|
|
|
|
|
|||
|
|
March 2005 Select the links for detailed information and removal tools for the latest viruses
W32.Beagle.BG@mm W32.Beagle.BG@mm is a mass-mailing worm that uses its own SMTP engine to spread copies of Trojan.Tooso.B. The worm opens a back door and allows a remote attacker to have unauthorized access to the compromised computer. Payload:
Opens a back door and may act as an email relay.
Read the full Symantec report here Trojan.Tooso.C Trojan.Tooso.C is a Trojan horse that interferes with the operation of security software by terminating processes, stopping services, removing registry entries, and deleting files. This Trojan is similar to a variant of the W32.Beagle@mm family of worms, but it does not send emails. Read
the full Symantec report here
W32.Beagle.BH@mm W32.Beagle.BH@mm is a mass-worm that uses its own SMTP engine to send out copies of Trojan.Tooso.B. Trojan.Tooso.B then downloads W32.Beagle.BH@mm on to the compromised computer. The worm
also opens a back door on TCP port 80. Large scale
e-mailing: Sends a mass-mailing. Read the full Symantec report here W32.Spybot.KHO W32.Spybot.KHO is a worm that has distributed denial of service and back door capabilities. The worm spreads to network shares protected by weak passwords and by exploiting computer vulnerabilities. Payload:
Allows unauthorized remote access. Read the full Symantec report here Trojan.Tooso.D Trojan.Tooso.D is a Trojan horse that disables security software by terminating processes, stopping services, removing registry entries, and deleting files. This Trojan is similar to a variant of the W32.Beagle@mm family of worms, but it does not send emails. Deletes files:
Deletes files related to security programs. Read the full Symantec report here W32.Gaobot.CPX W32.Gaobot.CPX is a network-aware worm with back door, keylogging, and denial of service capabilities. The worm spreads by exploiting common system vulnerabilities, weak passwords and systems compromised by various back doors. Degrades
performance: System and Network performance may be degraded while performing
denial of service attacks. Read the full Symantec report here W32.Beagle.BI@mm W32.Beagle.BI@mm is a mass-mailing worm that uses its own SMTP engine to spread copies of Trojan.Tooso.C, which then downloads W32.Beagle.BI@mm on to the compromised computer. The worm also opens a back door on TCP port 80. Large scale
e-mailing: Sends a mass-mailing. Read
the full Symantec report here
W32.Beagle.BJ@mm W32.Beagle.BJ@mm is a mass-mailing worm that uses its own SMTP engine to send out copies of Trojan.Tooso.B, which then downloads W32.Beagle.BJ@mm on to the compromised computer. The worm
also opens a back door on TCP port 80. Large scale
e-mailing: Sends a mass-mailing. Read the full Symantec report here W32.Myfip.R W32.Myfip.R is a network-aware worm that steals files from a compromised computer. Degrades
performance: Network propagation may result in performance degradation.
Read the full Symantec report here W32.Assiral.B@mm W32.Assiral.B@mm is a mass-mailing worm that sends a copy of itself to email addresses gathered from a compromised computer. The worm also ends various processes, some of which may be security related. Large scale
e-mailing: Sends mass emails. Read the full Symantec report here VBS.Allem@mm BS.Allem@mm is a mass-mailing worm that sends itself to email addresses it finds in the Microsoft Outlook Address Book. It also spreads using MIRC, and copies itself as .VBS and .VBE files. VBS.Allem@mm is an encrypted VBScript worm that lowers security settings and deletes files. Large scale
e-mailing: Sends a mass-mailing. Read the full Symantec report here W32.Comdor.A@mm W32.Comdor.A@mm is a worm that downloads malware and sends itself to addresses found in the Windows Address Book using it's own SMTP engine. Payload:
Downloads and executes a remote file. Read the full Symantec report here Trojan.Tooso.E rojan.Tooso.E is a Trojan horse program that interferes with the operation of security software by terminating processes, removing registry entries, stopping services, and deleting files. Read the full Symantec report here Backdoor.Sdbot.AP Backdoor.Sdbot.AP is a worm with back door capabilities that gives an attacker remote access to the compromised computer via IRC channels. Payload:
Opens a back door on TCP port 7812. Read the full Symantec report here W32.Beagle.BK@mm W32.Beagle.BK@mm is a mass-mailing worm that uses its own SMTP engine to send out copies of Trojan.Tooso.E. The worm also opens a back door on the compromised computer through TCP port 80. Large scale
e-mailing: Sends an email to addresses that it downloads from a remote
computer. Read the full Symantec report here W32.Kobot.L W32.Kobot.L is a worm that spreads through open network shares and remotely exploitable vulnerabilities. The worm also has the ability to act as a back door server program and attack other systems. Payload:
