<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-33424336</id><updated>2011-12-13T19:57:08.512-08:00</updated><title type='text'>new virus</title><subtitle type='html'>in this site you can find free anti virus, anti spyware and anti malware, adware, brontok, brontok cleaner and firewall software for home or business</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>10</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-33424336.post-115669086697502259</id><published>2006-08-27T07:58:00.001-07:00</published><updated>2006-08-27T09:23:33.213-07:00</updated><title type='text'>Worm/NetSky.P - Worm</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;Worm/NetSky.P It contains an integrated SMTP engine in order to send emails. A direct connection with the destination server will be established. &lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;The body of the email is one of the following&lt;/strong&gt;:  I noticed that you have visited illegal websites.     See the name in the list!   , Important message, do not show this anyone!     your big love, ;-)   ,Thanks!     Protected message is attached.   ,Congratulations!,      your best friend.   ,Best wishes,      your friend.  , Your document is attached.  , See the file.   , Please see the attached file for details.   , Your document is attached to this mail.   , SMTP: Please confirm the attached message.   , You have written a very good text, excellent, good work!   , Your photo, uahhh.... , you are naked!   ,You have received an extended message. Please read the instructions.  , Partial message is available.  , Waiting for authentification.  , I hope the patch works.   , Here is the website. ;-)   , Your file is attached.   ,Do not visit this illegal websites!   , Delivered message is attached.   , I cannot believe that.   , I am shocked about your document!   , Please authenticate the secure message   , I have corrected your document.   , Here is my icq list.   , You got a new message.   , I hope you accept the result!  , Important message, do not show this anyone!   , Please read the document.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;&lt;/span&gt; &lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Subject: &lt;/strong&gt;One of the following:   • Re:approved; approved bil; Re:Approved document; Re:Bad request;       Re:Bill; data; Re:Delivery Server; Do you?; Does it matter?;       Re:Encrypted Mail; Re:Error; Re:Error in document; Re:Failure;       Re:file; Re:Free porn; Re:hello; Re:here; Re:Hi; Hi; I cannot forget      you!; important data; Internet Provider Abuse; Is that your password?;       Re:Its me; Re:List; Re:Message Error; Re:my bill; Re:my data;       Re:Order; Postcard; Re:Proof of concept; Re:Protected Mail Delivery;       Protected Mail System; Re:Protected Mail system; Re:Question;       Re:Request; Re:Sample; Re:Secure SMTP Message; Shocking document;       Fw:Warning again; Re:Status; Your day; Re:Your document; Re:your      document_all&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;Aliases:&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Symantec: W32.Netsky.P@mm &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Mcafee: W32/Netsky.p@MM &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Kaspersky: Email-Worm.Win32.NetSky.q &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• TrendMicro: WORM_NETSKY.P &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• F-Secure: Email-Worm.Win32.NetSky.q &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Sophos: W32/Netsky-P &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Panda: W32/Netsky.P.worm &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Grisoft: I-Worm/Netsky.Q &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• VirusBuster: I-Worm.Netsky.Q1 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Eset: Win32/Netsky.Q worm &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Bitdefender: &lt;strong&gt;Win32.Netsky.P@mm&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Verdana;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;Platforms / OS:&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 95 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 98 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 98 SE &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows NT &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows ME &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 2000 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows XP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;Side effects:&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Drops a malicious file &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Uses its own Email engine &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Registry