Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - November 13, 2008

Nov 12, 2008 10:08AM PST

Discussion is locked

- Collapse -
W32/SillyFDC-CS
Nov 13, 2008 6:45AM PST

Category

* Viruses and Spyware

Type

* Worm

W32/SillyFDC-CS is a worm for the Windows platform.

On execution W32/SillyFDC-CS copies itself to:
<User>\Documents\Top Pictures.exe
<User>\My Documents\Sexy Pictures.exe
<Windows>\Windows Explorer.exe

The following registry entry is created to run W32/SillyFDC-CS on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Explorer
<Windows>\Windows Explorer.exe

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
HideFileExt

http://www.sophos.com/security/analyses/viruses-and-spyware/w32sillyfdccs.html?_log_from=rss

- Collapse -
W32/Brontok-W
Nov 13, 2008 6:47AM PST

Category

* Viruses and Spyware

Type

* Virus


W32/Brontok-W is an email worm for the Windows platform.

W32/Brontok-W attempts to send itself to email addresses harvested from the computer. The worm will also attempt to modify various Windows Explorer settings.

When first run W32/Brontok-W copies itself to:

<User>\Local Settings\Application Data\csrss.exe
<User>\Local Settings\Application Data\inetinfo.exe
<User>\Local Settings\Application Data\lsass.exe
<User>\Local Settings\Application Data\services.exe
<User>\Local Settings\Application Data\smss.exe
<User>\Start Menu\Programs\Startup\empty.gif
<Windows>\ShellNew\sempalong.exe
<Windows>\eksplorasi.exe

The following registry entries are created to run W32/Brontok-W on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Tok-Cirrhatus
<User>\Local Settings\Application Data\smss.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Bron-Spizaetus
<Windows>\ShellNew\sempalong.exe

More: http://www.sophos.com/security/analyses/viruses-and-spyware/w32brontokw.html?_log_from=rss

- Collapse -
W32/Autorun-OR
Nov 13, 2008 6:48AM PST
- Collapse -
W32/Autorun-OQ
Nov 13, 2008 6:49AM PST
- Collapse -
Troj/Psyme-KP
Nov 13, 2008 6:50AM PST
- Collapse -
Troj/FakeVir-HJ
Nov 13, 2008 6:51AM PST
- Collapse -
Troj/FakeVir-HH
Nov 13, 2008 6:53AM PST
- Collapse -
Troj/Buzus-V
Nov 13, 2008 6:54AM PST
- Collapse -
Troj/BHO-IA
Nov 13, 2008 6:56AM PST
- Collapse -
Mal/Bind-VB
Nov 13, 2008 6:57AM PST