<?xml version="1.0" encoding="utf-8"?><!--Generated by RSSMaster 1.0 (http://www.softtool.info/rssmaster)--><rss version="2.0"><channel><title>Sybari Virus Alerts</title><link>http://www.sybari.com/</link><description>High Threat Virus Alerts</description><generator>RSSMaster 1.0 (http://www.softtool.info/rssmaster)</generator><language>en-US</language><image><url>http://www.sybari.com//images/logos/corporate/screen/Sybari_AMS_Logo.jpg</url><title>Sybari home page</title><link>http://www.sybari.com/</link></image><item><title>Exploit-WMF trojan</title><description>Downloads backdoor trojan&lt;BR/&gt;
The trojan seen at the time of writing was spammed out in email, using the attachment name &lt;B&gt;HappyNewYear.jpg&lt;/B&gt; (note that the file is not a true JPG file).  
This trojan will attempt to download another trojan when it executes. This is a Bifrose backdoor trojan which can give an attacker access to your computer.&lt;BR/&gt;&lt;BR/&gt; 
****PLEASE NOTE****&lt;BR/&gt;&lt;br/&gt;
For &lt;B&gt;Windows platforms&lt;/B&gt;, users must set the "ScanAllAttachments" registry value to 1 for this filetype to be detected.&lt;BR/&gt;
&lt;BR/&gt;
For &lt;B&gt;Domino platforms&lt;/B&gt;, the following can be done:
&lt;OL&gt;
&lt;LI&gt;Open the "notes.ini" file.&lt;/LI&gt;
&lt;LI&gt;Add the ".JPG" and ".WMF" extension to the "AntigenAveExts" parameter.&lt;/LI&gt;
&lt;LI&gt;Save the file.&lt;/LI&gt;
&lt;LI&gt;Recycle services.&lt;/LI&gt;
&lt;/OL&gt;
See Microsoft Security Advisory (912840), 
Vulnerability in Graphics Rendering Engine Could Allow Remote Code Execution.&lt;BR/&gt;
&lt;A href='http://www.microsoft.com/technet/security/advisory/912840.mspx'&gt;
http://www.microsoft.com/technet/security/advisory/912840.mspx&lt;/A&gt;
</description><link>http://www.sybari.com/VirusAlerts/VirusAlertView.aspx?Alias=Rainbow&amp;TabId=0&amp;Lang=en-US&amp;mid=10659&amp;ItemID=102</link><pubDate>1/3/2006 12:00:00 AM</pubDate></item><item><title>W32/Sober.r@MM </title><description>This mass-mailing email virus arrives in an email message with one of the following attachment names: &lt;br&gt;

KlassenFoto.zip&lt;br&gt;
pword_change.zip&lt;br&gt;
Inside the ZIP archive is a file named PW_Klass.Pic.packed-bitmap.exe. &lt;br&gt;

Like many Sober variants, this variant uses several different email messages randomly, in either English or &lt;br&gt;German depending on the version of Windows.&lt;br&gt;

W32/Sober-O is a mass-mailing worm. &lt;br&gt;
</description><link>http://www.sybari.com/VirusAlerts/VirusAlertView.aspx?Alias=Rainbow&amp;TabId=0&amp;Lang=en-US&amp;mid=10659&amp;ItemID=101</link><pubDate>10/6/2005 12:00:00 AM</pubDate></item><item><title>W32/Tpbot-A</title><description>&lt;p&gt;W32/Tpbot-A is a network worm with backdoor Trojan functionality for
the Windows platform. &lt;/p&gt;
&lt;p&gt;When run, W32/Tpbot-A copies itself to the Windows system folder as
wintbp.exe and creates the following registry entry in order to run
each time a user logs on: &lt;/p&gt;
