_CONNECT   719
JAMNNTPD   0/233
JAMTLAND   0/47
KATTY_KORNER   0/41
LAN   0/16
LINUX-USER   0/19
LINUXHELP   0/1155
LINUX   0/22112
LINUX_BBS   0/957
mail   18.68
mail_fore_ok   249
MENSA   0/341
MODERATOR   0/102
MONTE   0/992
MOSCOW_OKLAHOMA   0/1245
MUFFIN   0/783
MUSIC   0/321
N203_STAT   930
N203_SYSCHAT   313
NET203   321
NET204   69
NET_DEV   0/10
NORD.ADMIN   0/101
NORD.CHAT   0/2572
NORD.FIDONET   189
NORD.HARDWARE   0/28
NORD.KULTUR   0/114
NORD.PROG   0/32
NORD.SOFTWARE   0/88
NORD.TEKNIK   0/58
NORD   0/453
OCCULT_CHAT   0/93
OS2BBS   0/787
OS2DOSBBS   0/580
OS2HW   0/42
OS2INET   0/37
OS2LAN   0/134
OS2PROG   0/36
OS2REXX   0/113
OS2USER-L   207
OS2   0/4786
OSDEBATE   0/18996
PASCAL   0/490
PERL   0/457
PHP   0/45
POINTS   0/405
POLITICS   0/29554
POL_INC   0/14731
PSION   103
R20_ADMIN   1123
R20_AMATORRADIO   0/2
R20_BEST_OF_FIDONET   13
R20_CHAT   0/893
R20_DEPP   0/3
R20_DEV   399
R20_ECHO2   1379
R20_ECHOPRES   0/35
R20_ESTAT   0/719
R20_FIDONETPROG...
...RAM.MYPOINT
  0/2
R20_FIDONETPROGRAM   0/22
R20_FIDONET   0/248
R20_FILEFIND   0/24
R20_FILEFOUND   0/22
R20_HIFI   0/3
R20_INFO2   3249
R20_INTERNET   0/12940
R20_INTRESSE   0/60
R20_INTR_KOM   0/99
R20_KANDIDAT.CHAT   42
R20_KANDIDAT   28
R20_KOM_DEV   112
R20_KONTROLL   0/13300
R20_KORSET   0/18
R20_LOKALTRAFIK   0/24
R20_MODERATOR   0/1852
R20_NC   76
R20_NET200   245
R20_NETWORK.OTH...
...ERNETS
  0/13
R20_OPERATIVSYS...
...TEM.LINUX
  0/44
R20_PROGRAMVAROR   0/1
R20_REC2NEC   534
R20_SFOSM   0/341
R20_SF   0/108
R20_SPRAK.ENGLISH   0/1
R20_SQUISH   107
R20_TEST   2
R20_WORST_OF_FIDONET   12
RAR   0/9
RA_MULTI   106
RA_UTIL   0/162
REGCON.EUR   0/2056
REGCON   0/13
SCIENCE   0/1206
SF   0/239
SHAREWARE_SUPPORT   0/5146
SHAREWRE   0/14
SIMPSONS   0/169
STATS_OLD1   0/2539.065
STATS_OLD2   0/2530
STATS_OLD3   0/2395.095
STATS_OLD4   0/1692.25
SURVIVOR   0/495
SYSOPS_CORNER   0/3
SYSOP   0/84
TAGLINES   0/112
TEAMOS2   0/4530
TECH   0/2617
TEST.444   0/105
Möte VIRUS, 378 texter
 lista första sista föregående nästa
Text 245, 1424 rader
Skriven 2006-12-02 11:50:00 av KURT WISMER (1:123/140)
Ärende: News, December 2 2006
=============================
[cut-n-paste from sophos.com]

Name   W32/Rbot-FWY

Type  
    * Worm

How it spreads  
    * Network shares

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Drops more malware
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities

Prevalence (1-5) 2

Description
W32/Rbot-FWY is a worm for the Windows platform that include IRC 
Backdoor functionality.

W32/Rbot-FWY spreads to other computers by exploiting common buffer 
overflow vulnerabilities like SRVSVC(MS06-040) and via network shares 
protected by weak passwords.

W32/Rbot-FWY runs continuously in the background, providing a 
backdoor server which allows a remote intruder to gain access and 
control over the computer via IRC channels.

Advanced
W32/Rbot-FWY is a worm for the Windows platform that include IRC 
Backdoor functionality.

