Tillbaka till svenska Fidonet
English   Information   Debug  
TRAPDOOR   0/19
TREK   0/755
TUB   0/290
UFO   0/40
UNIX   0/1316
USA_EURLINK   0/102
USR_MODEMS   0/1
VATICAN   0/2740
VIETNAM_VETS   0/14
VIRUS   0/378
VIRUS_INFO   0/201
VISUAL_BASIC   0/473
WHITEHOUSE   0/5187
WIN2000   0/101
WIN32   0/30
WIN95   0/4282
WIN95_OLD1   0/70272
WINDOWS   0/1517
WWB_SYSOP   0/419
WWB_TECH   0/810
ZCC-PUBLIC   0/1
ZEC   4

 
4DOS   0/134
ABORTION   0/7
ALASKA_CHAT   0/506
ALLFIX_FILE   0/1313
ALLFIX_FILE_OLD1   0/7997
ALT_DOS   0/152
AMATEUR_RADIO   0/1039
AMIGASALE   0/14
AMIGA   0/331
AMIGA_INT   0/1
AMIGA_PROG   0/20
AMIGA_SYSOP   0/26
ANIME   0/15
ARGUS   0/924
ASCII_ART   0/340
ASIAN_LINK   0/651
ASTRONOMY   0/417
AUDIO   0/92
AUTOMOBILE_RACING   0/105
BABYLON5   0/17862
BAG   135
BATPOWER   0/361
BBBS.ENGLISH   0/382
BBSLAW   0/109
BBS_ADS   0/5290
BBS_INTERNET   0/507
BIBLE   0/3563
BINKD   0/1119
BINKLEY   0/215
BLUEWAVE   0/2173
CABLE_MODEMS   0/25
CBM   0/46
CDRECORD   0/66
CDROM   0/20
CLASSIC_COMPUTER   0/378
COMICS   0/15
CONSPRCY   0/899
COOKING   32031
COOKING_OLD1   0/24719
COOKING_OLD2   0/40862
COOKING_OLD3   0/37489
COOKING_OLD4   0/35496
COOKING_OLD5   9370
C_ECHO   0/189
C_PLUSPLUS   0/31
DIRTY_DOZEN   0/201
DOORGAMES   0/2048
DOS_INTERNET   0/196
duplikat   6002
ECHOLIST   0/18295
EC_SUPPORT   0/318
ELECTRONICS   0/359
ELEKTRONIK.GER   1534
ENET.LINGUISTIC   0/13
ENET.POLITICS   0/4
ENET.SOFT   0/11701
ENET.SYSOP   33878
ENET.TALKS   0/32
ENGLISH_TUTOR   0/2000
EVOLUTION   0/1335
FDECHO   0/217
FDN_ANNOUNCE   0/7068
FIDONEWS   23979
FIDONEWS_OLD1   0/49742
FIDONEWS_OLD2   0/35949
FIDONEWS_OLD3   0/30874
FIDONEWS_OLD4   0/37224
FIDO_SYSOP   12852
FIDO_UTIL   0/180
FILEFIND   0/209
FILEGATE   0/212
FILM   0/18
FNEWS_PUBLISH   4357
FN_SYSOP   41651
FN_SYSOP_OLD1   71952
FTP_FIDO   0/2
FTSC_PUBLIC   0/13596
FUNNY   0/4886
GENEALOGY.EUR   0/71
GET_INFO   105
GOLDED   0/408
HAM   0/16066
HOLYSMOKE   0/6791
HOT_SITES   0/1
HTMLEDIT   0/71
HUB203   466
HUB_100   264
HUB_400   39
HUMOR   0/29
IC   0/2851
INTERNET   0/424
INTERUSER   0/3
IP_CONNECT   719
JAMNNTPD   0/233
JAMTLAND   0/47
KATTY_KORNER   0/41
LAN   0/16
LINUX-USER   0/19
LINUXHELP   0/1155
LINUX   0/22070
LINUX_BBS   0/957
mail   18.68
mail_fore_ok   249
MENSA   0/341
MODERATOR   0/102
MONTE   0/992
MOSCOW_OKLAHOMA   0/1245
MUFFIN   0/783
MUSIC   0/321
N203_STAT   920
N203_SYSCHAT   313
NET203   321
NET204   69
NET_DEV   0/10
NORD.ADMIN   0/101
NORD.CHAT   0/2572
NORD.FIDONET   189
NORD.HARDWARE   0/28
NORD.KULTUR   0/114
NORD.PROG   0/32
NORD.SOFTWARE   0/88