&lt;p&gt;HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br&gt;
wintbp.exe&lt;br&gt;
"wintbp.exe" &lt;/p&gt;
&lt;p&gt;W32/Tpbot-A spreads using a variety of techniques including the
exploitation of operating system vulnerabilities such as LSASS
(MS04-011) and PnP (MS05-039). &lt;/p&gt;
&lt;p&gt;The backdoor component connects to an IRC server and joins a
predetermined channel where it then awaits commands from attackers. &lt;/p&gt;
&lt;p&gt;W32/Tpbot-A may attempt to download and execute additional files. &lt;/p&gt;</description><link>http://www.sybari.com/VirusAlerts/VirusAlertView.aspx?Alias=Rainbow&amp;TabId=0&amp;Lang=en-US&amp;mid=10659&amp;ItemID=100</link><pubDate>8/17/2005 12:00:00 AM</pubDate></item><item><title>W32/Mytob-CP</title><description>W32/Mytob-CP is an email worm and IRC backdoor Trojan for the Windows
platform. &lt;br&gt;
W32/Mytob-CP includes functionality to modify the HOSTS file. &lt;br&gt;
When first run W32/Mytob-CP copies itself to &amp;lt;Windows system
folder&amp;gt;\Lien Van de Kelder.exe. &lt;br&gt;
The following registry entries are created to run Lien Van de
Kelder.exe on startup: &lt;br&gt;
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run&lt;br&gt;
http://www.lienvandekelder.be&lt;br&gt;
Lien Van de Kelder.exe &lt;br&gt;
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices&lt;br&gt;
http://www.lienvandekelder.be&lt;br&gt;
Lien Van de Kelder.exe &lt;br&gt;
W32/Mytob-CP sets the following registry entries, disabling the
automatic startup of other software: &lt;br&gt;
HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess&lt;br&gt;
Start&lt;br&gt;
4 &lt;br&gt;
W32/Mytob-CP send itself to emails harvested from files on the hard
disk with the following extensions: &lt;br&gt;
TXT, HTMB, SHTL, JSPL, CGIL, XMLS, PHPQ, ASPD, DBXN, TBBG, ADBH, WAB,
PL &lt;br&gt;
&lt;br&gt;
W32/Mytob-CP modifies the HOSTS file, changing the URL-to-IP mappings
for selected websites, therefore preventing normal access to the the
following sites: &lt;br&gt;
127.0.0.1 avp.com&lt;br&gt;
127.0.0.1 ca.com&lt;br&gt;
127.0.0.1 customer.symantec.com&lt;br&gt;
127.0.0.1 dispatch.mcafee.com&lt;br&gt;
127.0.0.1 download.mcafee.com&lt;br&gt;
127.0.0.1 f-secure.com&lt;br&gt;
127.0.0.1 kaspersky-labs.com&lt;br&gt;
127.0.0.1 kaspersky.com&lt;br&gt;
127.0.0.1 liveupdate.symantec.com&lt;br&gt;
127.0.0.1 liveupdate.symantecliveupdate.com&lt;br&gt;
127.0.0.1 mast.mcafee.com&lt;br&gt;
127.0.0.1 mcafee.com&lt;br&gt;
127.0.0.1 microsoft.com&lt;br&gt;
127.0.0.1 my-etrust.com&lt;br&gt;
127.0.0.1 nai.com&lt;br&gt;
127.0.0.1 networkassociates.com&lt;br&gt;
127.0.0.1 oxyd.fr&lt;br&gt;
127.0.0.1 rads.mcafee.com&lt;br&gt;
127.0.0.1 secure.nai.com&lt;br&gt;
127.0.0.1 securityresponse.symantec.com&lt;br&gt;
127.0.0.1 sophos.com&lt;br&gt;
127.0.0.1 symantec.com&lt;br&gt;
127.0.0.1 t35.com&lt;br&gt;
127.0.0.1 t35.net&lt;br&gt;
127.0.0.1 trendmicro.com&lt;br&gt;
127.0.0.1 update.symantec.com&lt;br&gt;
127.0.0.1 updates.symantec.com&lt;br&gt;
127.0.0.1 us.mcafee.com&lt;br&gt;
