Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS ALERTS - December 15, 2005

Dec 14, 2005 9:18PM PST

Discussion is locked

- Collapse -
Troj/Banload-AC
Dec 14, 2005 9:20PM PST
- Collapse -
Troj/Bancban-LV
Dec 14, 2005 9:21PM PST
- Collapse -
Troj/Bancban-LS
Dec 14, 2005 9:24PM PST
- Collapse -
Troj/Bancban-LT
Dec 14, 2005 9:26PM PST
- Collapse -
Troj/Dloadr-ABV
Dec 14, 2005 10:05PM PST

Type
Trojan

Aliases
Trojan-Downloader.Win32.Agent.zp

Troj/Dloadr-ABV is a Trojan for the Windows platform.

Troj/Dloadr-ABV has the following functionalities to:

- access the Internet and communicate with remote server
- modify dial up connection and Internet Explorer proxy settings
- establish dial up connection to a remote server

http://www.sophos.com/virusinfo/analyses/trojdloadrabv.html

- Collapse -
W32/Protorid-AF
Dec 14, 2005 10:06PM PST

Type
Worm

Aliases
Email-Worm.Win32.Mydoom.aw
W32.IRCBot.Gen

W32/Protorid-AF is a worm and IRC backdoor Trojan for the Windows platform.

W32/Protorid-AF has the functionalities to:

- spread via network shares
- provide a backdoor to allow remote access and control via IRC

http://www.sophos.com/virusinfo/analyses/w32protoridaf.html

- Collapse -
Troj/WinterLv-E
Dec 14, 2005 10:08PM PST
- Collapse -
Troj/Banker-UP
Dec 14, 2005 10:10PM PST

Type
Spyware Trojan

Aliases
Trojan-Spy.Win32.Banker.up
TSPY_BANCOS.ALK

Troj/Banker-UP is a password stealing Trojan targeted at customers of
Brazilian banks.

Troj/Banker-UP attempts to log keypresses entered into certain websites and
online banking applications. The Trojan may display fake user interfaces in
order to persuade the user to enter confidential details. Stolen information is
sent by email to a remote user.

http://www.sophos.com/virusinfo/analyses/trojbankerup.html

- Collapse -
W32/Rbot-BCE
Dec 14, 2005 10:11PM PST

Type
Spyware Worm

Aliases
Backdoor.Win32.Rbot.gen
W32/Sdbot.worm.gen.bz

W32/Rbot-BCE is a worm for the Windows platform.

W32/Rbot-BCE has the following functionalities to:

- allow access from a remote location
- steal information
- log keystrokes
- terminate processes

http://www.sophos.com/virusinfo/analyses/w32rbotbce.html

- Collapse -
Troj/Agent-FI
Dec 14, 2005 10:13PM PST
- Collapse -
Troj/BagleDl-AN
Dec 15, 2005 12:48AM PST

Type
Trojan

Troj/BagleDl-AN is a Trojan for the Windows platform.

When first run, Troj/BagleDl-AN opens a graphics file named ntimage.gif with the default image viewer.

Troj/BagleDl-AN attempts to download files from a number of pre-specified URLs.

http://www.sophos.com/virusinfo/analyses/trojbagledlan.html

- Collapse -
Troj/BagleDl-AO
Dec 15, 2005 8:49AM PST

Type Trojan

Troj/BagleDl-AO is a Trojan for the Windows platform.
When first run, Troj/BagleDl-AO opens a graphics file named ntimage.gif with the default image viewer.
Troj/BagleDl-AO attempts to download files from a number of pre-specified URLs to a file <Windows folder\exefld\<random number>.exe and run it.

http://www.sophos.com/virusinfo/analyses/trojbagledlao.html

- Collapse -
Troj/Jadown-A
Dec 15, 2005 8:50AM PST
- Collapse -
Troj/ConycSp-I
Dec 15, 2005 8:51AM PST
- Collapse -
Troj/PPdoor-Q
Dec 15, 2005 8:52AM PST

Type Trojan

Aliases Backdoor.Win32.PPdoor.bm
BackDoor-CHC

Troj/PPdoor-Q is a backdoor Trojan for the Windows platform.
Troj/PPdoor-Q includes functionality to access the internet and communicate with a remote server via HTTP.
Troj/PPdoor-Q attempts to disable some security related processes.

http://www.sophos.com/virusinfo/analyses/trojppdoorq.html

- Collapse -
Troj/Dloadr-ABS
Dec 15, 2005 8:53AM PST
- Collapse -
Troj/Kapod-N
Dec 15, 2005 8:53AM PST
- Collapse -
Troj/GrayBrd-K
Dec 15, 2005 8:55AM PST
- Collapse -
Troj/Feutel-AZ
Dec 15, 2005 8:55AM PST
- Collapse -
Troj/WinSpy-D
Dec 15, 2005 8:56AM PST