NORD.TEKNIK   0/58
NORD   0/453
OCCULT_CHAT   0/93
OS2BBS   0/787
OS2DOSBBS   0/580
OS2HW   0/42
OS2INET   0/37
OS2LAN   0/134
OS2PROG   0/36
OS2REXX   0/113
OS2USER-L   207
OS2   0/4786
OSDEBATE   0/18996
PASCAL   0/490
PERL   0/457
PHP   0/45
POINTS   0/405
POLITICS   0/29554
POL_INC   0/14731
PSION   103
R20_ADMIN   1121
R20_AMATORRADIO   0/2
R20_BEST_OF_FIDONET   13
R20_CHAT   0/893
R20_DEPP   0/3
R20_DEV   399
R20_ECHO2   1379
R20_ECHOPRES   0/35
R20_ESTAT   0/719
R20_FIDONETPROG...
...RAM.MYPOINT
  0/2
R20_FIDONETPROGRAM   0/22
R20_FIDONET   0/248
R20_FILEFIND   0/24
R20_FILEFOUND   0/22
R20_HIFI   0/3
R20_INFO2   3170
R20_INTERNET   0/12940
R20_INTRESSE   0/60
R20_INTR_KOM   0/99
R20_KANDIDAT.CHAT   42
R20_KANDIDAT   28
R20_KOM_DEV   112
R20_KONTROLL   0/13225
R20_KORSET   0/18
R20_LOKALTRAFIK   0/24
R20_MODERATOR   0/1852
R20_NC   76
R20_NET200   245
R20_NETWORK.OTH...
...ERNETS
  0/13
R20_OPERATIVSYS...
...TEM.LINUX
  0/44
R20_PROGRAMVAROR   0/1
R20_REC2NEC   534
R20_SFOSM   0/340
R20_SF   0/108
R20_SPRAK.ENGLISH   0/1
R20_SQUISH   107
R20_TEST   2
R20_WORST_OF_FIDONET   12
RAR   0/9
RA_MULTI   106
RA_UTIL   0/162
REGCON.EUR   0/2056
REGCON   0/13
SCIENCE   0/1206
SF   0/239
SHAREWARE_SUPPORT   0/5146
SHAREWRE   0/14
SIMPSONS   0/169
STATS_OLD1   0/2539.065
STATS_OLD2   0/2530
STATS_OLD3   0/2395.095
STATS_OLD4   0/1692.25
SURVIVOR   0/495
SYSOPS_CORNER   0/3
SYSOP   0/84
TAGLINES   0/112
TEAMOS2   0/4530
TECH   0/2617
TEST.444   0/105
Möte VIRUS, 378 texter
 lista första sista föregående nästa
Text 3, 866 rader
Skriven 2004-08-22 18:46:00 av KURT WISMER (1:123/140)
Ärende: News, Aug. 22 2004
==========================
[cut-n-paste from sophos.com's new, less convenient format... i won't be
doing any with a prevalence indicator of 1 as that seems to correspond
with 'no reports of users affected by this {whatever}' and if it isn't 
in the wild, the 'public service announcement' value just isn't there]

Name  W32/Agobot-MF

Type
    * Worm

How it spreads 
    * Network shares
    * Web browsing
    * Web downloads
    * Chat programs

Vulnerable operating systems
    * Windows

Side effects
    * Turns off anti-virus applications
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Reduces system security
    * Records keystrokes

Aliases
    * Backdoor.Agobot.gen

Prevalence (1-5) 2

Description
W32/Agobot-MF is an IRC backdoor Trojan and network worm that is capable 
of spreading to computers on the local network protected by weak 
passwords.

Advanced
W32/Agobot-MF is an IRC backdoor Trojan and network worm.