W32/Rbot-FWY spreads to other computers by exploiting common buffer 
overflow vulnerabilities like SRVSVC(MS06-040) and via network shares 
protected by weak passwords.

W32/Rbot-FWY runs continuously in the background, providing a 
backdoor server which allows a remote intruder to gain access and 
control over the computer via IRC channels.

When first run W32/Rbot-FWY copies itself to <System>\2x32.exe and 
creates the file \a.bat.

The file a.bat is detected as Troj/Batten-A.

The following registry entries are created to run 2x32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Numerical Xterm Agents
2x32.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Numerical Xterm Agents
2x32.exe

W32/Rbot-FWY sets the following registry entries, disabling the 
automatic
startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\wuauserv
Start
4

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4

Note: disabling autostart for the SharedAccess service deactivates the
Microsoft
Internet Connection Firewall (ICF).

Registry entries are set as follows:

HKCU\Software\Microsoft\OLE
Numerical Xterm Agents
2x32.exe

HKLM\SOFTWARE\Microsoft\Ole
EnableRemoteConnect
N

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
MaxConnectionsPer1_0Server
50

HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
MaxConnectionsPerServer
50

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1

Registry entries are created under:

HKCR\.key\





Name   Troj/NtRootK-AX

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
Troj/NtRootK-AX is a backdoor Trojan with rootkit functionality. When 
run Troj/NtRootK-AX creates a service with a name identical to the 
base filename of the Trojan file.

Troj/NtRootK-AX installs two drivers, xHide.sys and GxNdisHook.sys. 
The purpose of the drivers is to hide the presence of malicious 
files, registry entries and TCP ports used by malware.

Troj/NtRootK-AX provides the attacker with an interface for the 
remote control over the machine.





Name   W32/Stratio-BV

Type  
    * Worm

Affected operating systems  
    * Windows

Side effects  
    * Downloads code from the internet

Prevalence (1-5) 2

Description
W32/Stratio-BV is a worm for the Windows platform.

Advanced
W32/Stratio-BV is a worm for the Windows platform.

When run W32/Stratio-BV copies itself to <System>\<random 
filename>.exe. The file D.tmp is also created. This file can be 
safely deleted.

W32/Stratio-BV includes functionality to download, install and run 
new software.The downloaded file is currently detected as 
W32/Strati-Gen.





Name   Troj/Zlob-WQ

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Downloads code from the internet
    * Reduces system security

Prevalence (1-5) 2

Description
Troj/Zlob-WQ is a Trojan for the Windows platform.

Troj/Zlob-WQ includes functionality to access the internet and 
communicate with a remote server via HTTP.

Advanced
Troj/Zlob-WQ is a Trojan for the Windows platform.

Troj/Zlob-WQ includes functionality to access the internet and 
communicate with a remote server via HTTP.

Registry entries are created under:

HKCU\Software\Internet Security\





Name   Troj/Agent-DSF

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Prevalence (1-5) 2

Description
Troj/Agent-DSF is a Trojan for the Windows platform.

Troj/Agent-DSF includes functionality to access the internet and 
communicate
with a remote server via HTTP.

Advanced
Troj/Agent-DSF is a Trojan for the Windows platform.

Troj/Agent-DSF includes functionality to access the internet and 
communicate
with a remote server via HTTP.

When first run Troj/Agent-DSF copies itself to <Windows>\scvhost.exe 
and
creates the file <Windows>\mswinsck.ocx.

The file mswinsck.ocx is clean and can be deleted.

The following registry entries are created to run scvhost.exe on 
startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
run
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Active Setup\Installed
Components\(B1B5B0BF-A20B-A600-E040-F0F90BCC201C)
StubPath
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RUNSERVICES
Windows Update
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RUNSERVICES
msconfig
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RUNSERVICES
icq lite
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RUNSERVICES
Update Checker
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RUNSERVICES
AntiVir
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RUNSERVICES
(default)
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Update
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
msconfig
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
icq lite
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Update Checker
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
AntiVir
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
(default)
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Windows Update
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
msconfig
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
icq lite
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Update Checker
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
AntiVir
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
(default)
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Windows Update
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
msconfig
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
icq lite
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
Update Checker
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
AntiVir
<Windows>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
(default)
<Windows>\scvhost.exe

The following registry entry is changed to run scvhost.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe scvhost.exe

(the default value for this registry entry is "Explorer.exe" which 
causes the
Microsoft file <Windows>\Explorer.exe to be run on startup).