127.0.0.1 viruslist.com&lt;br&gt;
127.0.0.1 viruslist.com&lt;br&gt;
127.0.0.1 virustotal.com&lt;br&gt;
127.0.0.1 www.avp.com&lt;br&gt;
127.0.0.1 www.ca.com&lt;br&gt;
127.0.0.1 www.f-secure.com&lt;br&gt;
127.0.0.1 www.grisoft.com&lt;br&gt;
127.0.0.1 www.kaspersky.com&lt;br&gt;
127.0.0.1 www.mcafee.com&lt;br&gt;
127.0.0.1 www.microsoft.com&lt;br&gt;
127.0.0.1 www.msn.com&lt;br&gt;
127.0.0.1 www.my-etrust.com&lt;br&gt;
127.0.0.1 www.nai.com&lt;br&gt;
127.0.0.1 www.networkassociates.com&lt;br&gt;
127.0.0.1 www.oxyd.fr&lt;br&gt;
127.0.0.1 www.sophos.com&lt;br&gt;
127.0.0.1 www.symantec.com&lt;br&gt;
127.0.0.1 www.t35.com&lt;br&gt;
127.0.0.1 www.t35.net&lt;br&gt;
127.0.0.1 www.trendmicro.com&lt;br&gt;
127.0.0.1 www.viruslist.com&lt;br&gt;
127.0.0.1 www.virustotal.com &lt;br&gt;
W32/Mytob-CP also terminates the following processes: &lt;br&gt;
_AVP32.EXE&lt;br&gt;
_AVPCC.EXE&lt;br&gt;
_AVPM.EXE&lt;br&gt;
ACKWIN32.EXE&lt;br&gt;
ADAWARE.EXE&lt;br&gt;
ADVXDWIN.EXE&lt;br&gt;
AGENTSVR.EXE&lt;br&gt;
AGENTW.EXE&lt;br&gt;
ALERTSVC.EXE&lt;br&gt;
ALEVIR.EXE&lt;br&gt;
ALOGSERV.EXE&lt;br&gt;
AMON9X.EXE&lt;br&gt;
ANTI-TROJAN.EXE&lt;br&gt;
ANTIVIRUS.EXE&lt;br&gt;
ANTS.EXE&lt;br&gt;
APIMONITOR.EXE&lt;br&gt;
APLICA32.EXE&lt;br&gt;
APVXDWIN.EXE&lt;br&gt;
ARR.EXE&lt;br&gt;
ATCON.EXE&lt;br&gt;
ATGUARD.EXE&lt;br&gt;
ATRO55EN.EXE&lt;br&gt;
ATUPDATER.EXE&lt;br&gt;
ATUPDATER.EXE&lt;br&gt;
ATWATCH.EXE&lt;br&gt;
AU.EXE&lt;br&gt;
AUPDATE.EXE&lt;br&gt;
AUPDATE.EXE&lt;br&gt;
AUTO-PROTECT.NAV80TRY.EXE&lt;br&gt;
AUTODOWN.EXE&lt;br&gt;
AUTODOWN.EXE&lt;br&gt;
AUTOTRACE.EXE&lt;br&gt;
AUTOTRACE.EXE&lt;br&gt;
AUTOUPDATE.EXE&lt;br&gt;
AUTOUPDATE.EXE&lt;br&gt;
AVCONSOL.EXE&lt;br&gt;
AVE32.EXE&lt;br&gt;
AVGCC32.EXE&lt;br&gt;
AVGCTRL.EXE&lt;br&gt;
AVGNT.EXE&lt;br&gt;
AVGSERV.EXE&lt;br&gt;
AVGSERV9.EXE&lt;br&gt;
AVGUARD.EXE&lt;br&gt;
AVGW.EXE&lt;br&gt;
AVKPOP.EXE&lt;br&gt;
AVKSERV.EXE&lt;br&gt;
AVKSERVICE.EXE&lt;br&gt;
AVKWCTl9.EXE&lt;br&gt;
AVLTMAIN.EXE&lt;br&gt;
AVNT.EXE&lt;br&gt;
AVP.EXE&lt;br&gt;
AVP32.EXE&lt;br&gt;
AVPCC.EXE&lt;br&gt;
AVPDOS32.EXE&lt;br&gt;
AVPM.EXE&lt;br&gt;
AVPTC32.EXE&lt;br&gt;
AVPUPD.EXE&lt;br&gt;
AVPUPD.EXE&lt;br&gt;
AVSCHED32.EXE&lt;br&gt;
AVSYNMGR.EXE&lt;br&gt;
AVWINNT.EXE&lt;br&gt;
AVWUPD.EXE&lt;br&gt;
AVWUPD32.EXE&lt;br&gt;
AVWUPD32.EXE&lt;br&gt;
AVWUPSRV.EXE&lt;br&gt;
AVXMONITOR9X.EXE&lt;br&gt;
AVXMONITORNT.EXE&lt;br&gt;
AVXQUAR.EXE&lt;br&gt;
AVXQUAR.EXE&lt;br&gt;
BACKWEB.EXE&lt;br&gt;
BARGAINS.EXE&lt;br&gt;
BD_PROFESSIONAL.EXE&lt;br&gt;
BEAGLE.EXE&lt;br&gt;
BELT.EXE&lt;br&gt;
BIDEF.EXE&lt;br&gt;
BIDSERVER.EXE&lt;br&gt;
BIPCP.EXE&lt;br&gt;
BIPCPEVALSETUP.EXE&lt;br&gt;
BISP.EXE&lt;br&gt;
BLACKD.EXE&lt;br&gt;
BLACKICE.EXE&lt;br&gt;
BLSS.EXE&lt;br&gt;
BOOTCONF.EXE&lt;br&gt;
BOOTWARN.EXE&lt;br&gt;
BORG2.EXE&lt;br&gt;
BPC.EXE&lt;br&gt;
BRASIL.EXE&lt;br&gt;
BS120.EXE&lt;br&gt;
BUNDLE.EXE&lt;br&gt;
BVT.EXE&lt;br&gt;
CCAPP.EXE&lt;br&gt;
CCEVTMGR.EXE&lt;br&gt;
CCPXYSVC.EXE&lt;br&gt;
CDP.EXE&lt;br&gt;
CFD.EXE&lt;br&gt;
CFGWIZ.EXE&lt;br&gt;
CFIADMIN.EXE&lt;br&gt;
