Tillbaka till svenska Fidonet
English   Information   Debug  
TREK   0/755
TUB   0/290
UFO   0/40
UNIX   0/1316
USA_EURLINK   0/102
USR_MODEMS   0/1
VATICAN   0/2740
VIETNAM_VETS   0/14
VIRUS   0/378
VIRUS_INFO   0/201
VISUAL_BASIC   0/473
WHITEHOUSE   0/5187
WIN2000   0/101
WIN32   0/30
WIN95   0/4288
WIN95_OLD1   0/70272
WINDOWS   0/1517
WWB_SYSOP   0/419
WWB_TECH   0/810
ZCC-PUBLIC   0/1
ZEC   4

 
4DOS   0/134
ABORTION   0/7
ALASKA_CHAT   0/506
ALLFIX_FILE   0/1313
ALLFIX_FILE_OLD1   0/7997
ALT_DOS   0/152
AMATEUR_RADIO   0/1039
AMIGASALE   0/14
AMIGA   0/331
AMIGA_INT   0/1
AMIGA_PROG   0/20
AMIGA_SYSOP   0/26
ANIME   0/15
ARGUS   0/924
ASCII_ART   0/340
ASIAN_LINK   0/651
ASTRONOMY   0/417
AUDIO   0/92
AUTOMOBILE_RACING   0/105
BABYLON5   0/17862
BAG   135
BATPOWER   0/361
BBBS.ENGLISH   0/382
BBSLAW   0/109
BBS_ADS   0/5290
BBS_INTERNET   0/507
BIBLE   0/3563
BINKD   0/1119
BINKLEY   0/215
BLUEWAVE   0/2173
CABLE_MODEMS   0/25
CBM   0/46
CDRECORD   0/66
CDROM   0/20
CLASSIC_COMPUTER   0/378
COMICS   0/15
CONSPRCY   0/899
COOKING   32896
COOKING_OLD1   0/24719
COOKING_OLD2   0/40862
COOKING_OLD3   0/37489
COOKING_OLD4   0/35496
COOKING_OLD5   9370
C_ECHO   0/189
C_PLUSPLUS   0/31
DIRTY_DOZEN   0/201
DOORGAMES   0/2056
DOS_INTERNET   0/196
duplikat   6002
ECHOLIST   0/18295
EC_SUPPORT   0/318
ELECTRONICS   0/359
ELEKTRONIK.GER   1534
ENET.LINGUISTIC   0/13
ENET.POLITICS   0/4
ENET.SOFT   0/11701
ENET.SYSOP   33903
ENET.TALKS   0/32
ENGLISH_TUTOR   0/2000
EVOLUTION   0/1335
FDECHO   0/217
FDN_ANNOUNCE   0/7068
FIDONEWS   24125
FIDONEWS_OLD1   0/49742
FIDONEWS_OLD2   0/35949
FIDONEWS_OLD3   0/30874
FIDONEWS_OLD4   0/37224
FIDO_SYSOP   12852
FIDO_UTIL   0/180
FILEFIND   0/209
FILEGATE   0/212
FILM   0/18
FNEWS_PUBLISH   4408
FN_SYSOP   41678
FN_SYSOP_OLD1   71952
FTP_FIDO   0/2
FTSC_PUBLIC   0/13599
FUNNY   0/4886
GENEALOGY.EUR   0/71
GET_INFO   105
GOLDED   0/408
HAM   0/16070
HOLYSMOKE   0/6791
HOT_SITES   0/1
HTMLEDIT   0/71
HUB203   466
HUB_100   264
HUB_400   39
HUMOR   0/29
IC   0/2851
INTERNET   0/424
INTERUSER   0/3
IP_CONNECT   719
JAMNNTPD   0/233
JAMTLAND   0/47
KATTY_KORNER   0/41