modification&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33424336-115669086697502259?l=virusanti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/115669086697502259/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=33424336&amp;postID=115669086697502259' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115669086697502259'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115669086697502259'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/2006/08/wormnetskyp-worm.html' title='Worm/NetSky.P - Worm'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-33424336.post-115669061605918687</id><published>2006-08-27T07:55:00.000-07:00</published><updated>2006-08-27T09:27:14.646-07:00</updated><title type='text'>Worm/Bagz.D.3 - Worm</title><content type='html'>Worm/Bagz.D.3 make Side effects  Blocks access to certain websites ,Blocks access to security websites , Drops files ,Drops malicious files ,Uses its own Email engine ,Registry modification&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Aliases:&lt;/strong&gt;&lt;br /&gt;• Symantec: W32.Bagz.E@mm&lt;br /&gt;• Mcafee: W32/Bagz.e@MM&lt;br /&gt;• Kaspersky: Email-Worm.Win32.Bagz.d&lt;br /&gt;• TrendMicro: WORM_BAGZ.D&lt;br /&gt;• Sophos: W32/Bagz-D&lt;br /&gt;• Grisoft: I-Worm/Bagz.D&lt;br /&gt;• VirusBuster: I-Worm.Bagz.G&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Platforms / OS:&lt;/strong&gt;&lt;br /&gt;• Windows 98&lt;br /&gt;• Windows 98 SE&lt;br /&gt;• Windows NT&lt;br /&gt;• Windows ME&lt;br /&gt;• Windows 2000&lt;br /&gt;• Windows XP&lt;br /&gt;• Windows 2003&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33424336-115669061605918687?l=virusanti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/115669061605918687/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=33424336&amp;postID=115669061605918687' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115669061605918687'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115669061605918687'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/2006/08/wormbagzd3-worm.html' title='Worm/Bagz.D.3 - Worm'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-33424336.post-115669029795826420</id><published>2006-08-27T07:49:00.000-07:00</published><updated>2006-08-27T09:29:28.393-07:00</updated><title type='text'>BDS/Hupigon.E.201 - Backdoor Server</title><content type='html'>&lt;div align="justify"&gt;&lt;span style="font-family:verdana;"&gt;BDS/Hupigon.E.201 - Backdoor Server  Side effects Downloads a file and Drops malicious files , Records keystrokes and Registry modification , Steals information and Third party control&lt;br /&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;Aliases:&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Mcafee: BackDoor-AWQ.b.dr &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Kaspersky: Backdoor.Win32.Hupigon.bqp &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• TrendMicro: BKDR_HUPIGON.NP &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• F-Secure: Backdoor.Win32.Hupigon.bqp &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Sophos: Troj/Hupigo-BLN &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Bitdefender: Backdoor.Hupigon.E &lt;/span&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;Platforms / OS:&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 98 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 98 SE &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows NT &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows ME &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 2000 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows XP &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 2003&lt;/span&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33424336-115669029795826420?l=virusanti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/115669029795826420/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=33424336&amp;postID=115669029795826420' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115669029795826420'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115669029795826420'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/2006/08/bdshupigone201-backdoor-server.html' title='BDS/Hupigon.E.201 - Backdoor Server'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-33424336.post-115669016154837843</id><published>2006-08-27T07:47:00.000-07:00</published><updated>2006-08-27T09:31:18.226-07:00</updated><title type='text'>TR/PSW.Sinowal.V.5 - Trojan</title><content type='html'>&lt;span style="font-family:verdana;"&gt;TR/PSW.Sinowal.V.5 - Trojan&lt;/span&gt; virus make Side effects Drops malicious files and  Registry modification and Steals information , Third party control&lt;br /&gt;&lt;strong&gt;&lt;span