CFIAUDIT.EXE&lt;br&gt;
CFIAUDIT.EXE&lt;br&gt;
CFINET.EXE&lt;br&gt;
CFINET32.EXE&lt;br&gt;
CLAW95CF.EXE&lt;br&gt;
CLEAN.EXE&lt;br&gt;
CLEANER.EXE&lt;br&gt;
CLEANER3.EXE&lt;br&gt;
CLEANPC.EXE&lt;br&gt;
CLICK.EXE&lt;br&gt;
CMD.EXE&lt;br&gt;
CMD32.EXE&lt;br&gt;
CMESYS.EXE&lt;br&gt;
CMGRDIAN.EXE&lt;br&gt;
CMON016.EXE&lt;br&gt;
CONNECTIONMONITOR.EXE&lt;br&gt;
CPD.EXE&lt;br&gt;
CPF9X206.EXE&lt;br&gt;
CPFNT206.EXE&lt;br&gt;
CTRL.EXE&lt;br&gt;
CV.EXE&lt;br&gt;
CWNB181.EXE&lt;br&gt;
CWNTDWMO.EXE&lt;br&gt;
DATEMANAGER.EXE&lt;br&gt;
DCOMX.EXE&lt;br&gt;
DEFALERT.EXE&lt;br&gt;
DEFSCANGUI.EXE&lt;br&gt;
DEFWATCH.EXE&lt;br&gt;
DEPUTY.EXE&lt;br&gt;
DIVX.EXE&lt;br&gt;
DLLCACHE.EXE&lt;br&gt;
DLLREG.EXE&lt;br&gt;
DOORS.EXE&lt;br&gt;
DPF.EXE&lt;br&gt;
DPFSETUP.EXE&lt;br&gt;
DPPS2.EXE&lt;br&gt;
DRWATSON.EXE&lt;br&gt;
DRWEB32.EXE&lt;br&gt;
DRWEBUPW.EXE&lt;br&gt;
DSSAGENT.EXE&lt;br&gt;
DVP95.EXE&lt;br&gt;
DVP95_0.EXE&lt;br&gt;
ECENGINE.EXE&lt;br&gt;
EFPEADM.EXE&lt;br&gt;
EMSW.EXE&lt;br&gt;
ENT.EXE&lt;br&gt;
ESAFE.EXE&lt;br&gt;
ESCANHNT.EXE&lt;br&gt;
ESCANV95.EXE&lt;br&gt;
ESPWATCH.EXE&lt;br&gt;
ETHEREAL.EXE&lt;br&gt;
ETRUSTCIPE.EXE&lt;br&gt;
EVPN.EXE&lt;br&gt;
EXANTIVIRUS-CNET.EXE&lt;br&gt;
EXE.AVXW.EXE&lt;br&gt;
EXPERT.EXE&lt;br&gt;
EXPLORE.EXE&lt;br&gt;
F-PROT.EXE&lt;br&gt;
F-PROT95.EXE&lt;br&gt;
F-STOPW.EXE&lt;br&gt;
FAMEH32.EXE&lt;br&gt;
FAST.EXE&lt;br&gt;
FCH32.EXE&lt;br&gt;
FIH32.EXE&lt;br&gt;
FINDVIRU.EXE&lt;br&gt;
FIREWALL.EXE&lt;br&gt;
FNRB32.EXE&lt;br&gt;
FP-WIN.EXE&lt;br&gt;
FP-WIN_TRIAL.EXE&lt;br&gt;
FPROT.EXE&lt;br&gt;
FRW.EXE&lt;br&gt;
FSAA.EXE&lt;br&gt;
FSAV.EXE&lt;br&gt;
FSAV32.EXE&lt;br&gt;
FSAV530STBYB.EXE&lt;br&gt;
FSAV530WTBYB.EXE&lt;br&gt;
FSAV95.EXE&lt;br&gt;
FSGK32.EXE&lt;br&gt;
FSM32.EXE&lt;br&gt;
FSMA32.EXE&lt;br&gt;
FSMB32.EXE&lt;br&gt;
GATOR.EXE&lt;br&gt;
GBMENU.EXE&lt;br&gt;
GBPOLL.EXE&lt;br&gt;
GENERICS.EXE&lt;br&gt;
GMT.EXE&lt;br&gt;
GUARD.EXE&lt;br&gt;
GUARDDOG.EXE&lt;br&gt;
HACKTRACERSETUP.EXE&lt;br&gt;
HBINST.EXE&lt;br&gt;
HBSRV.EXE&lt;br&gt;
HOTACTIO.EXE&lt;br&gt;
HOTPATCH.EXE&lt;br&gt;
HTLOG.EXE&lt;br&gt;
HTPATCH.EXE&lt;br&gt;
HWPE.EXE&lt;br&gt;
HXDL.EXE&lt;br&gt;
HXIUL.EXE&lt;br&gt;
IAMAPP.EXE&lt;br&gt;
IAMSERV.EXE&lt;br&gt;
IAMSTATS.EXE&lt;br&gt;
IBMASN.EXE&lt;br&gt;
IBMAVSP.EXE&lt;br&gt;
ICLOADNT.EXE&lt;br&gt;
ICMON.EXE&lt;br&gt;
ICSUPP95.EXE&lt;br&gt;
ICSUPPNT.EXE&lt;br&gt;
IDLE.EXE&lt;br&gt;
IEDLL.EXE&lt;br&gt;
IEDRIVER.EXE&lt;br&gt;
IEXPLORER.EXE&lt;br&gt;
IFACE.EXE&lt;br&gt;
IFW2000.EXE&lt;br&gt;
INETLNFO.EXE&lt;br&gt;
INFUS.EXE&lt;br&gt;
INFWIN.EXE&lt;br&gt;
INIT.EXE&lt;br&gt;
INTDEL.EXE&lt;br&gt;
INTREN.EXE&lt;br&gt;
IOMON98.EXE&lt;br&gt;
ISTSVC.EXE&lt;br&gt;
JAMMER.EXE&lt;br&gt;
JDBGMRG.EXE&lt;br&gt;
JEDI.EXE&lt;br&gt;
KAVLITE40ENG.EXE&lt;br&gt;
KAVPERS40ENG.EXE&lt;br&gt;
KAVPF.EXE&lt;br&gt;
KAZZA.EXE&lt;br&gt;
KEENVALUE.EXE&lt;br&gt;
KERIO-PF-213-EN-WIN.EXE&lt;br&gt;
KERIO-WRL-421-EN-WIN.EXE&lt;br&gt;
KERIO-WRP-421-EN-WIN.EXE&lt;br&gt;
KERNEL32.EXE&lt;br&gt;
KILLPROCESSSETUP161.EXE&lt;br&gt;
LAUNCHER.EXE&lt;br&gt;
LDNETMON.EXE&lt;br&gt;