The file mswinsck.ocx is registered as a COM object, creating 
registry entries
under:

HKCR\CLSID\(248DD896-BB45-11CF-9ABC-0080C7E7B78D)
HKCR\CLSID\(248DD897-BB45-11CF-9ABC-0080C7E7B78D)
HKCR\Interface\(248DD892-BB45-11CF-9ABC-0080C7E7B78D)
HKCR\Interface\(248DD893-BB45-11CF-9ABC-0080C7E7B78D)
HKCR\MSWinsock.Winsock\
HKCR\MSWinsock.Winsock.1\
HKCR\TypeLib\(248DD890-BB45-11CF-9ABC-0080C7E7B78D)

The following registry entries are set, disabling the registry editor 
(regedit)
and the Windows task manager (taskmgr):

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableRegistryTools
1





Name   Troj/Dloadr-AQN

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Downloads code from the internet

Aliases  
    * Downloader-AAP
    * Win32/TrojanDownloader.Nurech.H

Prevalence (1-5) 2

Description
Troj/Dloadr-AQN is a Trojan for the Windows platform.

Troj/Dloadr-AQN includes functionality to access the internet and 
communicate with a remote server via HTTP.

Troj/Dloadr-AQN includes functionality to download, install and run 
new software.

Advanced
Troj/Dloadr-AQN is a Trojan for the Windows platform.

Troj/Dloadr-AQN includes functionality to access the internet and 
communicate with a remote server via HTTP.

Troj/Dloadr-AQN includes functionality to download, install and run 
new software.

Registry entries are created under:

HKCU\Software\unker\<ExecutableName>\main\





Name   W32/Stration-CD

Type  
    * Worm

How it spreads  
    * Email attachments

Affected operating systems  
    * Windows

Side effects  
    * Sends itself to email addresses found on the infected computer
    * Installs itself in the Registry

Aliases  
    * Email-Worm.Win32.Warezov.dq
    * W32/Stration@MM
    * Win32/Stration
    * W32.Stration@mm

Prevalence (1-5) 2

Description
W32/Stration-CD is a mass-mailing worm for the Windows platform.

Advanced
W32/Stration-CD is a mass-mailing worm for the Windows platform.

When W32/Stration-CD is installed the following files are created:

<Windows system folder>\brwconf.exe
<Windows system folder>\brwmgr32.dll
<Windows system folder>\brwperf.exe
<Windows system folder>\brwprf32.dll
<Windows system folder>\brwstat.dll
<Windows system folder>\confbrw.dll

The following registry entries are created to run code exported by 
brwmgr32.dll
on startup:

HKLM\SOFTWARE\Microsoft\Windows 
NT\CurrentVersion\Winlogon\Notify\brwmgr
DllName
brwmgr32.dll

HKLM\SOFTWARE\Microsoft\Windows 
NT\CurrentVersion\Winlogon\Notify\brwmgr
Impersonate
0

HKLM\SOFTWARE\Microsoft\Windows 
NT\CurrentVersion\Winlogon\Notify\brwmgr
Startup
WlxStartup





Name   W32/Looked-BA

Type  
    * Virus

How it spreads  
    * Network shares
    * Infected files

Affected operating systems  
    * Windows

Side effects  
    * Modifies data on the computer
    * Drops more malware
    * Downloads code from the internet
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Prevalence (1-5) 2

Description
W32/Looked-BA is a virus.

W32/Looked-BA infects EXE files found on the infected computer and 
attempts to spread to remote network shares with weak passwords.

Advanced
W32/Looked-BA is a virus.

W32/Looked-BA infects EXE files found on the infected computer and 
attempts to spread to remote network shares with weak passwords.

The virus includes functionality to access the internet and 
communicate with a remote server via HTTP.

When run W32/Looked-BA copies itself to <Windows>\rundl132.exe and 
creates the file <Windows>\Dll.dll, which is detected as W32/Looked-AP.

Many files with the name "_desktop.ini" are also created, in various 
folders on the infected computer. These files are harmless text files.

The following registry entry is created to run rundl132.exe on startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
load
<Windows>\rundl132.exe

Registry entries are created under:

HKLM\SOFTWARE\Soft\DownloadWWW\





Name   Troj/Zlob-WT

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Downloads code from the internet

Prevalence (1-5) 2

Description
Troj/Zlob-WT is a downloader Trojan for the Windows platform.