style="font-family:verdana;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;Aliases:&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Kaspersky: Trojan-PSW.Win32.Sinowal.v &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• TrendMicro: TSPY_SINOWAL.V &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• F-Secure: Trojan-PSW.Win32.Sinowal.v &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Sophos: Troj/Torpig-AY &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Eset: Win32/TrojanDropper.Small.NEC &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Bitdefender: Trojan.PWS.Sinowal.U &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;strong&gt;Platforms / OS:&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 98 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 98 SE &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows NT &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows ME &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 2000 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows XP &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;• Windows 2003&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33424336-115669016154837843?l=virusanti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/115669016154837843/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=33424336&amp;postID=115669016154837843' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115669016154837843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115669016154837843'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/2006/08/trpswsinowalv5-trojan.html' title='TR/PSW.Sinowal.V.5 - Trojan'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-33424336.post-115669003626882175</id><published>2006-08-27T07:45:00.000-07:00</published><updated>2006-08-27T09:32:32.503-07:00</updated><title type='text'>TR/Dldr.Small.GI.1 - Trojan</title><content type='html'>TR/Dldr.Small.GI.1  make Side effects Downloads a malicious file&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Aliases: &lt;/strong&gt;&lt;br /&gt;• Kaspersky: Trojan-Downloader.Win32.Small.dnz&lt;br /&gt;• TrendMicro: TROJ_SMALL.CPM&lt;br /&gt;• Sophos: Troj/Dloadr-AMA&lt;br /&gt;• VirusBuster: Trojan.DL.Small.DPN&lt;br /&gt;• Eset: Win32/TrojanDownloader.Small.NOF&lt;br /&gt;• Bitdefender: Trojan.Downloader.Small.BGX&lt;br /&gt;&lt;br /&gt;&lt;strong&gt;Platforms / OS:&lt;/strong&gt;&lt;br /&gt;• Windows 95&lt;br /&gt;• Windows 98&lt;br /&gt;• Windows 98 SE&lt;br /&gt;• Windows NT&lt;br /&gt;• Windows ME&lt;br /&gt;• Windows 2000&lt;br /&gt;• Windows XP&lt;br /&gt;• Windows 2003&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33424336-115669003626882175?l=virusanti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/115669003626882175/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=33424336&amp;postID=115669003626882175' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115669003626882175'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115669003626882175'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/2006/08/trdldrsmallgi1-trojan.html' title='TR/Dldr.Small.GI.1 - Trojan'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-33424336.post-115668990260142634</id><published>2006-08-27T07:42:00.000-07:00</published><updated>2006-08-27T09:33:36.526-07:00</updated><title type='text'>TR/Spy.Small.GI - Trojan</title><content type='html'>&lt;span style="font-family:verdana;font-size:85%;"&gt;TR/Spy.Small.GI make Side effects Registry modification and Steals information&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Verdana;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Aliases:&lt;/strong&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;• Mcafee: Spy-Agent.bg &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;• Kaspersky: Trojan-Spy.Win32.Small.gi &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;• TrendMicro: TSPY_SMALL.CPO &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;• Eset: Win32/Spy.Small.GI &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Platforms / OS:&lt;/strong&gt; &lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;• Windows 98 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;• Windows 98 SE &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;• Windows NT &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;• Windows ME &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;• Windows 2000 &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;• Windows XP&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:verdana;"&gt;&lt;span style="font-size:85%;"&gt;• Windows 