LDPRO.EXE&lt;br&gt;
LDPROMENU.EXE&lt;br&gt;
LDSCAN.EXE&lt;br&gt;
LNETINFO.EXE&lt;br&gt;
LOADER.EXE&lt;br&gt;
LOCALNET.EXE&lt;br&gt;
LOCKDOWN.EXE&lt;br&gt;
LOCKDOWN2000.EXE&lt;br&gt;
LOOKOUT.EXE&lt;br&gt;
LORDPE.EXE&lt;br&gt;
LSETUP.EXE&lt;br&gt;
LUALL.EXE&lt;br&gt;
LUALL.EXE&lt;br&gt;
LUAU.EXE&lt;br&gt;
LUCOMSERVER.EXE&lt;br&gt;
LUINIT.EXE&lt;br&gt;
LUSPT.EXE&lt;br&gt;
MAPISVC32.EXE&lt;br&gt;
MCAGENT.EXE&lt;br&gt;
MCMNHDLR.EXE&lt;br&gt;
MCSHIELD.EXE&lt;br&gt;
MCTOOL.EXE&lt;br&gt;
MCUPDATE.EXE&lt;br&gt;
MCUPDATE.EXE&lt;br&gt;
MCVSRTE.EXE&lt;br&gt;
MCVSSHLD.EXE&lt;br&gt;
MD.EXE&lt;br&gt;
MFIN32.EXE&lt;br&gt;
MFW2EN.EXE&lt;br&gt;
MFWENG3.02D30.EXE&lt;br&gt;
MGAVRTCL.EXE&lt;br&gt;
MGAVRTE.EXE&lt;br&gt;
MGHTML.EXE&lt;br&gt;
MGUI.EXE&lt;br&gt;
MINILOG.EXE&lt;br&gt;
MMOD.EXE&lt;br&gt;
MONITOR.EXE&lt;br&gt;
MOOLIVE.EXE&lt;br&gt;
MOSTAT.EXE&lt;br&gt;
MPFAGENT.EXE&lt;br&gt;
MPFSERVICE.EXE&lt;br&gt;
MPFTRAY.EXE&lt;br&gt;
MRFLUX.EXE&lt;br&gt;
MSAPP.EXE&lt;br&gt;
MSBB.EXE&lt;br&gt;
MSBLAST.EXE&lt;br&gt;
MSCACHE.EXE&lt;br&gt;
MSCCN32.EXE&lt;br&gt;
MSCMAN.EXE&lt;br&gt;
MSCONFIG.EXE&lt;br&gt;
MSDM.EXE&lt;br&gt;
MSDOS.EXE&lt;br&gt;
MSIEXEC16.EXE&lt;br&gt;
MSINFO32.EXE&lt;br&gt;
MSLAUGH.EXE&lt;br&gt;
MSMGT.EXE&lt;br&gt;
MSMSGRI32.EXE&lt;br&gt;
MSSMMC32.EXE&lt;br&gt;
MSSYS.EXE&lt;br&gt;
MSVXD.EXE&lt;br&gt;
MU0311AD.EXE&lt;br&gt;
MWATCH.EXE&lt;br&gt;
N32SCANW.EXE&lt;br&gt;
NAV.EXE&lt;br&gt;
NAVAP.NAVAPSVC.EXE&lt;br&gt;
NAVAPSVC.EXE&lt;br&gt;
NAVAPW32.EXE&lt;br&gt;
NAVDX.EXE&lt;br&gt;
NAVLU32.EXE&lt;br&gt;
NAVNT.EXE&lt;br&gt;
NAVSTUB.EXE&lt;br&gt;
NAVW32.EXE&lt;br&gt;
NAVWNT.EXE&lt;br&gt;
NCINST4.EXE&lt;br&gt;
NDD32.EXE&lt;br&gt;
NEOMONITOR.EXE&lt;br&gt;
NEOWATCHLOG.EXE&lt;br&gt;
NETARMOR.EXE&lt;br&gt;
NETD32.EXE&lt;br&gt;
NETINFO.EXE&lt;br&gt;
NETMON.EXE&lt;br&gt;
NETSCANPRO.EXE&lt;br&gt;
NETSPYHUNTER-1.2.EXE&lt;br&gt;
NETSTAT.EXE&lt;br&gt;
NETUTILS.EXE&lt;br&gt;
NISSERV.EXE&lt;br&gt;
NISUM.EXE&lt;br&gt;
NMAIN.EXE&lt;br&gt;
NOD32.EXE&lt;br&gt;
NORMIST.EXE&lt;br&gt;
NORTON_INTERNET_SECU_3.0_407.EXE&lt;br&gt;
NOTSTART.EXE&lt;br&gt;
NPF40_TW_98_NT_ME_2K.EXE&lt;br&gt;
NPFMESSENGER.EXE&lt;br&gt;
NPROTECT.EXE&lt;br&gt;
NPSCHECK.EXE&lt;br&gt;
NPSSVC.EXE&lt;br&gt;
NSCHED32.EXE&lt;br&gt;
NSSYS32.EXE&lt;br&gt;
NSTASK32.EXE&lt;br&gt;
NSUPDATE.EXE&lt;br&gt;
NT.EXE&lt;br&gt;
NTRTSCAN.EXE&lt;br&gt;
NTVDM.EXE&lt;br&gt;
NTXconfig.EXE&lt;br&gt;
NUI.EXE&lt;br&gt;
NUPGRADE.EXE&lt;br&gt;
NUPGRADE.EXE&lt;br&gt;
NVARCH16.EXE&lt;br&gt;
NVC95.EXE&lt;br&gt;
NVSVC32.EXE&lt;br&gt;
NWINST4.EXE&lt;br&gt;
NWSERVICE.EXE&lt;br&gt;
NWTOOL16.EXE&lt;br&gt;
OLLYDBG.EXE&lt;br&gt;
ONSRVR.EXE&lt;br&gt;
OPTIMIZE.EXE&lt;br&gt;
OSTRONET.EXE&lt;br&gt;
OTFIX.EXE&lt;br&gt;
OUTPOST.EXE&lt;br&gt;
OUTPOST.EXE&lt;br&gt;
OUTPOSTINSTALL.EXE&lt;br&gt;
OUTPOSTPROINSTALL.EXE&lt;br&gt;
PADMIN.EXE&lt;br&gt;
PANIXK.EXE&lt;br&gt;
PATCH.EXE&lt;br&gt;
PAVCL.EXE&lt;br&gt;
PAVPROXY.EXE&lt;br&gt;
PAVSCHED.EXE&lt;br&gt;
PAVW.EXE&lt;br&gt;
PCFWALLICON.EXE&lt;br&gt;
PCSCAN.EXE&lt;br&gt;
PDSETUP.EXE&lt;br&gt;
PERISCOPE.EXE&lt;br&gt;