LAN   0/16
LINUX-USER   0/19
LINUXHELP   0/1155
LINUX   0/22092
LINUX_BBS   0/957
mail   18.68
mail_fore_ok   249
MENSA   0/341
MODERATOR   0/102
MONTE   0/992
MOSCOW_OKLAHOMA   0/1245
MUFFIN   0/783
MUSIC   0/321
N203_STAT   926
N203_SYSCHAT   313
NET203   321
NET204   69
NET_DEV   0/10
NORD.ADMIN   0/101
NORD.CHAT   0/2572
NORD.FIDONET   189
NORD.HARDWARE   0/28
NORD.KULTUR   0/114
NORD.PROG   0/32
NORD.SOFTWARE   0/88
NORD.TEKNIK   0/58
NORD   0/453
OCCULT_CHAT   0/93
OS2BBS   0/787
OS2DOSBBS   0/580
OS2HW   0/42
OS2INET   0/37
OS2LAN   0/134
OS2PROG   0/36
OS2REXX   0/113
OS2USER-L   207
OS2   0/4786
OSDEBATE   0/18996
PASCAL   0/490
PERL   0/457
PHP   0/45
POINTS   0/405
POLITICS   2346/29554
POL_INC   0/14731
PSION   103
R20_ADMIN   1121
R20_AMATORRADIO   0/2
R20_BEST_OF_FIDONET   13
R20_CHAT   0/893
R20_DEPP   0/3
R20_DEV   399
R20_ECHO2   1379
R20_ECHOPRES   0/35
R20_ESTAT   0/719
R20_FIDONETPROG...
...RAM.MYPOINT
  0/2
R20_FIDONETPROGRAM   0/22
R20_FIDONET   0/248
R20_FILEFIND   0/24
R20_FILEFOUND   0/22
R20_HIFI   0/3
R20_INFO2   3218
R20_INTERNET   0/12940
R20_INTRESSE   0/60
R20_INTR_KOM   0/99
R20_KANDIDAT.CHAT   42
R20_KANDIDAT   28
R20_KOM_DEV   112
R20_KONTROLL   0/13270
R20_KORSET   0/18
R20_LOKALTRAFIK   0/24
R20_MODERATOR   0/1852
R20_NC   76
R20_NET200   245
R20_NETWORK.OTH...
...ERNETS
  0/13
R20_OPERATIVSYS...
...TEM.LINUX
  0/44
R20_PROGRAMVAROR   0/1
R20_REC2NEC   534
R20_SFOSM   0/340
R20_SF   0/108
R20_SPRAK.ENGLISH   0/1
R20_SQUISH   107
R20_TEST   2
R20_WORST_OF_FIDONET   12
RAR   0/9
RA_MULTI   106
RA_UTIL   0/162
REGCON.EUR   0/2056
REGCON   0/13
SCIENCE   0/1206
SF   0/239
SHAREWARE_SUPPORT   0/5146
SHAREWRE   0/14
SIMPSONS   0/169
STATS_OLD1   0/2539.065
STATS_OLD2   0/2530
STATS_OLD3   0/2395.095
STATS_OLD4   0/1692.25
SURVIVOR   0/495
SYSOPS_CORNER   0/3
SYSOP   0/84
TAGLINES   0/112
TEAMOS2   0/4530
TECH   0/2617
TEST.444   0/105
TRAPDOOR   0/19
Möte VIRUS_INFO, 201 texter
 lista första sista föregående nästa
Text 197, 1533 rader
Skriven 2007-07-23 00:10:00 av KURT WISMER
Ärende: News, July 23 2007
==========================
[cut-n-paste from sophos.com]