2003&lt;/span&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33424336-115668990260142634?l=virusanti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/115668990260142634/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=33424336&amp;postID=115668990260142634' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115668990260142634'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115668990260142634'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/2006/08/trspysmallgi-trojan.html' title='TR/Spy.Small.GI - Trojan'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-33424336.post-115668966111808298</id><published>2006-08-27T07:39:00.000-07:00</published><updated>2006-08-27T07:41:01.116-07:00</updated><title type='text'>JS/Wonka</title><content type='html'>&lt;div align="justify"&gt;&lt;strong&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;JS/Wonka Trojan&lt;/span&gt;&lt;/strong&gt;&lt;/div&gt;&lt;div align="justify"&gt;&lt;span style="font-family:verdana;font-size:85%;"&gt;This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33424336-115668966111808298?l=virusanti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/115668966111808298/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=33424336&amp;postID=115668966111808298' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115668966111808298'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115668966111808298'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/2006/08/jswonka.html' title='JS/Wonka'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-33424336.post-115668950010523549</id><published>2006-08-27T07:37:00.000-07:00</published><updated>2006-08-27T07:38:20.106-07:00</updated><title type='text'>Exploit-WMF</title><content type='html'>&lt;div align="justify"&gt;Trojan Exploit-WMF&lt;/div&gt;&lt;div align="justify"&gt;This is a trojan detection. Unlike viruses, trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted. The most common installation methods involve system or security exploitation, and unsuspecting users manually executing unknown programs. Distribution channels include email, malicious or hacked web pages, Internet Relay Chat (IRC), peer-to-peer networks, etc.&lt;br /&gt;Aliases&lt;br /&gt;Bloodhound.Exploit.56 (Symantec)&lt;br /&gt;Exploit.WMF&lt;br /&gt;PFV-Exploit &lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33424336-115668950010523549?l=virusanti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/115668950010523549/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=33424336&amp;postID=115668950010523549' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115668950010523549'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115668950010523549'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/2006/08/exploit-wmf.html' title='Exploit-WMF'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-33424336.post-115668841502644537</id><published>2006-08-27T07:16:00.000-07:00</published><updated>2006-08-27T09:35:17.576-07:00</updated><title type='text'>IRC-Mocbot!MS06-040</title><content type='html'>&lt;div align="justify"&gt;&lt;strong&gt;IRC-Mocbot&lt;/strong&gt; &lt;/div&gt;&lt;div align="justify"&gt; &lt;/div&gt;&lt;div align="justify"&gt;This is a detection for variants of IRC-Mocbot that exploits the Microsoft Windows Server Service Buffer Overflow MS06-040 against Windows 2000 machines.&lt;br /&gt;This worm installs itself in the WINDOWS SYSTEM directory (typically c:\windows\system32) as wgareg.exe (MD5: 9928a1e6601cf00d0b7826d13fb556f0) or wgavm.exe (MD5: 2bf2a4f0bdac42f4d6f8a062a7206797). It creates a service(s) with the following properties:&lt;br /&gt;Name: wgareg&lt;br /&gt;Display name: Windows Genuine Advantage Registration Service&lt;br /&gt;Description: Ensures that your copy of Microsoft Windows is genuine and registered. Stopping or disabling this service will result in system instability.&lt;br /&gt;Name: wgavm&lt;br /&gt;Display name: Windows Genuine Advantage Validation Monitor&lt;br /&gt;Description: Ensures that your copy of Microsoft Windows is genuine. Stopping or disabling this service will result in system instability..&lt;br /&gt;(The "Windows Genuine Advantage"programs installed by Microsoft via Windows Update does not typically contain a wgareg.exe or wgavm.exe file in the WINDOWS SYSTEM directory)&lt;br /&gt;&lt;br /&gt;Aliases&lt;br /&gt;Backdoor.Win32.IRCBot.st (Kaspersky)&lt;br /&gt;Backdoor:Win32/Graweg.A (Microsoft)&lt;br /&gt;Backdoor:Win32/Graweg.B (Microsoft)&lt;br /&gt;CME-482&lt;br /&gt;CME-762&lt;br /&gt;W32.Wargbot (Symantec)&lt;br /&gt;W32/Cuebot-L (Sophos)&lt;br /&gt;W32/Cuebot-M (Sophos)&lt;br /&gt;WORM_IRCBOT.JK (TrendMicro)&lt;br /&gt;WORM_IRCBOT.JL (TrendMicro)&lt;br /&gt;Characteristics&lt;br /&gt;This is a detection for a variant of IRC-Mocbot that exploits the Microsoft Windows Server Service Buffer Overflow MS06-040 against Windows 2000 machines.