PERSFW.EXE&lt;br&gt;
PERSWF.EXE&lt;br&gt;
PF2.EXE&lt;br&gt;
PFWADMIN.EXE&lt;br&gt;
PGMONITR.EXE&lt;br&gt;
PINGSCAN.EXE&lt;br&gt;
PLATIN.EXE&lt;br&gt;
POP3TRAP.EXE&lt;br&gt;
POPROXY.EXE&lt;br&gt;
POPSCAN.EXE&lt;br&gt;
PORTDETECTIVE.EXE&lt;br&gt;
PORTMONITOR.EXE&lt;br&gt;
POWERSCAN.EXE&lt;br&gt;
PPINUPDT.EXE&lt;br&gt;
PPTBC.EXE&lt;br&gt;
PPVSTOP.EXE&lt;br&gt;
PRIZESURFER.EXE&lt;br&gt;
PRMT.EXE&lt;br&gt;
PRMVR.EXE&lt;br&gt;
PROCDUMP.EXE&lt;br&gt;
PROCESSMONITOR.EXE&lt;br&gt;
PROCEXPLORERV1.0.EXE&lt;br&gt;
PROGRAMAUDITOR.EXE&lt;br&gt;
PROPORT.EXE&lt;br&gt;
PROTECTX.EXE&lt;br&gt;
PSPF.EXE&lt;br&gt;
PURGE.EXE&lt;br&gt;
QCONSOLE.EXE&lt;br&gt;
QSERVER.EXE&lt;br&gt;
RAPAPP.EXE&lt;br&gt;
RAV7.EXE&lt;br&gt;
RAV7WIN.EXE&lt;br&gt;
RAV8WIN32ENG.EXE&lt;br&gt;
RAY.EXE&lt;br&gt;
RB32.EXE&lt;br&gt;
RCSYNC.EXE&lt;br&gt;
REALMON.EXE&lt;br&gt;
REGED.EXE&lt;br&gt;
REGEDIT.EXE&lt;br&gt;
REGEDT32.EXE&lt;br&gt;
RESCUE.EXE&lt;br&gt;
RESCUE32.EXE&lt;br&gt;
RRGUARD.EXE&lt;br&gt;
RSHELL.EXE&lt;br&gt;
RTVSCAN.EXE&lt;br&gt;
RTVSCN95.EXE&lt;br&gt;
RULAUNCH.EXE&lt;br&gt;
RUN32DLL.EXE&lt;br&gt;
RUNDLL.EXE&lt;br&gt;
RUNDLL16.EXE&lt;br&gt;
RUXDLL32.EXE&lt;br&gt;
SAFEWEB.EXE&lt;br&gt;
SAHAGENT.EXE&lt;br&gt;
SAVE.EXE&lt;br&gt;
SAVENOW.EXE&lt;br&gt;
SBSERV.EXE&lt;br&gt;
SC.EXE&lt;br&gt;
SCAM32.EXE&lt;br&gt;
SCAN32.EXE&lt;br&gt;
SCAN95.EXE&lt;br&gt;
SCANPM.EXE&lt;br&gt;
SCRSCAN.EXE&lt;br&gt;
SETUP_FLOWPROTECTOR_US.EXE&lt;br&gt;
SETUPVAMEEVAL.EXE&lt;br&gt;
SFC.EXE&lt;br&gt;
SGSSFW32.EXE&lt;br&gt;
SH.EXE&lt;br&gt;
SHELLSPYINSTALL.EXE&lt;br&gt;
SHN.EXE&lt;br&gt;
SHOWBEHIND.EXE&lt;br&gt;
SMC.EXE&lt;br&gt;
SMS.EXE&lt;br&gt;
SMSS32.EXE&lt;br&gt;
SOAP.EXE&lt;br&gt;
SOFI.EXE&lt;br&gt;
SPERM.EXE&lt;br&gt;
SPF.EXE&lt;br&gt;
SPHINX.EXE&lt;br&gt;
SPOLER.EXE&lt;br&gt;
SPOOLCV.EXE&lt;br&gt;
SPOOLSV32.EXE&lt;br&gt;
SPYXX.EXE&lt;br&gt;
SREXE.EXE&lt;br&gt;
SRNG.EXE&lt;br&gt;
SS3EDIT.EXE&lt;br&gt;
SSGRATE.EXE&lt;br&gt;
ST2.EXE&lt;br&gt;
START.EXE&lt;br&gt;
STCLOADER.EXE&lt;br&gt;
SUPFTRL.EXE&lt;br&gt;
SUPPORT.EXE&lt;br&gt;
SUPPORTER5.EXE&lt;br&gt;
SVC.EXE&lt;br&gt;
SVCHOSTC.EXE&lt;br&gt;
SVCHOSTS.EXE&lt;br&gt;
SVSHOST.EXE&lt;br&gt;
SWEEP95.EXE&lt;br&gt;
SWEEPNET.SWEEPSRV.SYS.SWNETSUP.EXE&lt;br&gt;
SYMPROXYSVC.EXE&lt;br&gt;
SYMTRAY.EXE&lt;br&gt;
SYSEDIT.EXE&lt;br&gt;
SYSTEM.EXE&lt;br&gt;
SYSTEM32.EXE&lt;br&gt;
SYSUPD.EXE&lt;br&gt;
TASKMG.EXE&lt;br&gt;
TASKMGR.EXE&lt;br&gt;
TASKMO.EXE&lt;br&gt;
TASKMON.EXE&lt;br&gt;
TAUMON.EXE&lt;br&gt;
TBSCAN.EXE&lt;br&gt;
TC.EXE&lt;br&gt;
TCA.EXE&lt;br&gt;
TCM.EXE&lt;br&gt;
TDS-3.EXE&lt;br&gt;
TDS2-NT.EXE&lt;br&gt;
TEEKIDS.EXE&lt;br&gt;
TFAK.EXE&lt;br&gt;
TFAK5.EXE&lt;br&gt;
TGBOB.EXE&lt;br&gt;
TITANIN.EXE&lt;br&gt;
TITANINXP.EXE&lt;br&gt;
TRACERT.EXE&lt;br&gt;
TRICKLER.EXE&lt;br&gt;
TRJSCAN.EXE&lt;br&gt;
TRJSETUP.EXE&lt;br&gt;
TROJANTRAP3.EXE&lt;br&gt;
TSADBOT.EXE&lt;br&gt;
TVMD.EXE&lt;br&gt;
TVTMD.EXE&lt;br&gt;
UNDOBOOT.EXE&lt;br&gt;
UPDAT.EXE&lt;br&gt;
UPDATE.EXE&lt;br&gt;
UPDATE.EXE&lt;br&gt;
UPGRAD.EXE&lt;br&gt;
UTPOST.EXE&lt;br&gt;
VBCMSERV.EXE&lt;br&gt;
VBCONS.EXE&lt;br&gt;