Name   W32/Akbot-AS

Type  
    * Spyware Worm

How it spreads  
    * Network shares

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Reduces system security
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities

Prevalence (1-5) 2

Description
W32/Akbot-AS is a worm for the Windows platform.

W32/Akbot-AS spreads to other network computers infected with W32/Sasser and to
other network computers by exploiting common buffer overflow vulnerabilities,
including MS04-007.

Advanced
W32/Akbot-AS is a worm for the Windows platform.

W32/Akbot-AS spreads to other network computers infected with W32/Sasser and to
other network computers by exploiting common buffer overflow vulnerabilities,
including MS04-007.

When first run W32/Akbot-AS copies itself to <System>\sslms.exe.

The following registry entry is created to run code exported by sslms.exe on
startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
WinDll (sslms.exe)
rundll32.exe <System>\sslms.exe,start





Name   W32/Baysur-B

Type  
    * Worm

How it spreads  
    * Removable storage devices

Affected operating systems  
    * Windows

Side effects  
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Aliases  
    * Virus.Win32.VB.dg
    * Win32/VB.DG
    * WORM_VB.DTH

Prevalence (1-5) 2

Description
W32/Baysur-B is a worm for the Windows platform.

W32/Baysur-B attempts to spread to removable drives.

Advanced
W32/Baysur-B is a worm for the Windows platform.

W32/Baysur-B attempts to spread to removable drives.

When first run the worm attempts to copy itself to the following locations:

<Startup>\Adobe Online.com
<Startup>\Adobe Update.com

W32/Baysur-B attempts to copy itself using the names of existing files and
folders on the computer but with an SCR or COM extension, and sometimes with an
extra space in the filename.

W32/Baysur-B also attempts to drop some of the following files:

<Windows>\Thumbs .db
<Startup>\Autoexec.bat

The file Autoexec.bat attempts to display the following lines on startup,
before prompting for user input:

  81u3f4nt45y - 24.01.2007
  Don't kill me, i'm just send message from your computer
  Terima kasih telah menemaniku walaupun hanya sesaat, tapi bagiku sangat
berarti
  Maafkan jika kebahagiaan yang kuminta adalah teman sepanjang hidupku
  Seharusnya aku mengerti bahwa keberadaanku bukanlah disisimu, hanyalah
lamunan dalam sesal
  Untuk kekasih yang tak kan pernah kumiliki 3r1k1m0

W32/Baysur-B attempts to delete the following registry entry:

HKCR\scrfile
AlwaysShowExt

W32/Baysur-B attempts to set the following registry entries:

HKCR\scrfile
FileFolder
NULL

HKCR\scrfile
InfoTip
NULL

HKCR\scrfile
NeverShowExt
NULL

HKCR\scrfile
TileInfo
NULL

HKCR\scrfile\shell\open\command
default
%1

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
LegalNoticeCation
81u3f4nt45y - 24.01.2007 Surabaya

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
LegalNoticeText
"Surabaya in my birthday
Don't kill me, i'm just send message from your computer
Terima kasih telah menemaniku walaupun hanya sesaat, tapi bagiku sangat berarti
Maafkan jika kebahagiaan yang kuminta adalah teman sepanjang hidupku
Seharusnya aku mengerti bahwa keberadaanku bukanlah disisimu, hanyalah lamunan
dalam sesal
Untuk kekasih yang tak kan pernah kumiliki 3r1k1m0"

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\NOHIDDEN

CheckedValue
2

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\NOHIDDEN

DefaultValue
2

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\NOHIDORSYS

CheckedValue
0

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\NOHIDORSYS

DefaultValue
2

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL

CheckedValue
0

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHOWALL

DefaultValue
2

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\HideFileExt

CheckedValue
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\HideFileExt

DefaultValue
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\HideFileExt

UncheckedValue
1





Name   W32/Sohana-Y

Type  
    * Spyware Worm

How it spreads  
    * Removable storage devices
    * Network shares
    * Chat programs

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Reduces system security
    * Records keystrokes
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities

Aliases  
    * IM-Worm.Win32.Sohanad.am
    * WORM_SOHANAD.BO

Prevalence (1-5) 2

Description
W32/Sohana-Y is a worm for the Windows platform.

W32/Sohana-Y spreads through instant messaging applications, removable media
and network shares.

W32/Sohana-Y includes functionality to access the internet and communicate with
a remote server via HTTP.

Advanced
W32/Sohana-Y is a worm for the Windows platform.

W32/Sohana-Y spreads through instant messaging applications, removable media
and network shares.

W32/Sohana-Y includes functionality to access the internet and communicate with
a remote server via HTTP.

When first run W32/Sohana-Y copies itself to:

<Windows>\SSCVIIHOST.exe
<System>\SSCVIIHOST.exe
<System>\blastclnnn.exe

and creates the following files:

<System>\autorun.ini
<System>\setting.ini

The file autorun.ini is detected as Mal/AutoInf-A.