&lt;br /&gt;This worm installs itself in the WINDOWS SYSTEM directory (typically c:\windows\system32) as wgareg.exe (MD5: 9928a1e6601cf00d0b7826d13fb556f0) or wgavm.exe (MD5: 2bf2a4f0bdac42f4d6f8a062a7206797). It creates a service(s) with the following properties:&lt;br /&gt;Name: wgareg&lt;br /&gt;Display name: Windows Genuine Advantage Registration Service&lt;br /&gt;Description: Ensures that your copy of Microsoft Windows is genuine and registered. Stopping or disabling this service will result in system instability.&lt;br /&gt;Name: wgavm&lt;br /&gt;Display name: Windows Genuine Advantage Validation Monitor&lt;br /&gt;Description: Ensures that your copy of Microsoft Windows is genuine. Stopping or disabling this service will result in system instability..&lt;br /&gt;(The "Windows Genuine Advantage"programs installed by Microsoft via Windows Update does not typically contain a wgareg.exe or wgavm.exe file in the WINDOWS SYSTEM directory)&lt;br /&gt;As in the older variants, this bot first attempts to connect to the following IRC servers on TCP 18067:&lt;br /&gt;bbjj.househot.com&lt;br /&gt;ypgw.wallloan.com&lt;br /&gt;The bot connects to a specified channel and awaits commands, including:&lt;br /&gt;DDoS&lt;br /&gt;Scan (for vulnerable systems)&lt;br /&gt;Download / execute remote files&lt;br /&gt;Once instructed, the bot scans the class A subnet addresses, sending SYN packets via TCP 139 (netbios), and 445 (microsoft-ds), looking for systems vulnerable to the MS06-040 vulnerability. When a vulnerable system is discovered, the infected host causes a buffer overflow to occur on the remote system, instructing it to download Mocbot, save it to the WINDOWS SYSTEM directory as a file named .exe and then execute it. Unlike many exploiting bots, Mocbot doesn't use FTP or TFTP to achieve the downloading, but rather contains its own downloader code. The remote system downloads the worm via a random TCP port..&lt;br /&gt;Symptoms&lt;br /&gt;Heavy netbios and microsoft-ds network traffic&lt;br /&gt;Presense of the file wgareg.exe or wgavm.exe in the WINDOWS SYSTEM directory&lt;br /&gt;TCP 18067 connections to bniu.househot.com, bbjj.househot.com or ypgw.wallloan.com&lt;br /&gt;The following registry key(s) may be added or modified to disable the Windows Security Center firewall and anti-virus monitors:&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft&lt;/div&gt;&lt;div align="justify"&gt;\Ole\EnableDCOM = "n"&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\security center\antivirusdisablenotify = 0x00000001&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\security center\antivirusoverride = 0x00000001&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\security center\firewalldisablenotify = 0x00000001&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\security center\firewalldisableoverride = 0x00000001&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Lsa\restrictanonymous = 0x00000001&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft&lt;/div&gt;&lt;div align="justify"&gt;\windowsfirewall\standardprofile\enablefirewall = 0x00000000&lt;br /&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft&lt;/div&gt;&lt;div align="justify"&gt;\windowsfirewall\domainprofile\enablefirewall = 0x00000000&lt;br /&gt;HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SharedAccess\Start = 0x00000004&lt;br /&gt;&lt;br /&gt;Method of InfectionThis worm spreads by exploitin the MS06-040 vulnerability.&lt;br /&gt;Removal&lt;br /&gt;All Users:Please update to 4828 (08/13/2006) or later DAT release package&lt;br /&gt;Intrushield protects against this threat with sigset(s) 3.1.19, 2.1.46, 1.9.63, 1.8.80 released on?/8/2006.&lt;br /&gt;Buffer Overflow Protection in VirusScan Enterprise 8.0 and VirusScan Consumer 11 does NOT protect against this threat.&lt;br /&gt;Modifications made to the system Registry and/or INI files for the purposes of hooking system startup, will be successfully removed if cleaning with the recommended engine and DAT combination (or higher).&lt;br /&gt;Additional Windows ME/XP removal considerations&lt;br /&gt;This threat modifies a number of system configurations that includes disabling the default Windows Firewall on the infected machine. These changes should be manually configured.&lt;br /&gt;&lt;br /&gt;Variants&lt;br /&gt;Variants&lt;br /&gt;N/A&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33424336-115668841502644537?l=virusanti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/115668841502644537/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=33424336&amp;postID=115668841502644537' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115668841502644537'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115668841502644537'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/2006/08/irc-mocbotms06-040.html' title='IRC-Mocbot!MS06-040'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-33424336.post-115668429261437051</id><published>2006-08-27T05:48:00.000-07:00</published><updated>2006-08-27T09:36:29.723-07:00</updated><title type='text'>TR/Spy.Banker.819156</title><content type='html'>&lt;div align="left"&gt;TR/Spy.Banker.819156 make Side effects Uses its own Email engine and Registry modification , Steals information.