VBUST.EXE&lt;br&gt;
VBWIN9X.EXE&lt;br&gt;
VBWINNTW.EXE&lt;br&gt;
VCSETUP.EXE&lt;br&gt;
VET32.EXE&lt;br&gt;
VET95.EXE&lt;br&gt;
VETTRAY.EXE&lt;br&gt;
VFSETUP.EXE&lt;br&gt;
VIR-HELP.EXE&lt;br&gt;
VIRUSMDPERSONALFIREWALL.EXE&lt;br&gt;
VNLAN300.EXE&lt;br&gt;
VNPC3000.EXE&lt;br&gt;
VPC32.EXE&lt;br&gt;
VPC42.EXE&lt;br&gt;
VPFW30S.EXE&lt;br&gt;
VPTRAY.EXE&lt;br&gt;
VSCAN40.EXE&lt;br&gt;
VSCENU6.02D30.EXE&lt;br&gt;
VSCHED.EXE&lt;br&gt;
VSECOMR.EXE&lt;br&gt;
VSHWIN32.EXE&lt;br&gt;
VSISETUP.EXE&lt;br&gt;
VSMAIN.EXE&lt;br&gt;
VSMON.EXE&lt;br&gt;
VSSTAT.EXE&lt;br&gt;
VSWIN9XE.EXE&lt;br&gt;
VSWINNTSE.EXE&lt;br&gt;
VSWINPERSE.EXE&lt;br&gt;
W32DSM89.EXE&lt;br&gt;
W9X.EXE&lt;br&gt;
WATCHDOG.EXE&lt;br&gt;
WEBDAV.EXE&lt;br&gt;
WEBSCANX.EXE&lt;br&gt;
WEBTRAP.EXE&lt;br&gt;
WFINDV32.EXE&lt;br&gt;
WHOSWATCHINGME.EXE&lt;br&gt;
WIMMUN32.EXE&lt;br&gt;
WIN-BUGSFIX.EXE&lt;br&gt;
WIN32.EXE&lt;br&gt;
WIN32US.EXE&lt;br&gt;
WINACTIVE.EXE&lt;br&gt;
WINDOW.EXE&lt;br&gt;
WINDOWS.EXE&lt;br&gt;
WININETD.EXE&lt;br&gt;
WININIT.EXE&lt;br&gt;
WININITX.EXE&lt;br&gt;
WINLOGIN.EXE&lt;br&gt;
WINMAIN.EXE&lt;br&gt;
WINNET.EXE&lt;br&gt;
WINPPR32.EXE&lt;br&gt;
WINRECON.EXE&lt;br&gt;
WINSERVN.EXE&lt;br&gt;
WINSSK32.EXE&lt;br&gt;
WINSTART.EXE&lt;br&gt;
WINSTART001.EXE&lt;br&gt;
WINTSK32.EXE&lt;br&gt;
WINUPDATE.EXE&lt;br&gt;
WKUFIND.EXE&lt;br&gt;
WNAD.EXE&lt;br&gt;
WNT.EXE&lt;br&gt;
WRADMIN.EXE&lt;br&gt;
WRCTRL.EXE&lt;br&gt;
WSBGATE.EXE&lt;br&gt;
WUPDATER.EXE&lt;br&gt;
WUPDT.EXE&lt;br&gt;
WYVERNWORKSFIREWALL.EXE&lt;br&gt;
XPF202EN.EXE&lt;br&gt;
ZAPRO.EXE&lt;br&gt;
ZAPSETUP3001.EXE&lt;br&gt;
ZATUTOR.EXE&lt;br&gt;
ZONALM2601.EXE&lt;br&gt;
ZONEALARM.E</description><link>http://www.sybari.com/VirusAlerts/VirusAlertView.aspx?Alias=Rainbow&amp;TabId=0&amp;Lang=en-US&amp;mid=10659&amp;ItemID=99</link><pubDate>5/31/2005 12:00:00 AM</pubDate></item><item><title>W32/Sober-N</title><description>W32/Sober-N is a mass-mailing worm which sends itself to addresses harvested from the infected computer. </description><link>http://www.sybari.com/VirusAlerts/VirusAlertView.aspx?Alias=Rainbow&amp;TabId=0&amp;Lang=en-US&amp;mid=10659&amp;ItemID=98</link><pubDate>5/2/2005 12:00:00 AM</pubDate></item><item><title>W32/Bagle.dldr</title><description>This variant copies itself to the %WinDir%&amp;nbsp; \system32 as
WINSHOST.EXE (34, 304 bytes) and adds the following registry hooks:&lt;br&gt;
&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; DownloadManager&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKEY_CURRENT_USER\Software\Microsoft\Windows\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CurrentVersion\Run "winshost.exe" =
%WinDir% \system32\winshost.exe&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CurrentVersion\Run "winshost.exe" =
%WinDir% \system32\winshost.exe&lt;br&gt;
&lt;br&gt;
It drops a file wiwshost.exe (18,944 bytes), which is detected as W32/Bagle.dll.gen . This file gets injected into
the EXPLORER process and tries to download a file zo2.jpg from various