W32/Agobot-MF is capable of spreading to computers on the local network 
protected by weak passwords.

When first run W32/Agobot-MF moves itself to the Windows system folder 
as syxstem32.exe and creates the following registry entries to run 
itself on system logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
WSAConfiguration = syxtem32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
WSAConfiguration = syxtem32.exe

On NT-based versions of Windows the worm creates a new service named 
"WSAConfiguration" with the startup property set to automatic, so that 
the service starts automatically each time Windows is started.

Each time W32/Agobot-MF is run it attempts to connect to a remote IRC 
server and join a specific channel. The worm then runs continuously in 
the background, allowing a remote intruder to access and control the 
computer via IRC channels.

W32/Agobot-MF attempts to terminate and disable various anti-virus and 
security related programs.

W32/Agobot-MF attempts to restrict access to several anti-virus and 
security related websites by appending the following to the HOSTS file:

127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com





Name  W32/Rbot-GR

Type
    * Worm

How it spreads
    * Network shares 

Vulnerable operating systems
    * Windows

Side effects
    * Allows others to access the computer
    * Steals information
    * Uses its own emailing engine
    * Reduces system security
    * Records keystrokes
    * Installs itself in the Registry

Aliases
    * Backdoor.Rbot.gen
    * W32/Sdbot.worm.gen.g
    * W32.Spybot.Worm

Prevalence (1-5) 2

Description
W32/Rbot-GR is a worm with backdoor Trojan functionality.

W32/Rbot-GR is capable of spreading to computers on the local network 
protected by weak passwords after receiving the appropriate backdoor 
command. The worm may also spread by exploiting a number of 
vulnerabilities.

W32/Rbot-GR may be used to steal passwords and product keys from a 
number of games and applications.

Advanced
W32/Rbot-GR is a worm with backdoor Trojan functionality.

W32/Rbot-GR is capable of spreading to computers on the local network 
protected by weak passwords after receiving the appropriate backdoor 
command.

W32/Rbot-GR may also spread by exploiting the following vulnerabilities:

WebDav (MS03-007)
DCOM (MS03-039, MS04-012)
UPNP (MS01-059)
Microsoft SQL servers with weak passwords.
Buffer overflow in certain versions of DameWare (CAN-2003-1030)
Backdoors left open by other worms and Trojans such as W32/MyDoom, 
Troj/Optix, Troj/Kuang and Troj/NetDevil.

When first run, W32/Rbot-GR copies itself to the Windows system folder 
as SYSTEMC32.EXE and runs this copy of the worm. The copy will then 
attempt to delete the original file. In order to run each time Windows 
is started, W32/Rbot-GR will set the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Updates = systemc32.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Updates = systemc32.exe
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Updates = systemc32.exe

The worm runs continuously in the background providing backdoor access 
to the infected computer.

The backdoor component of W32/Rbot-GR may be used to:

    * Initiate distributed denial-of-service (DDOS) attacks using ICMP, 
      SYN and UDP.
    * Redirect TCP and SOCKS4 traffic.
    * Provide a remote login shell.
    * Download, upload, delete and execute files.
    * Set up an HTTP and TFTP file server.
    * Steal passwords (including PayPal account information).
    * Log key presses.
    * Capture screenshots.
    * Capture webcam screenshots and videos.
    * List and kill processes.
    * Open and close vulnerabilities.
    * Port scan for vulnerabilities on other remote machines.
    * Send emails as specified by the remote user.
    * Flush the DNS and ARP caches.
    * Shut down the machine.


W32/Rbot-GR may be used to steal registration and key details from 
several computer games including:

Counter-Strike
The Gladiators
Gunman Chronicles
Half-Life
Industry Giant 2
Legends of Might and Magic
Soldiers Of Anarchy
Microsoft Windows Product ID
Unreal Tournament 2003
Unreal Tournament 2004
IGI 2: Covert Strike
Freedom Force
Battlefield 1942
Battlefield 1942 (Road To Rome)
Battlefield 1942 (Secret Weapons of WWII)
Battlefield Vietnam
Black and White
Command and Conquer: Generals (Zero Hour)
James Bond 007: Nightfire
Command and Conquer: Generals
Global Operations
Medal of Honor: Allied Assault
Medal of Honor: Allied Assault: Breakthrough
Medal of Honor: Allied Assault: Spearhead
Need For Speed Hot Pursuit 2
Need For Speed: Underground
Shogun: Total War: Warlord Edition
FIFA 2002
FIFA 2003
NHL 2002
NHL 2003
Nascar Racing 2002
Nascar Racing 2003
Rainbow Six III RavenShield
Command and Conquer: Tiberian Sun
Command and Conquer: Red Alert
Command and Conquer: Red Alert 2
Chrome
NOX
Hidden & Dangerous 2
Soldier of Fortune II - Double Helix
Neverwinter Nights
Neverwinter Nights (Shadows of Undrentide)
Neverwinter Nights (Hordes of the Underdark)

W32/Rbot-GR may alter the following registry entries:

HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = N
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = 1

W32/Rbot-GR may create and delete network shares on the infected 
computer.





Name   W32/Rbot-GP

Type  
    * Worm

How it spreads  
    * Network shares

Vulnerable operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Downloads code from the internet
    * Installs itself in the Registry
    * Exploits known vulnerabilites

Aliases  
    * Backdoor.Rbot.gen
    * W32/Sdbot.worm.gen.n
    * W32.Spybot.Worm

Prevalence (1-5) 2

Description
W32/Rbot-GP is a worm which attempts to spread to remote network shares 
and also contains backdoor Trojan functionality allowing unauthorised 
access to an infected computer.

Advanced
W32/Rbot-GP is a worm which attempts to spread to remote network shares. 
It also contains backdoor Trojan functionality, allowing unauthorised 
remote access to the infected computer via IRC channels while running in 
the background as a service process.

W32/Rbot-GP moves itself to the Windows system folder as wuamgrd.exe and 
creates the following registry entries to ensure it is run at system 
logon:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Update = wuamgrd.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Update = wuamgrd.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Update = wuamgrd.exe

W32/Rbot-GP speads to network shares with weak passwords and via network 
security exploits.

W32/Rbot-GP will also download and execute remote files on the infected 
computer, log key strokes, retrieve information such as CD keys for 
various games and flood other computers with network packets.





Name   W32/Rbot-GS

Type  
    * Worm

How it spreads  
    * Network shares

Vulnerable operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Reduces system security
    * Records keystrokes
    * Installs itself in the Registry
    * Exploits known vulnerabilites
    * Used in DOS attacks

Aliases  
    * Backdoor.Rbot.gen

Prevalence (1-5) 2

Description
W32/Rbot-GS spreads by exploiting vulnerabilities, network services with 
weak passwords and backdoors opened by other worms.

W32/Rbot-GS allows unauthorised remote access to the infected computer.
The operating system vulnerabilities exploited by W32/Rbot-GS are 
addressed by MS04-011, MS03-039, MS03-007 and MS01-059.

Advanced
W32/Rbot-GS is a network worm and backdoor Trojan for the Windows 
platform.

W32/Rbot-GS allows a malicious user remote access to an infected 
computer.

The worm copies itself to scvhost.exe in the Windows system folder and 
creates the following registry entries to run itself on startup:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Microsoft Update Machine = scvhost.exe
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
Microsoft Update Machine = scvhost.exe
HKCU\Software\MicrosoftWindows\CurrentVersion\Run\
Microsoft Update Machine = scvhost.exe

W32/Rbot-GS spreads using a variety of techniques including exploiting 
weak passwords on computers and SQL servers, exploiting operating 
system vulnerabilites (including DCOM-RPC, LSASS, WebDAV and UPNP) and 
using backdoors opened by other worms or Trojans.