The following registry entry is created to run W32/Sohana-Y on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo Messengger
<System>\SSCVIIHOST.exe

The following registry entry is changed to run W32/Sohana-Y on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe SSCVIIHOST.exe

The following registry entries are set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NofolderOptions
1





Name   Troj/Hupigon-SL

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Downloads code from the internet
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
Troj/Hupigon-SL is a Trojan for the Windows platform.





Name   Troj/Riler-Y

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Drops more malware
    * Leaves non-infected files on computer

Prevalence (1-5) 2

Description
Troj/Riler-Y is a Trojan for the Windows platform.

Advanced
Troj/Riler-Y is a Trojan for the Windows platform.

When run Troj/Riler-Y creates the files:

<System>\toonjoke.dll - detected as Troj/Riler-Gen
<System>\feelcat.ini -can be safely removed

Troj/Riler-Y will install the file toonjoke.dll as a Windows Sockets 2
transport provider and reorder the WSC Chain such that it gets called first. As
a result, the Trojan may spy on the network traffic of applications.





Name   W32/Sdbot-DGJ

Type  
    * Worm

Affected operating systems  
    * Windows

Side effects  
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
W32/Sdbot-DGJ is a worm with backdoor functionality for the Windows platform.

Advanced
W32/Sdbot-DGJ is a worm with backdoor functionality for the Windows platform.

W32/Sdbot-DGJ includes functionality to access the internet and communicate
with a remote server via HTTP.

When first run W32/Sdbot-DGJ copies itself to:

<Windows>\nzbd.exe
<Program Files>\KaZaA\My Shared Folder\<filename.exe>

where <filename.exe> is the name of a file already found in that location.

The file nzbd.exe is registered as a new system driver service named "Windows
NZDB Service", with a display name of "Windows NZDB Service" and a startup type
of automatic, so that it is started automatically during system startup.
Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\Windows NZDB Service

The following registry entries are set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

W32/Sdbot-DGJ sets the following registry entries, disabling the automatic
startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\Messenger
Start
4

HKLM\SYSTEM\CurrentControlSet\Services\RemoteRegistry
Start
4

HKLM\SYSTEM\CurrentControlSet\Services\TlntSvr
Start
4

Registry entries are set as follows:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCScan
0

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall
0

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
EnableFirewall
0

HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
DoNotAllowXPSP2
1

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCDisable
ffffff9d

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe %WINDIR%\nzbd.exe

Registry entries are created under:

HKLM\SOFTWARE\Microsoft\Security Center
HKLM\SOFTWARE\Symantec\LiveUpdate Admin





Name   W32/Looked-DM

Type  
    * Virus

How it spreads  
    * Network shares
    * Infected files

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Downloads code from the internet
    * Installs itself in the Registry

Aliases  
    * Trojan-Dropper.Win32.Small.axi
    * Win32/Viking.DB
    * PE_LOOKED.ABM-O

Prevalence (1-5) 2

Description
W32/Looked-DM is a prepending virus and network worm for the Windows platform.

W32/Looked-DM spreads via file sharing on P2P networks.

W32/Looked-DM runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer.

W32/Looked-DM includes functionality to access the internet and communicate
with a remote server via HTTP.

Advanced
W32/Looked-DM is a prepending virus and network worm for the Windows platform.

W32/Looked-DM spreads via file sharing on P2P networks.

W32/Looked-DM runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer.

W32/Looked-DM includes functionality to access the internet and communicate
with a remote server via HTTP.

When W32/Looked-DM is installed the following files are created:

<Windows>\Logo1_.exe
<Windows>\RichDll.dll
<Windows>\uninstall\\rundl132.exe

These files are all detected as W32/Looked-DM.

W32/Looked-DM may also create many files with the name "_desktop.ini" in
various folders on the infected computer. These files are harmless text files
and can be deleted

The worm changes the following registry entry in order to be run automatically
on startup:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows\
load
<Windows>\uninstall\rundl132.exe

Registry entries are created under:

HKLM\SOFTWARE\Soft\DownloadWWW\





Name   W32/Poebot-MN

Type  
    * Spyware Worm

How it spreads  
    * Network shares

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities

Prevalence (1-5) 2

Description
W32/Poebot-MN is a worm with IRC backdoor functionality for the Windows
platform.

