Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS ALERTS - January 5, 2006

Jan 5, 2006 12:17AM PST

Discussion is locked

- Collapse -
Troj/Dropper-DJ
Jan 5, 2006 12:19AM PST
- Collapse -
Troj/Dropper-DK
Jan 5, 2006 12:21AM PST
- Collapse -
Troj/GrayBrd-V
Jan 5, 2006 12:23AM PST
- Collapse -
Troj/Bugspr-A
Jan 5, 2006 12:25AM PST
- Collapse -
Troj/Ciadoor-AA
Jan 5, 2006 12:26AM PST
- Collapse -
Troj/Bancban-NG
Jan 5, 2006 12:28AM PST
- Collapse -
Troj/BankDl-AH
Jan 5, 2006 12:30AM PST
- Collapse -
Troj/Prorat-AZ
Jan 5, 2006 12:33AM PST

Type
Spyware Trojan

Aliases
Backdoor.Win32.Prorat.am
BackDoor-AVW

Troj/Prorat-AZ is a Trojan for the Windows platform.

Troj/Prorat-AZ has the functionalities to:

- allows a remote intruder to gain access and control over the infected computer
- log keystroke

http://www.sophos.com/virusinfo/analyses/trojprorataz.html

- Collapse -
Troj/DNSBust-E
Jan 5, 2006 12:37AM PST

Type
Trojan

Aliases
DNSChanger.a

Troj/DNSBust-E is a Trojan for the Windows platform.

Troj/DNSBust-E includes functionality to access the internet and communicate with a remote server via HTTP.

Troj/DNSBust-E may also attempt to modify DNS settings on the computer.

http://www.sophos.com/virusinfo/analyses/trojdnsbuste.html

- Collapse -
Troj/Bancos-IU
Jan 5, 2006 12:41AM PST
- Collapse -
Troj/Banload-HN
Jan 5, 2006 12:42AM PST
- Collapse -
Troj/DownLdr-QP
Jan 5, 2006 12:44AM PST
- Collapse -
W32/Rbot-BIS
Jan 5, 2006 12:46AM PST

Type
Worm

Aliases
StartPage-IH

W32/Rbot-BIS is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-BIS spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012), WKS(MS03-049) (CAN-2003-0812), MSSQL (MS02-039) (CAN-2002-0649) and ASN.1 (MS04-007) and by copying itself to network shares protected by weak passwords.

http://www.sophos.com/virusinfo/analyses/w32rbotbis.html

- Collapse -
W32/Rbot-BIT
Jan 5, 2006 12:48AM PST

Type
Worm

Aliases
Backdoor.Win32.Rbot.aie

W32/Rbot-BIT is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-BIT spreads to other network computers by exploiting common buffer
overflow vulnerabilities, including IIS5SSL (MS04-011) (CAN-2003-0719).

W32/Rbot-BIT runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
IRC channels.

http://www.sophos.com/virusinfo/analyses/w32rbotbit.html

- Collapse -
Troj/Dloader-WO
Jan 5, 2006 12:55AM PST
- Collapse -
Troj/StartPa-HN
Jan 5, 2006 12:58AM PST
- Collapse -
Troj/Dloader-WP
Jan 5, 2006 12:59AM PST
- Collapse -
Troj/Subot-D
Jan 5, 2006 1:26AM PST
- Collapse -
W32/Rbot-ASW
Jan 5, 2006 1:29AM PST

Type
Worm

W32/Rbot-ASW is an IRC worm and backdoor Trojan for the Windows platform.

W32/Rbot-ASW may spread by copying itself to network shares or by exploiting the vulnerabilities LSASS (MS04-011), RPC-DCOM (MS04-012), WKS (MS03-049), WebDav (MS03-007), IIS5SSL (MS04-011), UPNP (MS01-059), Veritas (CAN-2004-1172), Dameware (CAN-2003-1030) or ASN.1 (MS04-007).

W32/Rbot-ASW runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32rbotasw.html

- Collapse -
W32/Rbot-ASU
Jan 5, 2006 1:30AM PST

Type
Worm

Aliases
W32/Sdbot.worm.gen.l

W32/Rbot-ASU is a worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-ASU spreads by copying itself to network shares protected by weak passwords and to other network computers by exploiting common buffer overflow vulnerabilities, including: RPC-DCOM (MS04-012), PNP (MS05-039) and ASN.1 (MS04-007).

W32/Rbot-ASU runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

http://www.sophos.com/virusinfo/analyses/w32rbotasu.html

- Collapse -
Troj/Banker-FZ
Jan 5, 2006 1:32AM PST

Type
Spyware Trojan

Aliases
Trojan-Spy.Win32.Banbra.ek

Troj/Banker-FZ is a password stealing Trojan for the Windows platform.

Troj/Banker-FZ targets the customers of certain Brazilian online banking websites, by logging any keystrokes entered into any forms at those websites as well as creating screen grabs.

http://www.sophos.com/virusinfo/analyses/trojbankerfz.html

- Collapse -
Troj/BankDl-O
Jan 5, 2006 1:38AM PST
- Collapse -
Troj/Banker-FY
Jan 5, 2006 1:41AM PST
- Collapse -
W32/Feebs-A
Jan 5, 2006 2:28AM PST

Type
Spyware Worm

W32/Feebs-A is a worm for the Windows platform.

The worm may arrive as an attachment to an email claiming to be sent via "Protected E-Mail service" with bogus credentials. The message may lure the recipient into entering the supplied credentials into an attached HTML document.

W32/Feebs-A also creates several copies of itself in ZIP format in paths containing "share".

W32/Feebs-A may also harvest information from the infected computer and send stolen data to a remote user via FTP.

http://www.sophos.com/virusinfo/analyses/w32feebsa.html

- Collapse -
Troj/Bifrose-R
Jan 5, 2006 2:30AM PST
- Collapse -
Troj/Dloadr-ACP
Jan 5, 2006 2:32AM PST
- Collapse -
Troj/Bizves-C
Jan 5, 2006 2:33AM PST

Type
Trojan

Aliases
Exploit-ByteVerify

Troj/Bizves-C is a Trojan for the Windows platform.

Troj/Bizves-C creates a file named loadclean.exe in the Windows folder.
Loadclean.exe is detected by Sophos's anti-virus products as Troj/Bizves-Gen.

http://www.sophos.com/virusinfo/analyses/trojbizvesc.html

- Collapse -
Troj/Dloadr-ACQ
Jan 5, 2006 2:50AM PST

Type
Trojan

Aliases
Trojan-Downloader.Win32.Adload.j

Troj/Dloadr-ACQ is a downloader Trojan for the Windows platform.
The Trojan downloads a file to C:\drsmartload.exe and runs the downloaded file.

At the time of writing drsmartload.exe is detected by Sophos's anti-virus products as Troj/Drsmartl-C.

http://www.sophos.com/virusinfo/analyses/trojdloadracq.html

- Collapse -
Troj/Banload-CA
Jan 5, 2006 2:52AM PST
- Collapse -
Troj/Banload-CC
Jan 5, 2006 2:55AM PST