W32/Rbot-GS can be controlled by a remote attacker over IRC channels. 
The infected computer can be used to perform any of the following 
functions:

Proxy server (SOCKS4)
HTTP server
File system manipulation
Port scanner
DDoS floods (TCP,UDP,SYN)
Remote shell (RLOGIN)
Packet sniffer
Key logger

Patches for the operating system vulnerabilities exploited by 
W32/Rbot-GS can be obtained from Microsoft at:
MS04-011
MS03-039
MS03-007
MS01-059





Name   W32/Rbot-GO

Type  
    * Worm

How it spreads  
    * Network shares

Vulnerable operating systems  
    * Windows

Side effects  
    * Turns off anti-virus applications
    * Allows others to access the computer
    * Steals information
    * Downloads code from the internet
    * Reduces system security

Aliases  
    * Backdoor.Rbot.gen

Prevalence (1-5) 2

Description
W32/Rbot-GO is a worm which attempts to spread to remote network shares.
W32/Rbot-GO also contains backdoor Trojan functionality, allowing 
unauthorised remote access to the infected computer via IRC channels.

Advanced
W32/Rbot-GO is a worm which attempts to spread to remote network shares. 
It also contains backdoor Trojan functionality, allowing unauthorised 
remote access to the infected computer via IRC channels while running in 
the background as a service process.

W32/Rbot-GO spreads using a variety of techniques including exploiting 
weak passwords on computers and SQL servers and exploiting operating 
system vulnerabilites (including DCOM-RPC, LSASS, WebDAV and UPNP).

W32/Rbot-GO can be controlled by a remote attacker over IRC channels.

W32/Rbot-GO moves itself to the file MSNMSG.EXE in the Windows system 
folder and creates entries at the following locations in the registry so 
as to run itself on Windows login:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
msn = msnmsg.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices\
msn = msnmsg.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
msn = msnmsg.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
msn = msnmsg.exe

W32/Rbot-GO may also set the following registry entries:

HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = "N"
HKLM\SYSTEM\CurrentControlSet\Control\Lsa\restrictanonymous = "1"

W32/Rbot-GO attempts to terminate processes relating to the following 
files:

regedit.exe
netstat.exe
msblast.exe
zapro.exe
navw32.exe
navapw32.exe
zonealarm.exe
taskmon_exe
wincfg32.exetaskmon.exe
PandaAVEngine.exe
sysinfo.exe
mscvb32.exe
MSBLAST.exe
teekids.exe
Penis32.exe
bbeagle.exe
SysMonXP.exe
winupd.exe
winsys.exe
ssate.exe
rate.exe
d3dupdate.exe
irun4.exe
i11r54n4.exe

Patches for the operating system vulnerabilities exploited by 
W32/Rbot-GO can be obtained from Microsoft at:
MS04-011
MS03-026
MS03-007
MS01-059





Name   Troj/Banker-K

Type  
    * Trojan

Vulnerable operating systems  
    * Windows

Side effects  
    * Steals credit card details
    * Records keystrokes

Prevalence (1-5) 2

Description
Troj/Banker-K attempts to steal login credentials for Brazilian online 
banking sites.

In order to run automatically when Windows starts up the Trojan drops 
the file svchost.exe into the Windows system folder and adds the 
registry entry 
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\svchost 
pointing to this file.

Troj/Banker-K also drops the files bb.exe, bmb.exe, bnet.exe, bra.exe, 
gf.exe and itau.exe into the Windows system folder.





Name   W32/Lovgate-W

Type  
    * Worm

How it spreads  
    * Email messages
    * Network shares
    * Peer-to-peer

Vulnerable operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Installs itself in the Registry

Prevalence (1-5) 3

Description
W32/Lovgate-W is a worm with the backdoor functionality that spreads via 
email, network shares with weak passwords and filesharing networks.

When executed W32/Lovgate-W creates a background process with the name 
"LSASS.EXE", copies itself to the Windows system folder, sets registry 
entries, extracts a backdoor component as a DLL file, harvests email 
addresses from *.ht files and sends itself out.

In order to run automatically when Windows starts up W32/Lovgate-W 
creates the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
VFW Encoder/Decoder Settings = RUNDLL32.EXE MSSIGN30.DLL ondll_reg

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Program In Windows = C:\WINDOWS\System32\IEXPLORE.EXE

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
Protected Storage = RUNDLL32.EXE MSSIGN30.DLL ondll_reg

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
SystemTra = C:\WINDOWS\SysTra.EXE.

where EXE is a worm copy and a DLL is a backdoor component.