Advanced
W32/Poebot-MN is a worm with IRC backdoor functionality for the Windows
platform.

W32/Poebot-MN runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.

W32/Poebot-MN spreads to other network computers:
- by exploiting common buffer overflow vulnerabilities, including: LSASS
(MS04-011), SRVSVC (MS06-040), RPC-DCOM (MS04-012) and PNP (MS05-039)
- by networks protected by weak passwords

W32/Poebot-MN includes functionality to:

- download code from the internet
- steal information

When run W32/Poebot-MN copies itself to <System>\csrs.exe.

The following registry entry is set to run W32/Poebot-MN on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Client Server Runtime Process
<System>\csrs.exe





Name   Troj/PSW-EF

Type  
    * Spyware Trojan

Affected operating systems  
    * Windows

Side effects  
    * Steals information
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
Troj/PSW-EF is a Trojan for the Windows platform.

Advanced
Troj/PSW-EF is a Trojan for the Windows platform.

When run Troj/PSW-EF copies itself to <System>\shareb.exe and creates the file
<Windows>\shareb32.dll. The file <Windows>\shareb32.dll is also detected as
Troj/PSW-EF.

Troj/PSW-EF installs the DLL as a Browser Helper Object creating the following
registry entries:

HKCR\CLSID\(FBF3B337-FEB6-403B-BBE2-2B67CB6563E3)

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
(FBF3B337-FEB6-403B-BBE2-2B67CB6563E3)





Name   W32/Loadme-A

Type  
    * Virus

Affected operating systems  
    * Windows

Side effects  
    * Modifies data on the computer
    * Deletes files off the computer
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
W32/Loadme-A is a virus for the Windows platform.

Advanced
W32/Loadme-A is a virus for the Windows platform.

W32/Loadme-A will replace files found on the system with copies of itself.





Name   W32/Tilebot-KB

Type  
    * Worm

How it spreads  
    * Network shares
    * Peer-to-peer

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Downloads code from the internet
    * Reduces system security
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities

Aliases  
    * Backdoor.Win32.SdBot.bhk
    * WORM_SDBOT.FCZ

Prevalence (1-5) 2

Description
W32/Tilebot-KB is a worm for the Windows platform.

W32/Tilebot-KB spreads via network shares and P2P applications.

W32/Tilebot-KB includes functionality to access the internet and communicate to
a remote server via HTTP.

Advanced
W32/Tilebot-KB is a worm for the Windows platform.

W32/Tilebot-KB spreads via network shares and P2P applications.

W32/Tilebot-KB includes functionality to access the internet and communicate to
a remote server via HTTP.

When first run W32/Tilebot-KB copies itself to <Windows>\netserv.exe.

W32/Tilebot-KB registers itself as a new system driver service named "Windows
.NET Service" with a display name of "Windows .NET Service" and a startup type
of automatic, so that it is started automatically during system startup.
Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\Windows .NET Service\

W32/Tilebot-KB may replace the contents of these files to render them useless:

<System>\tftp.exe
<System>\ftp.exe

if so a backup of these files may be found here:

<System>\Microsoft\backup.ftp (originally ftp.exe)
<System>\Microsoft\backup.tftp (originally tftp.exe)

W32/Tilebot-KB modifies the number of outbound TCP connections by patching:

<System>\drivers\tcpip.sys

W32/Tilebot-KB sets the following registry entries to reduce system security:

HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
DoNotAllowXPSP2
1

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
EnableFirewall
0

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall
0

HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SOFTWARE\Microsoft\Security Center
AntiVirusOverride
1

HKLM\SOFTWARE\Microsoft\Security Center
FirewallOverride
1

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe <Windows>\netserv.exe

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1





Name   Troj/DropRk-A

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Drops more malware
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
Troj/DropRk-A is a rootkit dropper Trojan for the Windows platform.

Advanced
Troj/DropRk-A is a rootkit dropper Trojan for the Windows platform.

