Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS ALERTS - December 12, 2005

Dec 11, 2005 10:15PM PST

Discussion is locked

- Collapse -
Troj/KillFil-P
Dec 11, 2005 10:17PM PST
- Collapse -
Troj/Banker-IO
Dec 11, 2005 10:19PM PST
- Collapse -
Dopozor-475
Dec 11, 2005 10:21PM PST

Type
Virus

Aliases
Virus.DOS.Pozor.a
Univ.ow/a

Dopozor-475 is a virus which overwrites the start of all files in the current folder with a copy of itself, destroying the original data.

Dopozor-475 also sets the system date to August 23, 1982.

Dopozor-475 is 16-bit DOS code but will still run on some versions of Windows.

http://www.sophos.com/virusinfo/analyses/dopozor475.html

- Collapse -
Troj/DownLdr-RR
Dec 11, 2005 10:23PM PST
- Collapse -
Troj/Banload-O
Dec 11, 2005 10:25PM PST
- Collapse -
Troj/Dloadr-D
Dec 11, 2005 10:27PM PST
- Collapse -
Troj/Abox-D
Dec 11, 2005 10:34PM PST

Type
Trojan

Aliases
Trojan-Downloader.Win32.VB.ft

Troj/Abox-D is a Trojan for the Windows platform.

When Troj/Abox-D is installed it creates the file <Temp> \ABox.ftp.

This file may be deleted.

Troj/Abox-D includes functionality to silently download, install and run new software.

http://www.sophos.com/virusinfo/analyses/trojaboxd.html

- Collapse -
Troj/Dloade-AAB
Dec 11, 2005 10:36PM PST
- Collapse -
Troj/Dloade-AAC
Dec 11, 2005 10:38PM PST
- Collapse -
Troj/DownLdr-EJ
Dec 11, 2005 10:40PM PST
- Collapse -
Troj/Dloade-AAD
Dec 11, 2005 10:41PM PST
- Collapse -
W32/Rbot-BBB
Dec 11, 2005 10:51PM PST

Type
Worm

Aliases
Backdoor.Win32.Rbot.age
W32/Sdbot.worm.gen.bh

W32/Rbot-BBB is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-BBB runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

W32/Rbot-BBB spreads to remote network shares protected by weak passwords and to computers vulnerable to common exploits, including LSASS (MS04-011), RPC-DCOM , (MS04-012), WebDav (MS03-007), IIS5SSL (MS04-011) (CAN-2003-0719), UPNP (MS01-059), Dameware (CAN-2003-1030) and ASN.1 (MS04-007).

http://www.sophos.com/virusinfo/analyses/w32rbotbbb.html

- Collapse -
Troj/Torpig-S
Dec 11, 2005 10:56PM PST

Type
Spyware Trojan

Aliases
Trojan-Spy.Win32.Small.dg
PWS-JA

Troj/Torpig-S is an information stealing Trojan for the Windows platform.

The Trojan attempts to steal passwords, as well as logging keypresses and open window titles to text files and periodically sends the collected information to a remote user via HTTP.

Troj/Torpig-S automatically closes security warning messages displayed by common anti-virus and security related applications.

http://www.sophos.com/virusinfo/analyses/trojtorpigs.html

- Collapse -
Troj/LegMir-BW
Dec 11, 2005 10:58PM PST
- Collapse -
Troj/Lineage-BU
Dec 11, 2005 11:03PM PST
- Collapse -
Troj/Ranck-DE
Dec 11, 2005 11:05PM PST
- Collapse -
Troj/Dloade-AAI
Dec 11, 2005 11:06PM PST

Type
Trojan

Aliases
Trojan-Downloader.Win32.PassAlert.d
StartPage-IC
Download.Trojan

Troj/Dloade-AAI is a Trojan for the Windows platform.

Troj/Dloade-AAI includes functionality to access the internet and communicate with a remote server via HTTP.

http://www.sophos.com/virusinfo/analyses/trojdloadeaai.html

- Collapse -
Troj/Dloade-AAJ
Dec 11, 2005 11:09PM PST
- Collapse -
Troj/GrayBrd-A
Dec 11, 2005 11:12PM PST
- Collapse -
Troj/Agent-FN
Dec 11, 2005 11:15PM PST
- Collapse -
Troj/Clicker-AI
Dec 11, 2005 11:17PM PST
- Collapse -
Troj/Agent-UF
Dec 11, 2005 11:20PM PST

Type
Trojan

Aliases
Trojan-Downloader.Win32.Agent.uf

Troj/Agent-UF is a Trojan for the Windows platform.

Troj/Agent-UF includes functionality to access the internet and communicate with a remote server via HTTP. It attempts to download and execute further code from predefined websites.

http://www.sophos.com/virusinfo/analyses/trojagentuf.html

- Collapse -
Troj/Viran-C
Dec 11, 2005 11:22PM PST

Type
Trojan

Aliases
Backdoor.Win32.Agent.qa

Troj/Viran-C is a Trojan for the Windows platform.

Troj/Viran-C includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Viran-C copies itself to:

<Common Files> \system\lsass.exe
<System> \ctfmon.exe
<System> \userinit.exe

and creates the following files:

<System> \divx5.dll
<System> \h323.txt

The file divx5.dll is detected as Troj/HideProc-K.

http://www.sophos.com/virusinfo/analyses/trojviranc.html

- Collapse -
W32/Sdbot-AGZ
Dec 12, 2005 7:09AM PST
- Collapse -
Troj/Prosti-Q
Dec 12, 2005 7:10AM PST

Type Trojan

Aliases Backdoor.Win32.Prosti.q

Troj/Prosti-Q is a Trojan for the Windows platform.
Troj/Prosti-Q includes functionality to access the internet and communicate with a remote server via HTTP. It attempts to download and execute further code. The Trojan may also allow a remote intruder to perform some backdoor commands.
Troj/Prosti-Q attempts to disable or bypass some security procedures.

http://www.sophos.com/virusinfo/analyses/trojprostiq.html

- Collapse -
Troj/Zlob-S
Dec 12, 2005 7:11AM PST
- Collapse -
Troj/Ranck-DJ
Dec 12, 2005 7:12AM PST
- Collapse -
Troj/FakeVir-B
Dec 12, 2005 7:13AM PST
- Collapse -
Troj/Puper-U
Dec 12, 2005 7:14AM PST
- Collapse -
Troj/GrayBrd-C
Dec 12, 2005 7:15AM PST