Type Trojan

Aliases Trojan-Spy.Win32.WinSpy.h

Troj/WinSpy-D is a Trojan for the Windows platform.
Registry entries are created under:
HKLM\SOFTWARE\MSN\
HKLM\SOFTWARE\Mail\
HKLM\SOFTWARE\NAVUpdater\
HKLM\SOFTWARE\Network\
HKLM\SOFTWARE\Out\
HKLM\SOFTWARE\SSET\
HKLM\SOFTWARE\SoundMaxDriver\
HKLM\SOFTWARE\VideoDriver\
HKLM\SOFTWARE\YahooMessenger\
HKLM\SOFTWARE\ZoneClient\

http://www.sophos.com/virusinfo/analyses/trojwinspyd.html

- Collapse -
Troj/DownLdr-FI
Dec 15, 2005 8:57AM PST
- Collapse -
Troj/Sdbot-AGX
Dec 15, 2005 8:58AM PST

Type Spyware Trojan

Troj/Sdbot-AGX is a backdoor Trojan for the Windows platform.
Troj/Sdbot-AGX enables a remote user to perform such actions as:
Record keystrokes and screenshots.
Use the infected computer as a proxy for mail or internet traffic.
Launch DDOS attacks.
Download new files.

http://www.sophos.com/virusinfo/analyses/trojsdbotagx.html

- Collapse -
Troj/Bancj-D
Dec 15, 2005 8:59AM PST

Type Spyware Trojan

Aliases Trojan-Spy.Win32.Banbra.df

Troj/Bancj-D is a Trojan for the Windows platform.
Troj/Bancj-D includes functionality to:
- access the internet and communicate with a remote server via HTTP
- send notification messages to remote locations
The Trojan monitors Internet Explorer windows for sessions with online banking web sites. The Trojan captures login credentials and sends stolen information to a remote attacker.

http://www.sophos.com/virusinfo/analyses/trojbancjd.html

- Collapse -
Troj/Bancban-MA
Dec 15, 2005 8:59AM PST

Type Spyware Trojan

Aliases Trojan-Spy.Win32.Banbra.df

Troj/Bancban-MA is a Trojan for the Windows platform.
Troj/Bancban-MA includes functionality to:
- access the internet and communicate with a remote server via HTTP
- send notification messages to remote locations
The Trojan monitors Internet Explorer windows for sessions with online banking web sites. The Trojan captures login credentials and sends stolen information to a remote attacker.

http://www.sophos.com/virusinfo/analyses/trojbancbanma.html

- Collapse -
Troj/Bancban-MB
Dec 15, 2005 9:00AM PST

Type Spyware Trojan

Aliases TSPY_BANBRA.CB
Trojan-Spy.Win32.Banbra.df

Troj/Bancban-MB is a Trojan for the Windows platform.
Troj/Bancban-MB includes functionality to:
- access the internet and communicate with a remote server via HTTP
- send notification messages to remote locations
The Trojan monitors Internet Explorer windows for sessions with online banking web sites. The Trojan captures login credentials and sends stolen information to a remote attacker.

http://www.sophos.com/virusinfo/analyses/trojbancbanmb.html

- Collapse -
Troj/LewDl-E
Dec 15, 2005 9:01AM PST
- Collapse -
W32/Dasher-B
Dec 15, 2005 9:02AM PST

Type Worm

Aliases Net-Worm.Win32.Reporter
W32/Dasher.worm

W32/Dasher-B is a worm for the Windows platform.
W32/Dasher-B spreads by exploiting the MSDTC (MS05-051) vulnerability.
When run the worm creates the following files :
<Windows system folder>\wins\sqlexp.exe
<Windows system folder>\wins\sqlscan.exe
<Windows system folder>\wins\svchost.exe
Sqlscan.exe is a port scanner, used to search networks for open ports.
Sqlexp.exe and svchost.exe are detected as W32/Dasher-B.
W32/Dasher-B searches a set of pre-defined networks for open ports and attempts to exploit and vulnerable computers it finds. The exploit opens a backdoor on the vulnerable computer and causes it to connect to a remote server for further instructions.
At the time of writing the instructions supplied by the remote server cause the exploited computer to download and execute two further programs.
A patch for the operating system vulnerabilty exploited by W32/Dasher-B is available from Microsoft:
MS05-051

http://www.sophos.com/virusinfo/analyses/w32dasherb.html

- Collapse -
W32/Tilebot-CP
Dec 15, 2005 9:03AM PST

Type Spyware Worm

Aliases Backdoor.Win32.SdBot.xd

W32/Tilebot-CP is a worm and IRC backdoor Trojan for the Windows platform.
W32/Tilebot-CP spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: WKS (MS03-049) (CAN-2003-0812), PNP (MS05-039) and ASN.1 (MS04-007) and by copying itself to network shares protected by weak passwords.
W32/Tilebot-CP runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32tilebotcp.html

- Collapse -
W32/Spybot-EM
Dec 15, 2005 9:04AM PST

Type Spyware Worm

Aliases Backdoor.Win32.IRCBot.gv

W32/Spybot-EM is a worm and backdoor Trojan for the Windows platform.
A remote intruder may use W32/Spybot-EM to download and execute further code, and to steal information by (for example) logging keystrokes and taking screenshots.

http://www.sophos.com/virusinfo/analyses/w32spybotem.html

- Collapse -
W32/Spybot-EN
Dec 15, 2005 9:05AM PST