When run Troj/DropRk-A copies itself to <Temp>\startdrv.exe and creates the
file <System>\drivers\runtime2.sys. The file runtime2.sys is detected as
Troj/Rootkit-BI.

Troj/DropRk-A then installs the rootkit runtim2.sys with a service name of
"runtime2" and a description of "runtime2" with a startup type of automatic.
Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_RUNTIME2\
HKLM\SYSTEM\CurrentControlSet\Services\runtime2

The following registry entry is created to run startdrv.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
startdrv
<Temp>\startdrv.exe





Name   Troj/Zapchas-DN

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Leaves non-infected files on computer

Prevalence (1-5) 2

Description
Troj/Zapchas-DN is a mIRC-based backdoor Trojan for the Windows platform.

Advanced
Troj/Zapchas-DN is a mIRC-based backdoor Trojan for the Windows platform.

When first run, Troj/Zapchas-DN creates the following files in
<System>\ShellExt:

greet.ini
aliases.ini
away.txt
channels.txt
conn.ini
control.ini
czvhost.exe
engine.ini
flood.txt
fullname.txt
add.txt
ident.txt
injuraturi.txt
IRC.ICO
kick.txt
mirc.ini
nick.txt
operator.ini
partmsg.ini
perform.ini
remote.ini
scr.ini
servers.ini
updater.ini

czvhost.exe is the legitimate mIRC IRC application. operator.ini and scr.ini
are also detected as Troj/Zapchas-DN. The remaining files are harmless and can
be deleted safely.

Troj/Zapchas-DN allows a remote user to control the infected computer via IRC
channels.





Name   W32/Rubble-A

Type  
    * Worm

How it spreads  
    * Removable storage devices

Affected operating systems  
    * Windows

Side effects  
    * Deletes files off the computer
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
W32/Rubble-A is a worm for the Windows platform.

Advanced
W32/Rubble-A is a worm for the Windows platform.

When first run W32/Rubble-A copies itself to:

<System>\win32.exe

The following registry entry is created to run win32.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Load
<System>\win32.exe

W32/Rubble-A attempts to spread by scanning local drives, including removable
drives, and replacing any files found with itself, using the same name (with an
EXE extension). W32/Rubble-A thus deletes the files it replaces. In overwriting
important system files, W32/Rubble-A may also prevent a computer from rebooting
once infected.





Name   W32/Sdbot-DGM

Type  
    * Spyware Worm

How it spreads  
    * Network shares

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities
    * Leaves non-infected files on computer

Prevalence (1-5) 2

Description
W32/Sdbot-DGM is a worm with IRC backdoor functionality for the Windows
platform.

Advanced
W32/Sdbot-DGM is a worm with IRC backdoor functionality for the Windows
platform.

W32/Sdbot-DGM runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.

W32/Sdbot-DGM spreads to other network computers:
- by exploiting common buffer over flow vulnerabilities, including: ASN.1
(MS04-007)
- by networks protected by weak passwords

W32/Sdbot-DGM includes functionality to:

- download code from the internet
- steal information

When run W32/Sdbot-DGM copies itself to <Windows>\MSTask.exe. W32/Sdbot-DGM
also creates the file <System>\trash1B9F4 which is not malicious and can be
safely removed.

W32/Sdbot-DGM also creates the file <System>\sfc_os.dll which is detected as
"Disabled System File Check DLL"

W32/Sdbot-DGM overwrites the files <System>\ftp.exe, <System>\tftp.exe with
non-malicious dummy files. These files can be safely removed.

W32/Sdbot-DGM registers the file <Windows>\MSTask.exe as a service with a
service name of "Windows Task Scheduler process", a description of "Windows
Task Scheduler process" and a startup type of automatic. Registry entries are
created under:

HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WINDOWS_TASK_SCHEDULER_PROCESS\
HKLM\SYSTEM\CurrentControlSet\Services\Windows Task Scheduler process\

The following registry entries are set:

