Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS ALERTS - December 19, 2005

Dec 18, 2005 11:46PM PST

Discussion is locked

- Collapse -
Troj/Dnet-C
Dec 18, 2005 11:48PM PST

Type
Trojan

Aliases
NetTool.Win32.Calc-DNet.h
Win32/TrojanProxy.DistNet.B
Win32/TrojanProxy.DistNet.B

Troj/Dnet-C launches a specific version of distributed.net's clean client application that is usually installed by a Trojan into the hidden folder IOSDT within the Windows system folder.

http://www.sophos.com/virusinfo/analyses/trojdnetc.html

- Collapse -
W32/Rbot-BDF
Dec 18, 2005 11:55PM PST

Type
Worm

Aliases
Backdoor.Win32.Rbot.gen
W32/Sdbot.worm.gen.bh
W32.Spybot.Worm
WORM_RBOT.CPU

W32/Rbot-BDF is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-BDF spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012), WKS (MS03-049) (CAN-2003-0812), PNP (MS05-039) and ASN.1 (MS04-007) and by copying itself to network shares protected by weak passwords.

W32/Rbot-BDF runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32rbotbdf.html

- Collapse -
Troj/CashGrab-I
Dec 18, 2005 11:57PM PST

Type
Spyware Trojan

Aliases
Trojan.Win32.Agent.cc

Troj/CashGrab-I is a Trojan for the Windows platform.

Troj/CashGrab-I monitors internet browser windows for certain banking URLs, attempting to steal information if it finds them.

Troj/CashGrab-I also contains browser redirecting functionality.

http://www.sophos.com/virusinfo/analyses/trojcashgrabi.html

- Collapse -
W32/Rbot-BDV
Dec 18, 2005 11:59PM PST

Type
Worm

Aliases
Backdoor.Win32.Aimbot.br

W32/Rbot-BDV is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-BDV spreads:

- by attempting to use AOL Instant Messenger
- to other network computers by exploiting common buffer overflow
vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012), WKS
(MS03-049), PNP (MS05-039) and ASN.1 (MS04-007)
- by copying itself to network shares and Microsoft SQL servers protected by
weak passwords

W32/Rbot-BDV runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.

http://www.sophos.com/virusinfo/analyses/w32rbotbdv.html

- Collapse -
Troj/Fiserv-A
Dec 19, 2005 12:01AM PST

Type
Trojan

Troj/Fiserv-A is a backdoor Trojan for the Windows platform.

Troj/Fiserv-A allows a remote intruder to use an infected computer as a file server, as well as run arbitrary programs.

Troj/Fiserv-A may attempt to hide its activities on an infected computer.

http://www.sophos.com/virusinfo/analyses/trojfiserva.html

- Collapse -
Troj/Dowdum-A
Dec 19, 2005 12:03AM PST

Type
Trojan

Aliases
Trojan-Downloader.Win32.Small.bav

Troj/Dowdum-A is a downloader Trojan for the Windows platform.

Troj/Dowdum-A attempts to download a file from a remote website to <Windows> \wmplayer.exe and execute it. This file is currently detected as Troj/Dumaru-BA.

http://www.sophos.com/virusinfo/analyses/trojdowduma.html

- Collapse -
Troj/Dowpok-A
Dec 19, 2005 12:05AM PST

Type
Trojan

Aliases
Exploit.VBS.Phel.bx
JS/Exploit-HelpXSite

Troj/Dowpok-A is a downloader Trojan.

Troj/Dowpok-A attempts to download a file from a remote website by exploiting the HTML Help Control Vulnerability (MS05-001). The downloaded file is currently detected as Troj/Inor-Fam.

http://www.sophos.com/virusinfo/analyses/trojdowpoka.html

- Collapse -
Troj/RuinDl-H
Dec 19, 2005 12:07AM PST
- Collapse -
Troj/Agent-GG
Dec 19, 2005 7:21AM PST

Type Trojan

Aliases Backdoor.Win32.Agent.ah
Trojan-Downloader.Win32.PurityScan.d
W32/Backdoor.ALU

Troj/Agent-GG is a Trojan for the Windows platform.
Troj/Agent-GG includes functionality to access the internet and communicate with a remote server via HTTP.

http://www.sophos.com/virusinfo/analyses/trojagentgg.html

- Collapse -
Troj/Haxdoor-FI
Dec 19, 2005 7:22AM PST
- Collapse -
Troj/VBDown-A
Dec 19, 2005 7:23AM PST
- Collapse -
Troj/Banload-AK
Dec 19, 2005 7:24AM PST
- Collapse -
Troj/Drocod-A
Dec 19, 2005 7:25AM PST