Allows unauthorized remote access. Read the full Symantec report here W32.Kelvir.A W32.Kelvir.A is a worm that spreads through Windows and MSN Messenger. The worm attempts to download and execute a variant of W32.Spybot.Worm. The worm arrives in a Windows Messenger window with a link to the file cute.pif. Payload: Downloads and executes a remote file.Target of infection: Spreads via MSN Messenger. Read the full Symantec report here Download the Removal Tool here W32.Kelvir.B W32.Kelvir.B is a worm that spreads through Windows Messenger and MSN Messenger and attempts to download and execute a variant of W32.Spybot.Worm. Payload:
Dropped W32.Spybot.Worm variant may open a back door. Read the full Symantec report here Download the Removal Tool here W32.Kelvir.C W32.Kelvir.C is a worm that spreads through Windows Messenger and MSN Messenger and drops a variant of W32.Spybot.Worm. Payload:
May open a back door. Read the full Symantec report here Download the Removal Tool here W32.Serflog.A W32.Serflog.A is a worm that spreads through file-sharing networks and MSN Messenger. The worm also lowers security settings. Compromises
security settings: Blocks access to security-related Web sites and terminates
security-related processes. Read the full Symantec report here W32.Sober.L@mm W32.Sober.L@mm is a mass-mailing worm that uses its own SMTP engine to spread. The email may be in either English or German. The email has a variable subject and attachment name. The attachment has a .zip file extension. Large scale
e-mailing: Sends email to all addresses harvested from the compromised
computer. Read the full Symantec report here W32.Kelvir.D W32.Kelvir.D is a worm that drops a variant of W32.Spybot.Worm and spreads through MSN Messenger and by exploiting vulnerabilities. Payload:
Drops and executes a variant of W32.Spybot.Worm which may open a back
door. Read the full Symantec report here Download the Removal Tool here W32.Serflog.B W32.Serflog.B is a worm that spreads through file-sharing networks and MSN Messenger. The worm also lowers security settings. The worm arrives via an MSN Messenger window with a blank message. Compromises
security settings: Blocks access to security-related Web sites and terminates
security-related processes. Read the full Symantec report here W32.Myfip.T W32.Myfip.T is a network-aware worm that steals files from a compromised computer. Releases
confidential info: May send confidential documents to an external location.
Read the full Symantec report here W32.Kelvir.E W32.Kelvir.E is a worm that drops a variant of W32.Spybot.Worm and spreads through MSN Messenger and by exploiting vulnerabilities. Payload Trigger:
Drops and executes a variant of W32.Spybot.Worm which may open a back
door. Read the full Symantec report here W32.Toxbot W32.Toxbot is a worm that opens an IRC back door on the compromised computer and spreads by exploiting vulnerabilities. Payload:
Opens a back door. Read the full Symantec report here W32.Toxbot.B W32.Toxbot.B is a worm that opens an IRC back door on the compromised computer and spreads by exploiting vulnerabilities. Payload:
Opens a back door. Read the full Symantec report here W32.Kelvir.F W32.Kelvir.F is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm. Payload:
Drops and executes a variant of W32.Spybot.Worm which may open a back
door. Read the full Symantec report here W32.Mytob.E@mm W32.Mytob.E@mm is a mass-mailing worm that uses it own SMTP engine to send an email to addresses that it gathers from the Windows Address Book on the compromised computer. The worm also has the ability to open a back door and spread through the network by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow vulnerability (described in Microsoft Security Bulletin MS04-011). Payload: Opens a back door.Large scale e-mailing: Sends an email to addresses gathered from the compromised computer. Subject of email: Varies. Name of attachment: Varies with a .bat, .cmd, .exe, .pif, .scr, or .zip file extension. Ports: TCP port s445 and 6667. Read the full Symantec report here W32.Selotima.A W32.Selotima.A is a worm that propagates through file-sharing networks and inserts itself into .zip and .rar archives. Modifies
files: Inserts itself as Readme.txt.exe into .zip or .rar files. Read the full Symantec report here W32.Chod@mm W32.Chod@mm is a mass-mailing worm that also propagates using MSN Messenger. The worm has back door capabilities and can be controlled through IRC channels. It also overwrites the Hosts file and lowers security settings. Payload:
Opens and back door. Read the full Symantec report here W32.Mytob.G@mm W32.Mytob.G@mm is a mass-mailing worm that uses it own SMTP engine to send an email to addresses that it gathers from the compromised computer. The worm also has the ability to spread through the network by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011) and open a back door. Payload: Drops and executes a W32.Spybot.Worm variant which may open a back door.Large scale e-mailing: Sends an email to addresses gathered from the compromised computer. Modifies files: Modifies the hosts file. Compromises security settings: Blocks access to security-related Web sites. Subject of email: Varies Name of attachment: Varies with a .bat, .cmd, .exe, .pif, .scr, or .zip file extension. Size of attachment: approximately 52 Kb Ports: Random TCP ports between 1000 to 65535 Read the full Symantec report here W32.Mytob.F@mm W32.Mytob.F@mm is a mass-mailing worm that uses it own SMTP engine to send an email to addresses that it gathers from the Windows Address Book on the compromised computer. The email has a variable subject and attachment name. The attachment has a .bat, .cmd, .exe, .pif, .scr, or .zip file extension. The worm also has the ability to open a back door and spread through the network by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011). Payload: Opens a back door.Large scale e-mailing: Sends an email to addresses gathered from the compromised computer. Compromises security settings: Blocks access to security-related Web sites. Subject of email: Varies Name of attachment: Varies with a .bat, .cmd, .exe, .pif, .scr, or .zip file extension. Ports: TCP port 8080. Read the full Symantec report here W32.Kelvir.H W32.Kelvir.H is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm. Read
the full Symantec report here
W32.Elitper.D@mm W32.Elitper.D@mm is a mass-mailing worm that also attempts to spread using file-sharing networks. It also terminates processes, deletes files, and lowers Windows security settings. Large scale
e-mailing: Sends a copy of itself to email addresses gathered from the
compromised computer. Read the full Symantec report here W32.Kelvir.G W32.Kelvir.G is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm. Read the full Symantec report here W32.Serflog.C 2.Serflog.C is a worm that spreads through file-sharing networks and MSN Messenger. The worm also lowers security settings. Compromises
security settings: Blocks access to security-related Web sites and terminates
security-related processes. Read the full Symantec report here W32.Randex.CZZ W32.Randex.CZZ is a network-aware worm that will attempt to connect to a predetermined IRC server to receive instructions from a remote attacker. Payload:
Opens a back door. Read the full Symantec report here VBS.Scafene@mm VBS.Scafene@mm is a mass-mailing worm that uses Microsoft Outlook to send itself to all email addresses in the Microsoft Outlook address book. It also attempts to spread itself through mIRC. The worm overwrites all .vbs and .vbe files with its code. Large scale
e-mailing: Sends itself to all email addresses in the Microsoft Outlook
address book. Read the full Symantec report here W32.Mytob.H@mm 32.Mytob.H@mm is a mass-mailing worm that has back door capabilities and uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer. The worm spreads through the network by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011), and by copying itself to unprotected shares. Payload: Opens a back door on port TCP port 6667.Large scale e-mailing: Sends an email to addresses gathered from the compromised computer. Degrades performance: Modifies the Hosts file. Compromises security settings: Blocks access to security-related Web sites. Subject of email: Varies. Name of attachment: Varies. Ports: TCP port 6667, random TCP port between 1000 to 65535. Read the full Symantec report here W32.Mytob.I@mm W32.Mytob.I@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer. The worm also spreads by exploiting the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS03-026) using TCP port 135. Payload:
Lowers Security Settings Read the full Symantec report here W32.Kelvir.I W32.Kelvir.I is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm. Payload:
Drops and executes a variant of W32.Spybot.Worm. Read the full Symantec report here W32.Mydoom.BG@mm W32.Mydoom.BG@mm is a mass-mailing worm that uses its own SMTP engine to send out an email message that contains a link to a web site with a copy of itself. The worm then downloads a PWSteal.Trojan onto the compromised computer. Payload:
Downloads and executes a back door Trojan. Read the full Symantec report here W32.Mytob.J@mm W32.Mytob.J@mm is a mass-mailing worm that has back door capabilities and uses its own SMTP engine to send emails to addresses that it gathers from the compromised computer. The worm spreads through the network by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011). Payload Trigger: Opens a back door.Large scale e-mailing: Sends emails Compromises security settings: Blocks access to several security-related Web sites. Distribution Subject of email: Varies Name of attachment: Varies Ports: Random TCP ports Read the full Symantec report here W32.Reidana.A W32.Reidana.A is a worm that spreads by using the Microsoft Windows DCOM RPC vulnerability (described in Microsoft Security Bulletin MS03-026). The worm attempts to download and execute a remote file. Payload:
Downloads and executes remote files. Read