HKLM\SOFTWARE\Microsoft\Security Center
AntiVirusDisableNotify
1

HKLM\SOFTWARE\Microsoft\Security Center
AntiVirusOverride
1

HKLM\SOFTWARE\Microsoft\Security Center
FirewallDisableNotify
1

HKLM\SOFTWARE\Microsoft\Security Center
FirewallOverride
1

HKLM\SOFTWARE\Microsoft\Security Center
UpdatesDisableNotify
1

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
SFCScan
0

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile
EnableFirewall
0

HKLM\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile
EnableFirewall
0

HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate
DoNotAllowXPSP2
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Enterprise Security Manager
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Ghost
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Intruder Alert
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
LiveAdvisor
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
LiveUpdate
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
NetRecon
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton AntiVirus Product Updates
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton AntiVirus Virus Definitions
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton CleanSweep
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton Commander
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton Internet Security
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton SystemWorks
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Norton Utilities
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
PC Handyman and HealthyPC
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Rescue Disk
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
SymEvent
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Symantec Desktop Firewall
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
Symantec Gateway Security IDS
1

HKLM\SOFTWARE\Symantec\LiveUpdate Admin
pcANYWHERE
1

HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters
AutoShareServer
0

HKLM\SYSTEM\CurrentControlSet\Services\lanmanserver\parameters
AutoShareWks
0

HKLM\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters
AutoShareServer
0

HKLM\SYSTEM\CurrentControlSet\Services\lanmanworkstation\parameters
AutoShareWks
0

HKLM\SYSTEM\CurrentControlSet\Services\wscsvc
Start
4





Name   W32/SillyFDC-AN

Type  
    * Worm

How it spreads  
    * Removable storage devices

Affected operating systems  
    * Windows

Side effects  
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
W32/SillyFDC-AN is a worm for the Windows platform.

Advanced
W32/SillyFDC-AN is a worm for the Windows platform.

Once installed W32/SillyFDC-AN will copy itself to <System>\systeminit.exe.

W32/SillyFDC-AN spreads via removable shared drives by creating the file
autorun.inf and a copy of the worm to setup.exe on the removable drive. The
file autorun.inf is subsequently set to run the worm component upon connecting
the removable drive to another computer.

W32/SillyFDC-AN sets the following registry entries:

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
systeminit
<System>\systeminit.exe

Registry entries are also created under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoDriveTypeAutoRun
0

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer
NoFind
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableCMD
2

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableRegistryTools
1

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system
DisableTaskMgr
1





Name   Troj/Banloa-CT

Type  
    * Trojan

Affected operating systems  
    * Windows

Side effects  
    * Downloads code from the internet

Prevalence (1-5) 2

Description
Troj/Banloa-CT is a Trojan for the Windows platform.





Name   Mal/Click-C

Type  
    * Malicious Behavior

How it spreads  
    * Web browsing

Affected operating systems  
    * Windows

Side effects  
    * Opens links to websites

Aliases  
    * Clicker.Win32.Chimoz.u

Prevalence (1-5) 2

Description
Mal/Click-C is a Trojan for the Windows platform.

Advanced
Mal/Click-C is a Trojan for the Windows platform.





Name   W32/Ircbot-WW

Type  
    * Spyware Worm

How it spreads  
    * Network shares

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities

Aliases  
    * Backdoor.Win32.IRCBot.aco

Prevalence (1-5) 2

Description
W32/Ircbot-WW is a worm for the Windows platform.

W32/Ircbot-WW spreads through network shares.

Advanced
W32/Ircbot-WW is a worm for the Windows platform.

W32/Ircbot-WW spreads through network shares.

When first run W32/Ircbot-WW copies itself to:

<System>\u.exe

W32/Ircbot-WW creates the following registry entry to start itself:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Office Monitor Word Exel R
<System>\u.exe

W32/Ircbot-WW also sets the following registry entries:

HKLM\SOFTWARE\Microsoft\Ole
EnableDCOM
N

HKLM\SYSTEM\CurrentControlSet\Control\Lsa
restrictanonymous
1





Name   W32/Sohana-Z

Type  
    * Spyware Worm

How it spreads  
    * Removable storage devices
    * Network shares
    * Chat programs

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Reduces system security
    * Records keystrokes
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities

Prevalence (1-5) 2

Description
W32/Sohana-Z is a worm for the Windows platform.

