Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS ALERTS - December 30, 2005

Dec 29, 2005 8:17PM PST

W32/Brontok-L

Type
Worm

Aliases
Email-Worm.Win32.Brontok.c

W32/Brontok-L is an email worm for the Windows platform.

W32/Brontok-L attempts to send itself to email addresses harvested from the computer. The worm will also attempt to modify various Windows Explorer settings.

http://www.sophos.com/virusinfo/analyses/w32brontokl.html

Discussion is locked

- Collapse -
W32/Sdbot-ALI
Dec 30, 2005 8:18AM PST

Type Worm

Aliases Backdoor.Win32.SdBot.ajx
W32/Sdbot.worm.gen.m

W32/Sdbot-ALI is a worm with backdoor functionality for the Windows platform.
W32/Sdbot-ALI spreads through network shares protected by weak passwords and through various operating system vulnerabilities, including ASN.1 (MS04-007).
W32/Sdbot-ALI runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32sdbotali.html

- Collapse -
W32/Tilebot-CT
Dec 30, 2005 8:19AM PST

Type Worm

Aliases Backdoor.Win32.SdBot.xd
StartPage-IH
W32.Spybot.Worm
WORM_SDBOT.CQV

W32/Tilebot-CT is a worm for the Windows platform.
W32/Tilebot-CT spreads to other network computers by means of:
- exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011) and RPC-DCOM (MS04-012)
- copying itself to network shares protected by weak passwords
- copying itself to MSSQL servers protected by weak passwords
W32/Tilebot-CT runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/Tilebot-CT includes functionality to:
- set up an FTP server
- set or remove network shares
- port scanning
- packet sniffing
- access the internet and communicate with a remote server via HTTP
- harvest information from clipboard
W32/Tilebot-CT includes functionality to access the internet and communicate with a remote server via HTTP.

http://www.sophos.com/virusinfo/analyses/w32tilebotct.html

- Collapse -
Troj/Hupigon-BQ
Dec 30, 2005 8:20AM PST
- Collapse -
Troj/Dloadr-DM
Dec 30, 2005 8:21AM PST
- Collapse -
Troj/Mosuck-S
Dec 30, 2005 8:22AM PST