Advanced
Troj/Zlob-WT is a downloader Trojan for the Windows platform.

Registry entries are created under:
HKCU\Software\Internet Security

The folder <Program Files>\Brain Codec may also be created.





Name   W32/RJump-H

Type  
    * Spyware Worm

How it spreads  
    * Network shares

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
W32/RJump-H is a worm for the Windows platform.

W32/RJump-H spreads by coping itself to the available mapped drives 
and creating create an "autorun.inf" file which will attempt to load 
the worm automatically when the infected drive is accessed.

W32/RJump-H also creates a backdoor, enabling a remote user control 
over the infected computer.

Advanced
W32/RJump-H is a worm for the Windows platform.

W32/RJump-H spreads by coping itself to the available mapped drives 
and creating create an "autorun.inf" file which will attempt to load 
the worm automatically when the infected drive is accessed.

W32/RJump-H also creates a backdoor, enabling a remote user control 
over the infected computer.

W32/RJump-H may copy itself to the following filename:

<Windows>\RavMonE.exe

When installed, W32/RJump-H may create the following registry entry, 
enabling it to run automatically on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
RavAV
<Windows>\RavMonE.exe





Name   W32/Sohana-B

Type  
    * Worm

How it spreads  
    * Chat programs

Affected operating systems  
    * Windows

Side effects  
    * Turns off anti-virus applications
    * Downloads code from the internet
    * Installs itself in the Registry

Aliases  
    * IM-Worm.Win32.Sohanad.e
    * W32/YahLover.worm

Prevalence (1-5) 2

Description
W32/Sohana-B is a worm for the Windows platform.

W32/Sohana-B may attempt to spread via instant messaging clients.

W32/Sohana-B includes functionality to download, install and run new 
software.

Advanced
W32/Sohana-B is a worm for the Windows platform.

W32/Sohana-B may attempt to spread via instant messaging clients.

W32/Sohana-B includes functionality to download, install and run new 
software.

When W32/Sohana-B is installed the following files are created:

<Windows system folder>\svchost32.exe
<Windows system folder>\svhost.exe

The following registry entries are created to run svchost32.exe and 
svhost.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Task Manager
<Windows system folder>\svchost32.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SVCHOST
<Windows system folder>\svhost.exe

W32/Sohana-B changes the Start Page for Microsoft Internet Explorer 
by setting the registry entry:

HKCU\Software\Microsoft\Internet Explorer\Main\Start Page

The following registry entries are set, disabling the registry editor 
(regedit) and the Windows task manager (taskmgr):

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

Registry entries are set as follows:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NoRun
1

HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel
Homepage
1

Registry entries are created under the following that help the worm 
spread via Yahoo Messenger :

HKCU\Software\Yahoo\Pager\View\YMSGR_Launchcast\
HKCU\Software\Yahoo\Pager\View\YMSGR_buzz\





Name   W32/Newurg-A

Type  
    * Worm

How it spreads  
    * Email attachments

Affected operating systems  
    * Windows

Side effects  
    * Sends itself to email addresses found on the infected computer
    * Drops more malware
    * Forges the sender's email address
    * Uses its own emailing engine
    * Downloads code from the internet
    * Reduces system security
    * Installs itself in the Registry

Aliases  
    * Trojan-Downloader.Win32.Small.dam

Prevalence (1-5) 2

Description
W32/Newurg-A is a worm for the Windows platform.

W32/Newurg-A includes functionality to access the internet and 
communicate with a remote server via HTTP.

Advanced
W32/Newurg-A is a worm for the Windows platform.

W32/Newurg-A includes functionality to access the internet and 
communicate with a remote server via HTTP.

When first run W32/Newurg-A copies itself to <System>\<worm 
filename>.exe and creates the file <current folder>\<random 
characters>.exe.

The file <current folder>\<random characters>.exe is detected as 
Troj/Dloadr-AQQ.

The following registry entries are created to run nordsys.exe on 
startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Nord
<System>\<worm filename>.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Nord
<System>\<worm filename>.exe

W32/Newurg-A sets the following registry entries, disabling the 
automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4

Note: disabling autostart for the SharedAccess service deactivates 
the Microsoft Internet Connection Firewall (ICF).