W32/Lovgate-W copies itself to the available filesharing networks shared 
folders and subfolders with a filename chosen from:

Are you looking for Love.doc.exe
The world of lovers.txt.exe
How To Hack Websites.exe
Panda Titanium Crack.zip.exe
Mafia Trainer!!!.exe
100 free essays school.pif
AN-YOU-SUCK-IT.txt.pif
Sex_For_You_Life.JPG.pif
CloneCD + crack.exe
Age of empires 2 crack.exe
MoviezChannelsInstaler.exe
Star Wars II Movie Full Downloader.exe





Name  W32/Tzet-B

Type  
    * Worm

How it spreads  
    * Network shares

Vulnerable operating systems  
    * Windows

Side effects  
    * Drops more malware
    * Installs itself in the Registry
    * Leaves non-infected files on computer

Aliases  
    * Worm.Win32.Tzet
    * W32/Tzet.worm.e
    * Win32/Tzet.A.dropper

Prevalence (1-5) 2

Description
W32/Tzet-B is a network worm.

W32/Tzet-B searches the local network for computers with weak or no 
passwords on the administrator or admin accounts to which it can copy 
itself.

Advanced
W32/Tzet-B is a network worm. When run the worm creates the following 
files in the folder C:\<Windows>\System32:

AUTHEXEC.BAT - A batch file used by the worm and detected as W32/Tzet-A.
IGLMTRAY.EXE - Detected by Sophos Anti-Virus as Troj/Flood-DP
IGLXTRAY.EXE - Detected by Sophos Anti-Virus as Troj/Flood-DP
LRSS.INI - A mIRC config file used by the worm and detected as W32/Tzet-A.
MDDE32.EXE - A clean utility for terminating processes.
NNA.EXE - A Trojan downloaded detected bp Sophos Anti-Virus as 
Troj/Apher-H.
PRINTF_CORE.EXE - Detected by Sophos Anti-Virus as Troj/Delsha-C
VIDRIV.EXE - A clean utility to hide/show windows.
WMPT.EXE - A clean utility called PSExec.
WSUBSYS.WAV - The main component of this worm.
XCOPY.DLL - A text file containing a list of IP domains.

The worm adds the following registry entry to run the file iglmtray.exe 
when Windows starts up:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WUPD

W32/Tzet-B searches the local network for computers with weak or no 
passwords on the administrator or admin accounts to which it can copy 
itself.






Name   W32/Agobot-ME

Type  
    * Worm

How it spreads  
    * Network shares

Vulnerable operating systems  
    * Windows

Side effects  
    * Turns off anti-virus applications
    * Allows others to access the computer
    * Installs itself in the Registry

Aliases  
    * Backdoor.Agobot.gen

Prevalence (1-5) 2

Description
W32/Agobot-ME is an IRC backdoor Trojan and network worm which also 
terminates and disables various anti-virus and security related programs.

Advanced
W32/Agobot-ME is an IRC backdoor Trojan and network worm.

W32/Agobot-ME is capable of spreading to computers on the local network 
protected by weak passwords.

When first run W32/Agobot-ME moves itself to the Windows system folder 
as mssvc32.exe and creates the following registry entries to run itself 
on system logon:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
mssvc32 = mssvc32.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
mssvc32 = mssvc32.exe

On NT-based versions of Windows the worm creates a new service named 
"mssvc32" with the startup property set to automatic, so that the 
service starts automatically each time Windows is started.

Each time W32/Agobot-ME is run it attempts to connect to a remote IRC 
server and join a specific channel. The worm then runs continuously in 
the background, allowing a remote intruder to access and control the 
computer via IRC channels.

W32/Agobot-ME attempts to terminate and disable various anti-virus and 
security related programs.

