Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS ALERTS - January 2, 2006

Jan 1, 2006 10:42PM PST

Troj/Horst-C

Type
Spyware Trojan

Troj/Horst-C is a keylogging Trojan for the Windows platform.

When run Troj/Horst-C may display a fake error message box with the title "Version" and the message "Software incompatibility occured! Please download another version."

http://www.sophos.com/virusinfo/analyses/trojhorstc.html

Discussion is locked

- Collapse -
Troj/Dloadr-DP
Jan 2, 2006 7:31AM PST
- Collapse -
Troj/DownLdr-QC
Jan 2, 2006 7:32AM PST
- Collapse -
Troj/DownLdr-QD
Jan 2, 2006 7:33AM PST
- Collapse -
Troj/DownLdr-QF
Jan 2, 2006 7:33AM PST
- Collapse -
Troj/Whim-A
Jan 2, 2006 7:34AM PST
- Collapse -
Troj/YMob-A
Jan 2, 2006 7:35AM PST
- Collapse -
W32/Spybot-ET
Jan 2, 2006 2:29PM PST

Type Spyware Worm

Aliases W32/Spybot.worm.gen.o

W32/Spybot-ET is a worm and IRC backdoor Trojan for the Windows platform.
W32/Spybot-ET spreads via file sharing on P2P networks and to other network computers infected with: Troj/Kuang and Troj/Sub7.
W32/Spybot-ET runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32spybotet.html

- Collapse -
W32/Rbot-BHR
Jan 2, 2006 2:30PM PST

Type Spyware Worm

W32/Rbot-BHR is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-BHR spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012), WKS (MS03-049) (CAN-2003-0812), Veritas (CAN-2004-1172), PNP (MS05-039) and ASN.1 (MS04-007) and by copying itself to network shares protected by weak passwords.
W32/Rbot-BHR runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32rbotbhr.html

- Collapse -
Troj/Borobot-W
Jan 2, 2006 2:30PM PST
- Collapse -
W32/Agobot-UX
Jan 2, 2006 2:31PM PST

Type Worm

Aliases W32/Gaobot.worm.gen.t
Backdoor.Win32.Agobot.agh

W32/Agobot-UX is a worm and backdoor Trojan for the Windows platform.
W32/Agobot-UX runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer.

http://www.sophos.com/virusinfo/analyses/w32agobotux.html

- Collapse -
Troj/Delf-MO
Jan 2, 2006 2:32PM PST
- Collapse -
W32/Tilebot-CV
Jan 2, 2006 2:33PM PST

Type Worm

Aliases Backdoor.Win32.SdBot.xd
W32/Sdbot.worm.gen.l

W32/Tilebot-CV is a worm and IRC backdoor Trojan for the Windows platform.
W32/Tilebot-CV spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012), PNP (MS05-039) and ASN.1 (MS04-007), by copying itself to network shares protected by weak passwords and by AOL Instant Messenger.
W32/Tilebot-CV runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32tilebotcv.html

- Collapse -
Troj/Bankem-R
Jan 2, 2006 2:34PM PST
- Collapse -
Troj/Keylog-BM
Jan 2, 2006 2:35PM PST
- Collapse -
Troj/DownLdr-QE
Jan 2, 2006 2:36PM PST

Type Trojan

Troj/DownLdr-QE is a Trojan downloader for the Windows platform.
Troj/DownLdr-QE includes functionality to access the internet and communicate with a remote server via HTTP.
Troj/DownLdr-QE changes settings for Microsoft Internet Explorer, including the Start Page and Search Page, by modifying values under:
HKCU\Software\Microsoft\Internet Explorer\Main\Search Bar
HKCU\Software\Microsoft\Internet Explorer\Main\Search Page
HKCU\Software\Microsoft\Internet Explorer\Main\Start Page
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Page_URL
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Search Bar
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page

http://www.sophos.com/virusinfo/analyses/trojdownldrqe.html

- Collapse -
Troj/Vixup-V
Jan 2, 2006 2:36PM PST