Name   W32/Stratio-CF

Type  
    * Worm

How it spreads  
    * Email attachments

Affected operating systems  
    * Windows

Side effects  
    * Drops more malware

Prevalence (1-5) 2

Description
W32/Stratio-CF is a worm for the Windows platform.

When run W32/Stratio-CF creates a file with a random filename in the 
Windows System folder. This file is currently detected as 
W32/Strati-Gen.





Name   Troj/Dloadr-AQS

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Steals information
    * Downloads code from the internet
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Prevalence (1-5) 2

Description
Troj/Dloadr-AQS is a downloader Trojan for the Windows platform.

Advanced
Troj/Dloadr-AQS is a downloader Trojan for the Windows platform.

Troj/Dloadr-AQS may create the following filename:

<Temp>\gkjnr.conf - this may be deleted

When first run Troj/Dloadr-AQS may inject code into "services.exe" 
and set the following registry entry:

Software\Microsoft\Windows\CurrentVersion\Run
WinUpdate
<original path to Trojan>





Name   Troj/Bckdr-PQP

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Steals information
    * Installs itself in the Registry
    * Used in DOS attacks
    * Leaves non-infected files on computer

Aliases  
    * Backdoor.Win32.Delf.we
    * Backdoor.Win32.Agent.fs

Prevalence (1-5) 2

Description
Troj/Bckdr-PQP is a backdoor Trojan for the Windows platform.

Advanced
Troj/Bckdr-PQP is a backdoor Trojan for the Windows platform.

When first run Troj/Bckdr-PQP copies itself to <System>\msvce.exe and 
creates the following files:

<System>\Deleteme.bat
<System>\dllhosts.dll

The file <System>\dllhosts.dll is also detected as Troj/Bckdr-PQP. 
The Trojan inserts this file into Iexplore.exe process space.
The file <System>\Deleteme.bat is a batch script that contains 
instructions to delete the Trojan host once it is installed. This 
file may be safely deleted.

The following registry entry is changed to run msvce.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe <System>\msvce.exe

(the default value for this registry entry is "Explorer.exe" which 
causes the Microsoft file <Windows>\Explorer.exe to be run on startup).





Name   W32/Bagle-QS

Type  
    * Worm

How it spreads  
    * Email attachments

Affected operating systems  
    * Windows

Side effects  
    * Turns off anti-virus applications
    * Sends itself to email addresses found on the infected computer
    * Forges the sender's email address
    * Uses its own emailing engine
    * Downloads code from the internet

Prevalence (1-5) 2

Description
W32/Bagle-QS is a worm for the Windows platform.

W32/Bagle-QS emails itself in an encrypted zip file to addresses 
found on the users computer.

Emails sent by the worm have the following characteristics:

Subject line chosen from:
new <date>
price<date>
price_ <date>
price_new <date>

Message text chosen from:

It Is Protected
Passwrd:

thank you !!!
Passwrd:

New year's discounts
Passwrd:

The attached file is named:
new_price<date>.zip
price_list<date>.zip
latest_price<date>.zip

<date> is the date the email was sent in the following format 
30-Nov-2006.

The zip file is detected as W32/Bagle-Zip.

Advanced
W32/Bagle-QS is a worm for the Windows platform.

W32/Bagle-QS emails itself in an encrypted zip file to addresses 
found on the users computer.

Emails sent by the worm have the following characteristics:

Subject line chosen from:
new <date>
price<date>
price_ <date>
price_new <date>

Message text chosen from:

It Is Protected
Passwrd:

thank you !!!
Passwrd:

New year's discounts
Passwrd:

The attached file is named:
new_price<date>.zip
price_list<date>.zip
latest_price<date>.zip

<date> is the date the email was sent in the following format 
30-Nov-2006.

The zip file is detected as W32/Bagle-Zip.

The zip file is password protected with a 6 digit password which is 
embedded in the email as an image.

When first run W32/Bagle-QS copies itself to:

<User>\Application Data\hidn\hidn2.exe
<User>\Application Data\hidn\hldrrr.exe

W32/Bagle-QS attempts to disable anti-virus and security software and 
contains functionality to download and run further software.





Name   W32/Stratio-CF

Type  
    * Worm

How it spreads  
    * Email attachments

Affected operating systems  
    * Windows

Side effects  
    * Drops more malware

Prevalence (1-5) 2

Description
W32/Stratio-CF is a worm for the Windows platform.

