Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS ALERTS - December 30, 2005

Dec 29, 2005 8:17PM PST

W32/Brontok-L

Type
Worm

Aliases
Email-Worm.Win32.Brontok.c

W32/Brontok-L is an email worm for the Windows platform.

W32/Brontok-L attempts to send itself to email addresses harvested from the computer. The worm will also attempt to modify various Windows Explorer settings.

http://www.sophos.com/virusinfo/analyses/w32brontokl.html

Discussion is locked

- Collapse -
Troj/Jupdow-C
Dec 29, 2005 8:18PM PST

Type
Trojan

Aliases
Backdoor.Win32.Delf.ald
Proxy-Raser

Troj/Jupdow-C is a Trojan for the Windows platform.

Troj/Jupdow-C attempts to download configuration files from a remote website to
the Windows temp folder, and may then attempt to download files from further
websites.

http://www.sophos.com/virusinfo/analyses/trojjupdowc.html

- Collapse -
Troj/Paymite-H
Dec 29, 2005 8:20PM PST
- Collapse -
W32/Sdbot-AIL
Dec 29, 2005 8:21PM PST
- Collapse -
Troj/Riler-N
Dec 29, 2005 8:23PM PST
- Collapse -
Troj/Raser-D
Dec 29, 2005 8:25PM PST
- Collapse -
Troj/Ranck-DK
Dec 29, 2005 8:26PM PST
- Collapse -
Troj/DownLdr-NR
Dec 30, 2005 3:44AM PST
- Collapse -
Troj/DownLdr-NQ
Dec 30, 2005 3:46AM PST
- Collapse -
Troj/Codebase-P
Dec 30, 2005 3:47AM PST
- Collapse -
W32/Antiman-H
Dec 30, 2005 3:49AM PST
- Collapse -
Troj/Spywad-M
Dec 30, 2005 3:51AM PST
- Collapse -
Troj/Jupdrop-B
Dec 30, 2005 3:53AM PST
- Collapse -
Troj/DownLdr-NP
Dec 30, 2005 3:55AM PST

Type
Trojan

Aliases
Trojan-Downloader.Win32.Small.cdk

Troj/DownLdr-NP is a Trojan for the Windows platform.

Troj/DownLdr-NP includes functionality to access the internet and communicate with a remote server via HTTP and bypass personal firewall software.

http://www.sophos.com/virusinfo/analyses/trojdownldrnp.html

- Collapse -
Troj/Agent-JK
Dec 30, 2005 3:57AM PST
- Collapse -
Troj/Banload-Z
Dec 30, 2005 4:00AM PST
- Collapse -
Troj/Bancos-GD
Dec 30, 2005 4:01AM PST
- Collapse -
Troj/Vixup-U
Dec 30, 2005 4:53AM PST
- Collapse -
Troj/GrayBrd-U
Dec 30, 2005 4:55AM PST

Type
Trojan

Aliases
Backdoor.Win32.Hupigon.ri

Troj/GrayBrd-U is a backdoor Trojan for the Windows platform.

Troj/GrayBrd-U includes functionality to access the internet and communicate with a remote server via HTTP. The Trojan may also act as a proxy, allowing a remote intruder to route internet traffic through the infected computer.

http://www.sophos.com/virusinfo/analyses/trojgraybrdu.html

- Collapse -
Troj/Zlob-AY
Dec 30, 2005 4:57AM PST
- Collapse -
Troj/Feutel-BI
Dec 30, 2005 4:59AM PST

Type
Spyware Trojan

Aliases
Backdoor.Win32.Hupigon.le

Troj/Feutel-BI is a backdoor Trojan for the Windows platform.

Troj/Feutel-BI includes functionality to log keypresses, and to access the internet and communicate with a remote server via HTTP.

http://www.sophos.com/virusinfo/analyses/trojfeutelbi.html

- Collapse -
W32/Mytob-GK
Dec 30, 2005 5:04AM PST

Type
Worm

W32/Mytob-GK is an mass-mailing worm with backdoor functionality for the Windows platform.

W32/Mytob-GK runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

W32/Mytob-GK spreads by sending itself as an attachment to the email addresses harvested from files on the infected computer and from the Windows address book.

http://www.sophos.com/virusinfo/analyses/w32mytobgk.html

- Collapse -
Troj/Bancban-ND
Dec 30, 2005 5:06AM PST

Type
Spyware Trojan

Aliases
Trojan-Spy.Win32.Banbra.do

Troj/Bancban-ND is an internet banking Trojan for the Windows platform.

Troj/Bancban-ND monitors internet sessions and displays fake login pages when certain banking web sites are visited, in order to steal account details.

http://www.sophos.com/virusinfo/analyses/trojbancbannd.html

- Collapse -
Troj/BankDL-AF
Dec 30, 2005 5:08AM PST
- Collapse -
Troj/Shpiel-A
Dec 30, 2005 5:09AM PST

Type
Trojan

Troj/Shpiel-A is a backdoor Trojan for the Windows platform.

When first run Troj/Shpiel-A copies itself to the Windows folder with a name chosen randomly from the following list :

'msnupdate.exe'
'winfog.exe'
'winsys.exe'
'lsass1.exe'
'lovcx.exe'
'winsress.exe'
'winlog.exe'
'winsock.exe'
'saveruser.exe'
'winbackup.exe'

http://www.sophos.com/virusinfo/analyses/trojshpiela.html

- Collapse -
Troj/Bander-AC
Dec 30, 2005 5:12AM PST

Type
Spyware Trojan

Aliases
Trojan-Spy.Win32.Banker.alw

Troj/Bander-AC is an Internet banking Trojan for Windows platform.

Troj/Bander-AC has the functionalities to:

- display fake screens and messages
- steal information
- communicate with a remote server via email
- terminate AV related applications

http://www.sophos.com/virusinfo/analyses/trojbanderac.html

- Collapse -
Troj/Bander-U
Dec 30, 2005 5:14AM PST

Type
Spyware Trojan

Aliases
Trojan-Spy.Win32.Banker.ang

Troj/Bander-U is an Internet banking Trojan for Windows platform.

Troj/Bander-U has the functionalities to:

- display fake screens and messages
- steal information
- communicate with a remote server via email
- terminate AV related applications

http://www.sophos.com/virusinfo/analyses/trojbanderu.html

- Collapse -
Troj/Bander-V
Dec 30, 2005 5:15AM PST

Type
Spyware Trojan

Aliases
Trojan-Spy.Win32.Banker.alw

Troj/Bander-V is an Internet banking Trojan for Windows platform.

Troj/Bander-V has the functionalities to:

- display fake screens and messages
- steal information
- communicate with a remote server via email
- terminate AV related applications

http://www.sophos.com/virusinfo/analyses/trojbanderv.html

- Collapse -
Troj/Bandler-H
Dec 30, 2005 5:17AM PST
- Collapse -
W32/Sdbot-AKZ
Dec 30, 2005 8:17AM PST

Type Worm

Aliases W32/Sdbot.worm.gen.l

W32/Sdbot-AKZ is a worm with backdoor functionality for the Windows platform.
W32/Sdbot-AKZ runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32sdbotakz.html

- Collapse -
Troj/Zlob-BG
Dec 30, 2005 8:17AM PST