Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS ALERTS - January 6, 2006

Jan 6, 2006 12:14AM PST

Troj/Bancban-NI

Type
Spyware Trojan

Aliases
Trojan-Spy.Win32.Banker.apt
PWS-Banker.gen.i

Troj/Bancban-NI is a password-stealing Trojan for the Windows platform.

Troj/Bancban-NI includes functionality to send notification messages to remote locations.

http://www.sophos.com/virusinfo/analyses/trojbancbanni.html

Discussion is locked

- Collapse -
Troj/ServU-BO
Jan 6, 2006 12:16AM PST
- Collapse -
Troj/LegMir-DZ
Jan 6, 2006 12:18AM PST
- Collapse -
Troj/Bancban-NH
Jan 6, 2006 12:21AM PST
- Collapse -
W32/Chode-R
Jan 6, 2006 12:23AM PST

Type
Worm

Aliases
Backdoor.Win32.Virkel.d
W32/Backdoor.HJJ

W32/Chode-R is an instant messaging worm for the Windows platform with IRC backdoor functionality.

W32/Chode-R attempts to spread via MSN Instant Messenger and AOL Instant Messenger by sending users a link to a copy of the worm.

http://www.sophos.com/virusinfo/analyses/w32choder.html

- Collapse -
W32/Rbot-BHT
Jan 6, 2006 12:54AM PST

Type
Worm

Aliases
Backdoor.Win32.Rbot.alt
W32/Sdbot.worm.gen.bh
W32.Spybot.Worm
WORM_SDBOT.CTV

W32/Rbot-BHT is a worm with backdoor functionality for the Windows platform.

W32/Rbot-BHT attempts to spread by copying itself to network shares protected by weak passwords.

W32/Rbot-BHT runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channels.

The worm contains functionality to modify the system hosts file and to terminate certain processes.

http://www.sophos.com/virusinfo/analyses/w32rbotbht.html

- Collapse -
W32/Feebs-C
Jan 6, 2006 12:56AM PST

Type
Spyware Worm

Aliases
JS/Kmax.gen@MM
JS_FEEBS.A
Worm.Win32.Feebs.g

W32/Feebs-C is a worm for the Windows platform.

The worm may arrive as an attachment to an email claiming to be sent via "Protected E-Mail service" with bogus credentials. The message may lure the recipient into entering the supplied credentials into an attached HTML document.

W32/Feebs-C spreads via file sharing on P2P networks.

http://www.sophos.com/virusinfo/analyses/w32feebsc.html

- Collapse -
Troj/VB-QD
Jan 6, 2006 12:58AM PST
- Collapse -
Troj/PWS-HU
Jan 6, 2006 1:00AM PST

Type
Spyware Trojan

Troj/PWS-HU is a password stealing Trojan for the Windows platform.

The Trojan steals usernames, passwords and email addresses from the infected computer.

Troj/PWS-HU may also attempt to download and install additional files.

http://www.sophos.com/virusinfo/analyses/trojpwshu.html

- Collapse -
Troj/Small-IE
Jan 6, 2006 1:03AM PST
- Collapse -
Troj/SmDown-A
Jan 6, 2006 1:05AM PST
- Collapse -
Troj/SmDown-B
Jan 6, 2006 1:19AM PST
- Collapse -
Troj/Banker-SV
Jan 6, 2006 1:21AM PST

Type
Spyware Trojan

Aliases
Trojan-Spy.Win32.Banker.ahy
PWS-Banker.gen.b
PWSteal.Bancos

Troj/Banker-SV is a Trojan for the Windows platform which attempts to capture confidential information related to Internet Banking, such as usernames and logon passwords.

Troj/Banker-SV includes functionality to send notification messages to remote locations.

Troj/Banker-SV may display fake login interfaces for certain Brazilian banking websites in order to steal login details. Any information retrieved in this manner is submitted to the author by email.

http://www.sophos.com/virusinfo/analyses/trojbankersv.html

- Collapse -
Troj/Small-IC
Jan 6, 2006 1:22AM PST
- Collapse -
Troj/Banload-JE
Jan 6, 2006 2:27AM PST
- Collapse -
Troj/Clicker-AZ
Jan 6, 2006 2:29AM PST
- Collapse -
Troj/Banload-HG
Jan 6, 2006 2:32AM PST
- Collapse -
Troj/Vixup-W
Jan 6, 2006 2:34AM PST
- Collapse -
Troj/Banload-HF
Jan 6, 2006 2:36AM PST
- Collapse -
Troj/Downldr-GX
Jan 6, 2006 2:38AM PST
- Collapse -
Troj/Banker-SW
Jan 6, 2006 2:40AM PST
- Collapse -
Troj/BagleDl-AO
Jan 6, 2006 3:45AM PST

Type
Trojan

Troj/BagleDl-AO is a Trojan for the Windows platform.

When first run, Troj/BagleDl-AO opens a graphics file named ntimage.gif with the default image viewer.

The latest Bagle Trojan horse open a graphics file when first run.

Troj/BagleDl-AO attempts to download files from a number of pre-specified URLs to a file <Windows folder\exefld\ <random number>.exe and run it.

http://www.sophos.com/virusinfo/analyses/trojbagledlao.html

- Collapse -
Troj/Jadown-A
Jan 6, 2006 3:47AM PST
- Collapse -
Troj/ConycSp-I
Jan 6, 2006 3:48AM PST
- Collapse -
Troj/PPdoor-Q
Jan 6, 2006 3:52AM PST

Type
Trojan

Aliases
Backdoor.Win32.PPdoor.bm
BackDoor-CHC

Troj/PPdoor-Q is a backdoor Trojan for the Windows platform.

Troj/PPdoor-Q includes functionality to access the internet and communicate with a remote server via HTTP.

Troj/PPdoor-Q attempts to disable some security related processes.

http://www.sophos.com/virusinfo/analyses/trojppdoorq.html

- Collapse -
Troj/Dloadr-ABS
Jan 6, 2006 3:54AM PST
- Collapse -
Troj/Kapod-N
Jan 6, 2006 3:56AM PST
- Collapse -
Troj/GrayBrd-K
Jan 6, 2006 3:57AM PST
- Collapse -
Troj/Feutel-AZ
Jan 6, 2006 4:00AM PST
- Collapse -
Troj/WinSpy-D
Jan 6, 2006 4:03AM PST

Type
Trojan

Aliases
Trojan-Spy.Win32.WinSpy.h

Troj/WinSpy-D is a Trojan for the Windows platform.

Registry entries are created under:

HKLM\SOFTWARE\MSN\
HKLM\SOFTWARE\Mail\
HKLM\SOFTWARE\NAVUpdater\
HKLM\SOFTWARE\Network\
HKLM\SOFTWARE\Out\
HKLM\SOFTWARE\SSET\
HKLM\SOFTWARE\SoundMaxDriver\
HKLM\SOFTWARE\VideoDriver\
HKLM\SOFTWARE\YahooMessenger\
HKLM\SOFTWARE\ZoneClient\

http://www.sophos.com/virusinfo/analyses/trojwinspyd.html

- Collapse -
Troj/DownLdr-FI
Jan 6, 2006 4:05AM PST