Version: 2008
  • On TV.com: TOP 10 Shows CANCELED Too Soon
Advanced Search
advertisement
advertisement
Click Here

Forum display:

Spyware, viruses, & security : VIRUS ALERTS - April 22, 2004

by Marianna Schmudlach Moderator - 4/22/04 7:03 AM
advertisement
Post 16 of 39

Troj/Agent-AA

by Marianna Schmudlach Moderator - 4/22/04 7:48 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Type
Trojan

Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/trojagentaa.html

Post 17 of 39

W32/Agobot-GN

by Marianna Schmudlach Moderator - 4/22/04 7:51 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Type
Win32 worm

At the time of writing, Sophos has received just one report of this worm from the wild.


Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/w32agobotgn.html

Post 18 of 39

W32/Agobot-KR

by Marianna Schmudlach Moderator - 4/22/04 7:53 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Type
Win32 worm

Sophos has received several reports of this worm from the wild.


Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/w32agobotkr.html

Post 19 of 39

W32/Rbot-F

by Marianna Schmudlach Moderator - 4/22/04 7:56 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Type
Win32 worm

At the time of writing, Sophos has received just one report of this worm from the wild.


Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/w32rbotf.html

Post 20 of 39

W32/Sdbot-HP

by Marianna Schmudlach Moderator - 4/22/04 7:59 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Type
Win32 worm

Description
W32/SdBot-HP is a worm which attempts to spread to remote network shares. It
also contains backdoor Trojan functionality, allowing unauthorised remote access
to the infected computer via IRC channels while running in the background as a service process.
W32/SdBot-HP spreads to network shares with weak passwords as a result of
the backdoor Trojan element receiving the appropriate command from a remote
user.

W32/Sdbot-HP may also spread using the vulnerability in Microsoft RPC-DCOM
service similar to W32/Blaster-A.


More: http://www.sophos.com/virusinfo/analyses/w32sdbothp.html

Post 21 of 39

Troj/Banker-R

by Marianna Schmudlach Moderator - 4/22/04 8:02 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Aliases
TrojanSpy.Win32.Banker.r

Type
Trojan

Description
Troj/Banker-R is a password stealing Trojan that attempts to capture keylogs
associated with web browsing.
Troj/Banker-R creates the following files which are all detected by this
identity:

<Windows>\dllreg.exe
<Windows>\sock64.dll
<StartUp>\rundllw.exe
<Windows System>\load32.exe
<Windows System>\vxdmgr32.exe

In order to run on system restart Troj/Banker-R creates the following
registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\load32

Troj/Banker-R attempts to send details to a Russian email address.

http://www.sophos.com/virusinfo/analyses/trojbankerr.html

Post 22 of 39

Troj/StartPa-AE

by Marianna Schmudlach Moderator - 4/22/04 10:08 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Aliases
Trojan.WinREG.StartPage

Type
Trojan

At the time of writing, Sophos has received just one report of this Trojan from the wild.


Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/trojstartpaae.html

Post 23 of 39

Troj/Mixtar-B

by Marianna Schmudlach Moderator - 4/22/04 10:12 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Aliases
DoS.Win32.Mixter, FDoS-Mixtar, Hacktool.DoS

Type
Trojan

At the time of writing, Sophos has received just one report of this Trojan from the wild.


Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/trojmixtarb.html

Post 24 of 39

Troj/Agent-E

by Marianna Schmudlach Moderator - 4/22/04 10:15 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Aliases
TrojanProxy.Win32.Agent.y, Proxy-Swiss

Type
Trojan

At the time of writing, Sophos has received just one report of this Trojan from the wild.


Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/trojagente.html

Post 25 of 39

Troj/Ketch-B

by Marianna Schmudlach Moderator - 4/22/04 10:18 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Aliases
Backdoor.Ketch.h

Type
Trojan

At the time of writing, Sophos has received just one report of this Trojan from the wild.


Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/trojketchb.html

Post 26 of 39

Troj/StartPa-GH

by Marianna Schmudlach Moderator - 4/22/04 10:20 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Aliases
Trojan.Win32.StartPage.gh

Type
Trojan

At the time of writing, Sophos has received just one report of this Trojan from the wild.


Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/trojstartpagh.html

Post 27 of 39

Troj/DeathCo-B

by Marianna Schmudlach Moderator - 4/22/04 10:23 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Aliases
Backdoor.VB.ph, VB-BackDoor.a.gen, Win32/VB.PH

Type
Trojan

At the time of writing, Sophos has received just one report of this Trojan from the wild.


Description
Troj/DeathCo-B is a backdoor Trojan that allows an attacker to remotely control a compromised computer.

http://www.sophos.com/virusinfo/analyses/trojdeathcob.html

Post 28 of 39

W32/FlyVB-A

by Marianna Schmudlach Moderator - 4/22/04 10:25 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Aliases
Worm.Win32.FlyVB, W32/Spidr@MM, W32.Spider.A@mm

Type
Win32 worm

At the time of writing, Sophos has received no reports from users affected by this worm. However, we have issued this advisory following enquiries to our support department from customers.


Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/w32flyvba.html

Post 29 of 39

Troj/Agent-L

by Marianna Schmudlach Moderator - 4/22/04 10:28 AM In reply to: VIRUS ALERTS - April 22, 2004 by Marianna Schmudlach Moderator

Type
Trojan

At the time of writing, Sophos has received just one report of this Trojan from the wild.


Description
A detailed analysis will be published here shortly. Please check again later.

http://www.sophos.com/virusinfo/analyses/trojagentl.html

Post 30 of 39

Re:Troj/Agent-L

by bigisle - 5/14/04 1:35 AM In reply to: Troj/Agent-L by Marianna Schmudlach Moderator

Aloha I have this worm on my computer.
Can you please direct me for directions to get it
off? Norton did not pick it up. But House Call Trend Micro did.
It was unable to clean it or delete it however.
Today is May 14th, I hope it is not too late to contact you about this and you can reply as soon as possible. Thank you,
Antoinette
islandantoinette@earthlink.net
OS is
I have a Pentium 4
Run Windows XP Home Edition
512 RAM
HD 30
HD 80
Flat Panel 15" Monitor Neovo Brand
Lexmark 3 in 1 printer
Apollo Printer (HP knock off)

Forum legend:
Locked Locked thread
Moderator Moderator
CNET staff CNET staff
Samsung staff Samsung staff
Norton Authorized Support team Norton Authorized Support team
AVG staff AVG staff
Windows Outreach team Windows Outreach team
Dell staff Dell staff
Intel staff Intel staff
Powered by Jive Software