Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS ALERTS - December 15, 2005

Dec 14, 2005 9:18PM PST

Discussion is locked

- Collapse -
W32/Antiman-G
Dec 15, 2005 9:06AM PST

Type Spyware Worm

Aliases PWS-Banker.gen.p
TSPY_BANCOS.BIA

W32/Antiman-G is an email worm for the Windows platform.
W32/Antiman-G includes functionality to access the internet and communicate with a remote server via HTTP, and may attempt to download a file from a remote website.
W32/Antiman-G may attempt to terminate processes, delete files and close windows related to certain anti-virus and security programs.
W32/Antiman-G logs user information and keystrokes, in particular those related to certain Brazilian banking websites.
W32/Antiman-G may send itself by email to addresses it harvests from the infected computer.

http://www.sophos.com/virusinfo/analyses/w32antimang.html

- Collapse -
W32/Bagle-AX
Dec 15, 2005 1:03PM PST

Type Worm

Aliases Email-Worm.Win32.Bagle.ex

W32/Bagle-AX is a mass-mailing worm for the Windows platform.
W32/Bagle-AX sends a ZIP file as an email attachment. The ZIP file contains an executable detected as Troj/BagleDl-AO.
Once installed, this executable attempts to download further files, which may include copies of the original worm W32/Bagle-AX.

http://www.sophos.com/virusinfo/analyses/w32bagleax.html

- Collapse -
Troj/IRCBot-AY
Dec 15, 2005 1:04PM PST
- Collapse -
Troj/Feutel-AX
Dec 15, 2005 1:04PM PST
- Collapse -
Troj/Feutel-AY
Dec 15, 2005 1:05PM PST
- Collapse -
Troj/BanLoad-AD
Dec 15, 2005 1:06PM PST
- Collapse -
Troj/Dcmbot-G
Dec 15, 2005 1:07PM PST
- Collapse -
W32/Rbot-BCL
Dec 15, 2005 1:08PM PST
- Collapse -
Troj/LewDr-A
Dec 15, 2005 1:09PM PST

Type Trojan

Aliases Trojan-Downloader.Win32.Zlob.cu

Troj/LewDr-A is a Trojan for the Windows platform.
Troj/LewDr-A will drop a file to the Windows system folder with the name mscornet.exe, this file is detected as Troj/LewDl-E.

http://www.sophos.com/virusinfo/analyses/trojlewdra.html

- Collapse -
Troj/Dcmbot-H
Dec 15, 2005 1:10PM PST