Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS ALERTS - December 9, 2005

Dec 8, 2005 8:12PM PST

Troj/Bancban-LB

Type
Spyware Trojan

Aliases
Trojan-Spy.Win32.Banker.ahy

Troj/Bancban-LB is a Trojan for the Windows platform.

Troj/Bancban-LB includes functionality to:

- access the internet and communicate with a remote server via HTTP
- send notification messages to remote locations

http://www.sophos.com/virusinfo/analyses/trojbancbanlb.html

Discussion is locked

- Collapse -
Troj/LegMir-BU
Dec 9, 2005 7:15AM PST
- Collapse -
Troj/GrayBrd-AW
Dec 9, 2005 7:16AM PST
- Collapse -
Troj/Feutel-AW
Dec 9, 2005 7:17AM PST
- Collapse -
Troj/Goldun-AL
Dec 9, 2005 7:18AM PST
- Collapse -
Troj/YSpy-A
Dec 9, 2005 7:19AM PST
- Collapse -
Troj/Bankem-L
Dec 9, 2005 7:19AM PST
- Collapse -
Troj/Bankem-M
Dec 9, 2005 7:20AM PST
- Collapse -
Troj/Bankem-N
Dec 9, 2005 7:21AM PST
- Collapse -
Troj/Bankem-O
Dec 9, 2005 7:22AM PST

Type Spyware Trojan

Aliases Trojan-Spy.Win32.Goldun.fq

Troj/Bankem-O is a password-stealing Trojan for the Windows platform.
Troj/Bankem-O includes functionality to access the internet and communicate with a remote server via HTTP.

http://www.sophos.com/virusinfo/analyses/trojbankemo.html

- Collapse -
W32/Rbot-BBA
Dec 9, 2005 10:15AM PST

Type Worm

Aliases Backdoor.Win32.Alicia.p

W32/Rbot-BBA is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-BBA can spread via network shares, MSSQL when it finds weak passwords, file sharing on P2P networks, or by exploiting common vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012), and WINS (MS04-045).
W32/Rbot-BBA runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/Rbot-BBA may attempts to disable various security related applications.
The following patches for the operating system vulnerabilities exploited by W32/Rbot-BBA can be obtained from the Microsoft website:
MS04-011
MS04-012
MS04-045

http://www.sophos.com/virusinfo/analyses/w32rbotbba.html

- Collapse -
W32/Gobot-N
Dec 9, 2005 10:16AM PST

Type Worm

Aliases WORM_GOBOT.H

W32/Gobot-N is a worm and IRC backdoor Trojan for the Windows platform.
W32/Gobot-N spreads to other network computers.
W32/Gobot-N runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32gobotn.html

- Collapse -
Troj/QQRob-AC
Dec 9, 2005 10:18AM PST
- Collapse -
Troj/AdClick-BG
Dec 9, 2005 10:19AM PST
- Collapse -
Troj/DNSChan-X
Dec 9, 2005 10:19AM PST
- Collapse -
Troj/Agent-QZ
Dec 9, 2005 10:20AM PST
- Collapse -
W32/Sdbot-AGI
Dec 9, 2005 10:21AM PST

Type Worm

W32/Sdbot-AGI is a worm and IRC backdoor Trojan for the Windows platform.
W32/Sdbot-AGI runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.
W32/Sdbot-AGI includes functionality to access the internet and communicate with a remote server via HTTP.

http://www.sophos.com/virusinfo/analyses/w32sdbotagi.html

- Collapse -
Troj/AdClick-BH
Dec 9, 2005 10:22AM PST
- Collapse -
Troj/OptixP-G
Dec 9, 2005 10:23AM PST
- Collapse -
Troj/Dumaru-AA
Dec 9, 2005 10:24AM PST
- Collapse -
Troj/Dumaru-AB
Dec 9, 2005 10:25AM PST
- Collapse -
W32/Loosky-F
Dec 9, 2005 10:25AM PST