Spyware, Viruses, & Security forum

General discussion

VIRUS ALERTS - January 15, 2007

W32/Rbot-GAY

Type Worm

W32/Rbot-GAY is a network worm with IRC backdoor functionality for the Windows platform.

W32/Rbot-GAY spreads to other network computers by:
- exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), SRVSVC (MS06-040), RPC-DCOM (MS04-012), PNP (MS05-039), ASN.1 (MS04-007) and RealVNC (CVE-2006-2369)
- networks protected by weak passwords

http://www.sophos.com/security/analyses/w32rbotgay.html

Discussion is locked
You are posting a reply to: VIRUS ALERTS - January 15, 2007
The posting of advertisements, profanity, or personal attacks is prohibited. Please refer to our CNET Forums policies for details. All submitted content is subject to our Terms of Use.
Track this discussion and email me when there are updates

If you're asking for technical help, please be sure to include all your system info, including operating system, model number, and any other specifics related to the problem. Also please exercise your best judgment when posting in the forums--revealing personal information such as your e-mail address, telephone number, and address is not recommended.

You are reporting the following post: VIRUS ALERTS - January 15, 2007
This post has been flagged and will be reviewed by our staff. Thank you for helping us maintain CNET's great community.
Sorry, there was a problem flagging this post. Please try again now or at a later time.
If you believe this post is offensive or violates the CNET Forums' Usage policies, you can report it below (this will not automatically remove the post). Once reported, our moderators will be notified and the post will be reviewed.
Collapse -
Troj/Agent-DYZ

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/WowPWS-AQ

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/Zlob-YF

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/DwnLdr-FXY

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/Lineag-I

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Infostealer.Rovbin

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
W32.Spybot.ANOO

In reply to: VIRUS ALERTS - January 15, 2007

Alert ID : FrSIRT/ALRT-2007-00383
Aliases : N/A
Size : 169984 bytes
Rated as : Low Risk
Release Date : 2007-01-15


Description

W32.Spybot.ANOO is a worm that opens a back door on the compromised computer, and spreads through mIRC and to network shares protected by weak passwords. It also spreads by exploiting system vulnerabilities.

References

http://www.symantec.com/enterprise/security_response/writeup.jsp?docid=2007-011510-4850-99

Credits

Reported by Symantec

Collapse -
TROJ_AGENT.JAW

In reply to: VIRUS ALERTS - January 15, 2007

Alert ID : FrSIRT/ALRT-2007-00382
Aliases : W32/Downloader.ARAT - Win32/SillyDl.BCL
Size : N/A
Rated as : Low Risk
Release Date : 2007-01-15


Description

A Trojan horse program is a malware that is not capable of automatically spreading to other systems. Trojans are usually downloaded from the Internet and installed by unsuspecting users.

References

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.JAW

Credits

Reported by Trend Micro

Collapse -
W32/Levona-C

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/DwnLdr-FXZ

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/Servu-EI

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/KitDBw-A

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
BDS/Ciadoor.13.C.2

In reply to: Troj/KitDBw-A

BDS/Ciadoor.13.C.2, Backdoor Trojan

Collapse -
Troj/ShipUp-B

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/DwnLdr-FXX

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/Bckdr-PVO

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
W32/Looked-BM

In reply to: VIRUS ALERTS - January 15, 2007

Type Worm

Aliases Worm.Win32.Viking.da
W32/HLLP.Philis.eh
PE_LOOKED.GD-O
TROJ_LOOKED.FW
W32/HLLP.Philis.dll

W32/Looked-BM is a virus and network worm for the Windows platform.

W32/Looked-BM infects files found on the local computer. W32/Looked-BM also copies itself to remote network shares and may infect files found on those shares.

http://www.sophos.com/virusinfo/analyses/w32lookedbm.html

Collapse -
Troj/Agent-DZE

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/DwnLdr-FYA

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/IRCBot-TN

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
W32.Rahack.W

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
W32/Levona-D

In reply to: VIRUS ALERTS - January 15, 2007

Type Worm

Aliases Email-Worm.Win32.Levona.e

W32/Levona-D is a worm for the Windows platform.

W32/Levona-D spreads to network shares and removable drives.

The worm will search for logical drives on the computer and copy itself to any found/

W32/Levona-D includes the functionality to disable or minimize many applications
by searching for certain words or phrases in the Windows Title Bar.

http://www.sophos.com/security/analyses/w32levonad.html

Collapse -
Troj/Lineag-AIR

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/Nugin-A

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/Nugin-B

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
Troj/Ranck-FA

In reply to: VIRUS ALERTS - January 15, 2007

Collapse -
W32/Rbot-GAU

In reply to: VIRUS ALERTS - January 15, 2007

Type Spyware Worm

Aliases WORM_SPYBOT.QY

W32/Rbot-GAU is a worm and IRC backdoor for the Windows platform.

W32/Rbot-GAU spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), SRVSVC (MS06-040), RPC-DCOM (MS04-012), Veritas (CAN-2004-1172) and ASN.1 (MS04-007). The worm may also spread via networks shares and MSSQL servers protected by weak passwords.

W32/Rbot-GAU runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32rbotgau.html

Collapse -
Troj/VB-CWO

In reply to: VIRUS ALERTS - January 15, 2007

Popular Forums

icon
Computer Newbies 10,686 discussions
icon
Computer Help 54,365 discussions
icon
Laptops 21,181 discussions
icon
Networking & Wireless 16,313 discussions
icon
Phones 17,137 discussions
icon
Security 31,287 discussions
icon
TVs & Home Theaters 22,101 discussions
icon
Windows 7 8,164 discussions
icon
Windows 10 2,657 discussions

SMART HOME

This one tip will help you sleep better tonight

A few seconds are all you need to get a better night's rest.