When run W32/Stratio-CF creates a file with a random filename in the 
Windows System folder. This file is currently detected as 
W32/Strati-Gen.





Name   W32/Looked-BB

Type  
    * Virus

How it spreads  
    * Infected files

Affected operating systems  
    * Windows

Side effects  
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
W32/Looked-BB is a prepending virus and worm for the Windows platform.

Advanced
W32/Looked-BB is a prepending virus and worm for the Windows platform.

W32/Looked-BB spreads to other network computers.

W32/Looked-BB includes functionality to access the internet and 
communicate with a remote server via HTTP. W32/Looked-BB may attempt 
to download and execute additional files from a remote location.

When first run W32/Looked-BB copies itself to 
<Windows>\uninstall\rundl132.exe and creates the file 
<Windows>\RichDll.dll. The file RichDll.dll is also detected as 
W32/Looked-BB.

W32/Looked-BB may also create many files with the name "_desktop.ini" 
are created, in various folders on the infected computer. These files 
are harmless text files and can be deleted.

The following registry entry is created to run rundl132.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
load
<Windows>\uninstall\rundl132.exe

Registry entries are created under:

HKLM\SOFTWARE\Soft\DownloadWWW\





Name   Troj/QQRob-ABD

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Turns off anti-virus applications
    * Steals information
    * Uses its own emailing engine
    * Reduces system security
    * Records keystrokes
    * Installs itself in the Registry

Aliases  
    * Trojan-PSW.Win32.QQRob.il
    * BackDoor-AWQ

Prevalence (1-5) 2

Description
Troj/QQRob-ABD is a password stealing Trojan for the Windows platform.

Troj/QQRob-ABD includes functionality to

- send notification messages to remote locations.
- terminate processes related to anti-virus software.

Advanced
Troj/QQRob-ABD is a password stealing Trojan for the Windows platform.

Troj/QQRob-ABD includes functionality to

- send notification messages to remote locations.
- terminate processes related to anti-virus software.

When first run Troj/QQRob-ABD copies itself to:

<Common Files>\Microsoft Shared\msinfo\<filename>.dat
<Windows>\help\wshmcepts.chm

and creates the file <Common Files>\Microsoft 
Shared\msinfo\<filename>.dll

where <filename> is a random 8-character string. This file is also 
detected as Troj/QQRob-ABD.

The file <filename>.dll is registered as a COM object and 
ShellExecute hook,
creating registry entries under:

HKCR\CLSID\<CLSID>

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
ShellExecuteHooks
<CLSID>





Name   W32/Bagle-QT

Type  
    * Worm

How it spreads  
    * Email attachments

Affected operating systems  
    * Windows

Side effects  
    * Turns off anti-virus applications
    * Sends itself to email addresses found on the infected computer
    * Forges the sender's email address
    * Uses its own emailing engine
    * Downloads code from the internet
    * Reduces system security
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Aliases  
    * Win32/Bagle
    * Bloodhound.Beagle

Prevalence (1-5) 2

Description
W32/Bagle-QT is an email worm for the Windows platform.

W32/Bagle-QT emails itself in an encrypted zip file to addresses 
found on the users computer.

Emails sent by the worm have the following characteristics:

Subject line chosen from:
new <date>
price<date>
price_ <date>
price_new <date>

Message text chosen from:

It Is Protected
Passwrd:

thank you !!!
Passwrd:

New year's discounts
Passwrd:

The attached file is named:
new_price<date>.zip
price_list<date>.zip
latest_price<date>.zip

<date> is the date the email was sent in the following format 
01-Dec-2006.

Advanced
W32/Bagle-QT is an email worm for the Windows platform.

W32/Bagle-QT emails itself in an encrypted zip file to addresses 
found on the user's computer.

Emails sent by the worm have the following characteristics:

Subject line chosen from:

new <date>
price<date>
price_ <date>
price_new <date>

Message text chosen from:

It Is Protected
Passwrd:

thank you !!!
Passwrd:

New year's discounts
Passwrd:

The attached file is named:
new_price<date>.zip
price_list<date>.zip
latest_price<date>.zip

<date> is the date the email was sent in the following format 
01-Dec-2006.

The zip file is detected as W32/Bagle-Zip.

The zip file is password protected with a 6 digit password which is 
embedded in the email as an image. The image file displays a 5 digit 
password.