Type Trojan

Aliases Trojan-Downloader.JS.Cobase.d
Trojan-PSW.Win32.PdPinch.gen

roj/Drocod-A is a Trojan for the Windows platform.
Troj/Drocod-A contains a javascript file sp2.js, detected as Troj/Codebase-O, that it uses to attempt to execute another contained file web.exe, detected as Troj/LdPnch-Gen.

http://www.sophos.com/virusinfo/analyses/trojdrocoda.html

- Collapse -
Troj/Rider-AC
Dec 19, 2005 7:25AM PST

Type Trojan

Troj/Rider-AC is a downloader Trojan.
Troj/Rider-AC attempts to exploit a vulnerability associated with some versions of Microsoft Internet Explorer to load and run a remote file. This file is currently detected as Troj/Drocod-A.

http://www.sophos.com/virusinfo/analyses/trojriderac.html

- Collapse -
Troj/Codebase-O
Dec 19, 2005 7:26AM PST
- Collapse -
Troj/Dowlet-A
Dec 19, 2005 7:27AM PST
- Collapse -
Troj/LegMir-CC
Dec 19, 2005 7:28AM PST
- Collapse -
Troj/Lineage-BV
Dec 19, 2005 7:29AM PST

Type Spyware Trojan

Aliases Trojan-PSW.Win32.Gamania.be
PWS-Lineage

Troj/Lineage-BV is a password stealing Trojan for the Windows platform.
Troj/Lineage-BV includes functionality to access the internet and communicate with a remote server via HTTP.

http://www.sophos.com/virusinfo/analyses/trojlineagebv.html

- Collapse -
Troj/Lineage-PO
Dec 19, 2005 7:30AM PST
- Collapse -
Troj/Bancban-LE
Dec 19, 2005 7:31AM PST
- Collapse -
Troj/Bankem-P
Dec 19, 2005 7:32AM PST

Type Spyware Trojan

Aliases Trojan-Spy.Win32.Goldun.en
PWS-Banker.ar

Troj/Bankem-P is a Trojan for the Windows platform.
Troj/Bankem-P includes functionality to access the internet and communicate with a remote server via HTTP.

http://www.sophos.com/virusinfo/analyses/trojbankemp.html

- Collapse -
Troj/Bancban-LD
Dec 19, 2005 7:33AM PST
- Collapse -
W32/Feebs-A
Dec 19, 2005 2:04PM PST

Type Spyware Worm

W32/Feebs-A is a worm for the Windows platform.
The worm may arrive as an attachment to an email claiming to be sent via "Protected E-Mail service" with bogus credentials. The message may lure the recipient into entering the supplied credentials into an attached HTML document.
W32/Feebs-A also creates several copies of itself in ZIP format in paths containing "share".
W32/Feebs-A may also harvest information from the infected computer and send stolen data to a remote user via FTP.

http://www.sophos.com/virusinfo/analyses/w32feebsa.html

- Collapse -
Troj/Bifrose-R
Dec 19, 2005 2:04PM PST
- Collapse -
Troj/Dloadr-ACP
Dec 19, 2005 2:05PM PST
- Collapse -
Troj/Bizves-C
Dec 19, 2005 2:06PM PST

Type Trojan

Aliases Exploit-ByteVerify

Troj/Bizves-C is a Trojan for the Windows platform.
Troj/Bizves-C creates a file named loadclean.exe in the Windows folder.
Loadclean.exe is detected by Sophos's anti-virus products as Troj/Bizves-Gen.

http://www.sophos.com/virusinfo/analyses/trojbizvesc.html

- Collapse -
Troj/Dloadr-ACQ
Dec 19, 2005 2:07PM PST

Type Trojan

Aliases Trojan-Downloader.Win32.Adload.j

Troj/Dloadr-ACQ is a downloader Trojan for the Windows platform.
The Trojan downloads a file to C:\drsmartload.exe and runs the downloaded file.
At the time of writing drsmartload.exe is detected by Sophos's anti-virus products as Troj/Drsmartl-C.

http://www.sophos.com/virusinfo/analyses/trojdloadracq.html

- Collapse -
Troj/Banload-CA
Dec 19, 2005 2:08PM PST
- Collapse -
Troj/Banload-CC
Dec 19, 2005 2:09PM PST
- Collapse -
Troj/VBanker-C
Dec 19, 2005 2:10PM PST

Type Spyware Trojan

Aliases Trojan-Spy.Win32.Bancos.lo

Troj/VBanker-C is a Trojan for the Windows platform.
The Trojan monitors Internet Explorer windows for sessions with online banking web sites. The Trojan captures login credentials and sends stolen information to a remote attacker.

http://www.sophos.com/virusinfo/analyses/trojvbankerc.html