W32/Sohana-Z spreads through instant messaging applications, removable media
and network shares.

W32/Sohana-Z includes functionality to access the internet and communicate with
a remote server via HTTP.

Advanced
W32/Sohana-Z is a worm for the Windows platform.

W32/Sohana-Z spreads through instant messaging applications, removable media
and network shares.

W32/Sohana-Z includes functionality to access the internet and communicate with
a remote server via HTTP.

When first run W32/Sohana-Z copies itself to:

<Windows>\SCVHOST.exe
<System>\SCVHOST.exe
<System>\blastclnnn.exe

and creates the following files:

<System>\autorun.ini

The file autorun.ini is detected as Mal/AutoInf-A.

The following registry entry is created to run W32/Sohana-Z on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo Messengger
<System>\SCVHOST.exe

The following registry entry is changed to run W32/Sohana-Z on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe SCVHOST.exe

The following registry entries are set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NofolderOptions
1





Name   W32/Sohana-Z

Type  
    * Spyware Worm

How it spreads  
    * Removable storage devices
    * Network shares
    * Chat programs

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Reduces system security
    * Records keystrokes
    * Installs itself in the Registry
    * Exploits system or software vulnerabilities

Prevalence (1-5) 2

Description
W32/Sohana-Z is a worm for the Windows platform.

W32/Sohana-Z spreads through instant messaging applications, removable media
and network shares.

W32/Sohana-Z includes functionality to access the internet and communicate with
a remote server via HTTP.

Advanced
W32/Sohana-Z is a worm for the Windows platform.

W32/Sohana-Z spreads through instant messaging applications, removable media
and network shares.

W32/Sohana-Z includes functionality to access the internet and communicate with
a remote server via HTTP.

When first run W32/Sohana-Z copies itself to:

<Windows>\SCVHOST.exe
<System>\SCVHOST.exe
<System>\blastclnnn.exe

and creates the following files:

<System>\autorun.ini

The file autorun.ini is detected as Mal/AutoInf-A.

The following registry entry is created to run W32/Sohana-Z on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo Messengger
<System>\SCVHOST.exe

The following registry entry is changed to run W32/Sohana-Z on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe SCVHOST.exe

The following registry entries are set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskMgr
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
NofolderOptions
1





Name   W32/Frawrm-A

Type  
    * Worm

How it spreads  
    * Removable storage devices
    * Network shares

Affected operating systems  
    * Windows

Side effects  
    * Installs itself in the Registry

Aliases  
    * Virus.Win32.AutoRun.bb
    * Win32/Delf.NFG
    * W32/Generic.worm.j

Prevalence (1-5) 2

Description
W32/Frawrm-A is a worm for the Windows platform.

Advanced
W32/Frawrm-A is a worm for the Windows platform.

W32/Frawrm-A spreads to other network computers and removable drives.

When first run W32/Frawrm-A copies itself to:

<Root>\recycler\systems.com
<System>\taskmger.com

and creates the file <Root>\autorun.inf.

Autorun.inf is detected as Mal/AutoInf-A.

The following registry entry is changed to run taskmger.com on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe taskmger.com

The following registry entries are set, disabling system software:

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableTaskmgr
1

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
DisableRegistryTools
1





Name   W32/Rbot-GSJ

Type  
    * Worm

How it spreads  
    * Network shares

Affected operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Downloads code from the internet
    * Reduces system security
    * Installs itself in the Registry

Prevalence (1-5) 2

Description
W32/Rbot-GSJ is a network worm for the Windows platform.

Advanced
W32/Rbot-GSJ is a network worm for the Windows platform.

W32/Rbot-GSJ runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.

When first run W32/Rbot-GSJ copies itself to <System>\rundll.exe.

The following registry entries are created to run rundll.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Microsoft
rundll.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
Microsoft
rundll.exe

The following registry entry is set:

HKCU\Software\ASProtect
Microsoft
rundll.exe

 
--- MultiMail/Win32 v0.43
 * Origin: Doc's Place BBS Fido Since 1991 docsplace.tzo.com (1:123/140)