W32/Bagle-QT copies itself to the hidden file <Application 
Data>\hidn\hidn.exe and drops the hidden file <Application 
Data>\hidn\m_hook.sys, also detected as W32/Bagle-QT, which it uses 
to stealth itself from certain processes including AV applications.
The file <Application Data>\hidn\m_hook.sys is registered as a new 
system driver service named "m_hook". Registry entries are created 
under:

HKLM\SYSTEM\CurrentControlSet\Services\m_hook\

W32/Bagle-QT attempts to terminate and disable a number of services 
related to security and anti-virus applications.

The first time it is run, W32/Bagle-QT drops the clean file 
C:\error.gif and opens it. This is an image of the word "Error".

W32/Bagle-QT drops the file C:\temp.zip which contains an encrypted 
zip of itself.

W32/Bagle-QT attempts to download a file from a number of remote 
websites to <System>\re_file.exe and then execute it.

W32/Bagle-QT attempts to delete the following registry entry in order 
to disrupt booting into Safe Mode:

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot

W32/Bagle-QT creates the following registry entry the first time it 
is run:

HKCU\Software\FirstRu<xx>n
FirstRun
1

where <xx> will vary.





Name   W32/Poebot-JD

Type  
    * Worm

How it spreads  
    * Network shares

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities

Aliases  
    * Backdoor.Win32.PoeBot.j
    * W32/Poebot.BO@bd

Prevalence (1-5) 2

Description
W32/Poebot-JD is a worm with IRC Backdoor functionality for the 
Windows platform.

W32/Poebot-JD spreads
- to computers vulnerable to common exploits, including: LSASS 
(MS04-011), RPC-DCOM (MS04-012), WKS (MS03-049), Dameware 
(CAN-2003-1030) and PNP (MS05-039)
- to network shares protected by weak passwords

W32/Poebot-JD runs continuously in the background, providing a 
backdoor server which allows a remote intruder to gain access and 
control over the computer via IRC channels.

Advanced
W32/Poebot-JD is a worm with IRC Backdoor functionality for the 
Windows platform.

W32/Poebot-JD spreads
- to computers vulnerable to common exploits, including: LSASS 
(MS04-011), RPC-DCOM (MS04-012), WKS (MS03-049), Dameware 
(CAN-2003-1030) and PNP (MS05-039)
- to network shares protected by weak passwords

W32/Poebot-JD runs continuously in the background, providing a 
backdoor server which allows a remote intruder to gain access and 
control over the computer via IRC channels.

When first run W32/Poebot-JD copies itself to \explorer.exe.

The following registry entry is created to run W32/Poebot-JD on 
startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Windows Explorer
<System>\explorer.exe





Name   W32/Pardona-C

Type  
    * Virus

How it spreads  
    * Email messages
    * Infected files

Affected operating systems  
    * Windows

Side effects  
    * Drops more malware
    * Uses its own emailing engine
    * Downloads code from the internet

Prevalence (1-5) 2

Description
W32/Pardona-C is a virus for the Windows platform.

The virus attempts to infect EXE files, and to modify HTM and ASP 
files so that they silently download from a remote webiste.

W32/Pardona-C may spread to other network computers and may also 
spread via email.

W32/Pardona-C also includes functionality to download, install and 
run new software.

W32/Pardona-C installs a rootkit detected as Troj/Pardot-B.

Infected HTM and ASP files are detected as Troj/Psyme-DO.

Advanced
W32/Pardona-C is a virus for the Windows platform.

The virus attempts to infect EXE files, and to modify HTM and ASP 
files so that they silently download from a remote webiste.

W32/Pardona-C may spread to other network computers and may also 
spread via email.

W32/Pardona-C also includes functionality to download, install and 
run new software.

When first run W32/Pardona-C copies itself to \ePower.exe and to 
several files of the form

\

Each of these files is either identical to, or slight variants of, 
the original file. All will be detected as W32/Pardona-C.

The virus also creates the file C:\WINDOWS\System32\<random 
letters>.sys

This SYS file is registered as a new system driver service named 
"SysDrver", with a display name of "System SSDP Services".

Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\SysDrver\

The SYS file, which is detected as Troj/Pardot-B, uses stealth 
functionality to hide processes created by W32/Pardona-C.

Infected HTM and ASP files are detected as Troj/Psyme-DO.

 
--- MultiMail/Win32 v0.43
 * Origin: Try Our Web Based QWK: DOCSPLACE.ORG (1:123/140)