&lt;br /&gt;&lt;br /&gt;Virus: TR/Spy.Banker.819156&lt;br /&gt;Date discovered: 02/07/2006&lt;br /&gt;Type: Trojan&lt;br /&gt;In the wild: No&lt;br /&gt;Reported Infections: Low&lt;br /&gt;Distribution&lt;br /&gt;Potential: Low&lt;br /&gt;Damage Potential: Medium&lt;br /&gt;Static file: Yes&lt;br /&gt;&lt;br /&gt;Aliases:&lt;br /&gt;• Kaspersky: Trojan-Spy.Win32.Banker.anv&lt;br /&gt;• TrendMicro: TSPY_BANKER.OK&lt;br /&gt;• F-Secure: Trojan-Spy.Win32.Banker.anv&lt;br /&gt;• Eset: Win32/Spy.Banker.ANV&lt;br /&gt;&lt;br /&gt;Platforms / OS:&lt;br /&gt;• Windows 98&lt;br /&gt;• Windows 98 SE&lt;br /&gt;• Windows NT&lt;br /&gt;• Windows ME&lt;br /&gt;• Windows 2000&lt;br /&gt;• Windows XP&lt;br /&gt;• Windows 2003&lt;br /&gt;&lt;br /&gt;Side effects:&lt;br /&gt;• Uses its own Email engine&lt;br /&gt;• Registry modification&lt;br /&gt;• Steals information&lt;br /&gt;&lt;br /&gt;It doesn't have its own spreading routine but it has the ability to send an email. It is most likely that the receiver is the author. The characteristics are described below:&lt;br /&gt;&lt;br /&gt;Email design:&lt;br /&gt;From: "Infectou"&lt;br /&gt;To: xptoban@gmail.com;cyberband74@gmail.com&lt;br /&gt;Subject: %computer name%&lt;br /&gt;Body: • -~*´¨¯¨`*·~-.¸-()-,.-~*´¨¯¨`*·~-.¸&lt;br /&gt;[Infectado OnLine]:&lt;br /&gt;Maquina.............: %computer name%&lt;br /&gt;IP..................: %IP address%&lt;br /&gt;Data................: %current date%&lt;br /&gt;Hora................: %current hour%&lt;br /&gt;Versão do Windows...: %Windows version%&lt;br /&gt;Mac Address.........: %MAC address%&lt;br /&gt;..-~*´¨¯¨`*·~-.¸-()-,.-~*´¨¯¨`*·~-.¸ .&lt;br /&gt;&lt;br /&gt;From: H1S1B1C1&lt;br /&gt;To: xptoban@gmail.com&lt;br /&gt;Subject: INFO B4NK %computer name%&lt;br /&gt;Body: • h1s1b1c1&lt;br /&gt;!=-=-=-=-=-=-=-=-=-=-=-=-=-=-=&lt;br /&gt;[Ag/Conta]: %stolen information%&lt;br /&gt;[cpf]:%stolen information%&lt;br /&gt;[AssEle]:%stolen information%&lt;br /&gt;[Cartao]:%stolen information%&lt;br /&gt;!=-=-=-=-=-=-=-=-=-=-=-=-=-=-= .&lt;br /&gt;&lt;br /&gt;From: CaixaEconomica&lt;br /&gt;To: xptoban@gmail.com&lt;br /&gt;Subject: INFO B4NK %computer name%&lt;br /&gt;Body: • Caixa Economica federal -&lt;br /&gt;VindO d3: %computer name%&lt;br /&gt;Site: "https://internetcaixa.caixa.gov.br/NASApp/SIIBC&lt;/div&gt;&lt;div align="left"&gt;/login_autentica.processa","Internet Banking CAIXA"&lt;br /&gt;!=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=&lt;br /&gt;[Caixa Tip].............: %stolen information%&lt;br /&gt;[Caixa Agê].............: %stolen information%&lt;br /&gt;[Caixa Con].............: %stolen information%&lt;br /&gt;[Caixa SeNet]...........: %stolen information%&lt;br /&gt;[Caixa AssElet].........: %stolen information%&lt;br /&gt;!=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-&lt;br /&gt;Placa de Rede: %MAC address% .&lt;br /&gt;&lt;br /&gt;From: Banespa&lt;br /&gt;To: xptoban@gmail.com&lt;br /&gt;Subject: INFO B4NK %computer name%&lt;br /&gt;Body: • Banespa -&lt;br /&gt;Vindo d3:%computer name% Site:"http://www.santanderbanespa.com.br&lt;/div&gt;&lt;div align="left"&gt;/portal/gsb/script/templates/GCMRequest.do?page=50 ","http://www.santanderbanespa.com.br/portal/gsb/script&lt;/div&gt;&lt;div align="left"&gt;/templates/GCMRequest.do?page=50"&lt;br /&gt;!=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=&lt;br /&gt;![Ag]:...........%stolen information%&lt;br /&gt;![Cont]:.........%stolen information%&lt;br /&gt;![Nome Acesso]:..%stolen information%&lt;br /&gt;![Sen]:..........%stolen information%&lt;br /&gt;![Ass E]:........%stolen information%&lt;br /&gt;!=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=&lt;br /&gt;MacAddress:%MAC address% .&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/33424336-115668429261437051?l=virusanti.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusanti.blogspot.com/feeds/115668429261437051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=33424336&amp;postID=115668429261437051' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115668429261437051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/33424336/posts/default/115668429261437051'/><link rel='alternate' type='text/html' href='http://virusanti.blogspot.com/2006/08/trspybanker819156.html' title='TR/Spy.Banker.819156'/><author><name>comp virus</name><uri>http://www.blogger.com/profile/17811771912163574055</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