W32/Agobot-ME attempts to restrict access to several anti-virus and 
security related websites by appending the following to the HOSTS file:

127.0.0.1 www.symantec.com
127.0.0.1 securityresponse.symantec.com
127.0.0.1 symantec.com
127.0.0.1 www.sophos.com
127.0.0.1 sophos.com
127.0.0.1 www.mcafee.com
127.0.0.1 mcafee.com
127.0.0.1 liveupdate.symantecliveupdate.com
127.0.0.1 www.viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 viruslist.com
127.0.0.1 f-secure.com
127.0.0.1 www.f-secure.com
127.0.0.1 kaspersky.com
127.0.0.1 www.avp.com
127.0.0.1 www.kaspersky.com
127.0.0.1 avp.com
127.0.0.1 www.networkassociates.com
127.0.0.1 networkassociates.com
127.0.0.1 www.ca.com
127.0.0.1 ca.com
127.0.0.1 mast.mcafee.com
127.0.0.1 my-etrust.com
127.0.0.1 www.my-etrust.com
127.0.0.1 download.mcafee.com
127.0.0.1 dispatch.mcafee.com
127.0.0.1 secure.nai.com
127.0.0.1 nai.com
127.0.0.1 www.nai.com
127.0.0.1 update.symantec.com
127.0.0.1 updates.symantec.com
127.0.0.1 us.mcafee.com
127.0.0.1 liveupdate.symantec.com
127.0.0.1 customer.symantec.com
127.0.0.1 rads.mcafee.com
127.0.0.1 trendmicro.com
127.0.0.1 www.trendmicro.com





Name   Troj/Winflux-B

Type  
    * Trojan

Vulnerable operating systems  
    * Windows

Side effects  
    * Allows others to access the computer
    * Steals information
    * Reduces system security
    * Records keystrokes
    * Installs itself in the Registry

Aliases  
    * Backdoor.Win32.Flux.d
    * TrojanSpy.Win32.Flux.a

Prevalence (1-5) 2

Description
Troj/Winflux-B is backdoor Trojan for the Windows platform.

Troj/Winflux-B can be used by a remote attacker to control an infected 
computer and steal information.

Advanced
Troj/Winflux-B is backdoor Trojan for the Windows platform.

Troj/Winflux-B can be used by a remote attacker to control an infected 
computer and steal information.

When first run, Troj/Winflux-B may copy itself to the Windows or Windows 
system folder. The Trojan may then delete the original file.

In order to hide from the user, Troj/Winflux-B may inject its code into 
a running process such as Explorer, MSN Messenger or any other process 
specified by the creator of the Trojan.

In order to run automatically each time Windows is started, 
Troj/Winflux-B may set the following registry entries:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\<Name> = <Trojan path>
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce\*<Name> = <Trojan 
path>
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\<Name> = <Trojan path>
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce\*<Name> = <Trojan 
path>

The Trojan has the ability to monitor these autostart entries and may 
restore them if they are deleted.

Troj/Winflux-B may also set the following additional registry entries:

HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\(CLASS ID)\
HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\(CLASS ID)\
StubPath = <Trojan path> <Number>

where CLASS ID is a randomly generated Class ID number sequence.

Troj/Winflux-B gives remote attackers control of an infected computer. 
The Trojan allows an attacker to:

    * Create screen captures.
    * Create Webcam captures.
    * Log key presses.
    * Log entered passwords.
    * Download and execute files.
    * Control an infected machine's Windows environment.
    * Display message boxes.
    * List and kill processes and tasks.
    * Shut down, log off or reboot an infected machine.
    * Update the server.
    * Disconnect and reconnect an infected machine from the internet.
    * Install a SOCKS4 proxy.




Name   W32/Wort-A

Type  
    * Worm

Vulnerable operating systems  
    * Windows

Side effects  
    * Downloads code from the internet
    * Exploits known vulnerabilites

Prevalence (1-5) 2

Description
W32/Wort-A is a networm worm which exploits the LSASS (MS04-011) 
vulnerability.
W32/Wort-A may download files from the internet.

Advanced
W32/Wort-A is a worm which spreads by exploting the LSASS vulnerability.

The worm sets the following registry entry to ensure that it is run each 
time Windows starts:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\WinLsass

W32/Wort-A randomly generates IPs to infect. The worm may also attempt 
to download a file from the internet.

A patch for the vulnerability exploited by the worm is available from 
Microsoft.

 
--- MultiMail/Win32 v0.43
 * Origin: Try Our Web Based QWK: DOCSPLACE.ORG (1:123/140)