the full Symantec report here
W32.Mytob.L@mm W32.Mytob.L@mm is a mass-mailing worm with back door capabilities. The worm uses its own SMTP engine to send email to addresses that it gathers from the compromised computer. The worm also spreads by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011). Payload:
Opens a back door. Read
the full Symantec report here
W32.Mytob.K@mm W32.Mytob.K@mm is a mass-mailing worm with back door capabilities. The worm uses its own SMTP engine to send email to addresses that it gathers from the compromised computer. The worm also spreads by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011). Payload:
Opens a back door. Read
the full Symantec report here
W32.Mytob.O@mm W32.Mytob.O@mm is a mass-mailing worm with back door capabilities. The worm uses its own SMTP engine to send email to addresses that it gathers from the compromised computer. The worm also spreads by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011). Payload:
Opens a back door. Read
the full Symantec report here
W32.Mytob.M@mm W32.Mytob.M@mm is a mass-mailing worm with back door capabilities. The worm uses its own SMTP engine to send email to addresses that it gathers from the compromised computer. The worm also spreads by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011). Payload:
Opens a back door. Read
the full Symantec report here
W32.Elitper.E@mm W32.Elitper.E@mm is a worm that attempts to spreads using MS Outlook and file-sharing networks. It also terminates processes, deletes files, and lowers Windows security settings. Large scale
e-mailing: Sends emails. Read the full Symantec report here W32.Mytob.Q@mm W32.Mytob.Q@mm is a mass-mailing worm with back door capabilities that is infected with W32.Pinfi. The worm uses its own SMTP engine to send email to addresses that it gathers from the compromised computer. The worm also spreads by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011) and the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (as described in Microsoft Security Bulletin MS03-026). Large scale
e-mailing: Sends an email to addresses gathered from the compromised computer.
Read
the full Symantec report here
W32.Mytob.S@mm W32.Mytob.S@mm is a mass-mailing worm with back door capabilities that uses its own SMTP engine to send email to addresses that it gathers from the compromised computer. The worm also spreads by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011). Payload:
Opens a back door. Read
the full Symantec report here
W32.Mytob.R@mm W32.Mytob.R@mm is a mass-mailing worm with back door capabilities that uses its own SMTP engine to send email to addresses that it gathers from the compromised computer. The worm also spreads by exploiting the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (as described in Microsoft Security Bulletin MS04-011) and the Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability (as described in Microsoft Security Bulletin MS03-026). Payload:
Opens a back door. Read
the full Symantec report here
W32.Kelvir.J W32.Kelvir.J is a worm that spreads through MSN Messenger. It attempts to download and execute a remote file. Payload:
Downloads a remote file which may allow unauthorized remote access. Read the full Symantec report here W32.Sory.A W32.Sory.A is a worm that spreads through network shares and steals confidential information. Logs the following information: Keystrokes
Read
the full Symantec report here
W32.Zori.B W32.Zori.B is a virus that spreads over Windows file shares and is written in Delphi. The virus also infects .exe files by writing its code to the beginning of the files. Nine days after the original infection, the virus begins to delete files from all disks. Deletes files:
Deletes files after nine days. Read the full Symantec report here W32.Sober.N@mm W32.Sober.N@mm is a mass-mailing worm that uses its own SMTP engine to send itself to addresses gathered from the compromised computer. The email will be in either English or German. Large scale
e-mailing: Sends an email to addresses gathered from a compromised computer.
Read the full Symantec report here W32.Kelvir.K W32.Kelvir.K is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm. Payload:
Attempts to drop and execute a variant of W32.Spybot.Worm. Read the full Symantec report here Trojan.Ascetic.B Trojan.Ascetic.B uses its own SMTP engine to send the email addresses that it finds on the infected computer to some predefined email addresses. The email address of the sender is spoofed. The subject is randomly generated text. Large scale
e-mailing: Sends an email to addresses gathered from a compromised computer.
Read the full Symantec report here W32.Ahker.F@mm W32.Ahker.F@mm is a mass-mailing worm that uses MAPI to send a copy of itself to email addresses gathered from the compromised computer. Large scale
e-mailing: Sends an email to addresses gathered from the compromised computer.
Read the full Symantec report here
|
|
©
Copyright 1999 - 2005 The Computer Wizard
|
||||