sites. (Refer to Symptoms). It also terminates security services like
its predecessors and in some cases renames the main security program
executable.&lt;br&gt;
&lt;br&gt;
Sets to "disable" the following services:&lt;br&gt;
&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\System\CurrentControlSet\Services\wuauserv&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\System\CurrentControlSet\Services\SharedAccess&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\System\CurrentControlSet\Services\vsmon&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\System\CurrentControlSet\Services\Alerter&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\System\CurrentControlSet\Services\wuauserv&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\System\CurrentControlSet\Services\McShield&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; *
HKLM\System\CurrentControlSet\Services\McAfeeFramework&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; *
HKLM\System\CurrentControlSet\Services\McTaskManager&lt;br&gt;
&lt;br&gt;
Attempts to delete the following keys:&lt;br&gt;
&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Symantec NetDriver Monitor&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ccApp&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NAV CfgWiz&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SSC_UserPrompt&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; McAfee Guardian &amp;nbsp;&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; McAfee.InstantUpdate.Monitor &lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; APVXDWIN&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; KAV50 &lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; avg7_cc &lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; * HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; avg7_emc&lt;br&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; *
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Zone Labs Client&lt;br&gt;
&lt;br&gt;
It also modifies the file %WinDir% \system32\drivers\etc\hosts to
prevent the user and any running software from contacting certain
security websites. The trojanized hosts file is detected as "trojan
QHosts" .&lt;br&gt;
&lt;br&gt;
The trojan disables any configured HTTP proxy.&lt;br&gt;
&lt;br&gt;
The last 3 Bagle Variants (.bb@MM , .bc@MM, .bd@MM) attempt to download
a file named G.JPG from various sites and to execute it. In the
meantime, some of those sites were hosting an executeable file.&lt;br&gt;
&lt;br&gt;
When this file gets executed, it copies itself to the %WinDir%
\system32 as WINSHOST.EXE (7172 bytes) and drops another file named
WIDSHOST.EXE (11264 bytes) which get injected into the EXPLORER process
and tries to download a ZOO.JPG from various sites.</description><link>http://www.sybari.com/VirusAlerts/VirusAlertView.aspx?Alias=Rainbow&amp;TabId=0&amp;Lang=en-US&amp;mid=10659&amp;ItemID=97</link><pubDate>3/1/2005 12:00:00 AM</pubDate></item><item><title>W32/Mydoom.be@MM</title><description>This variant W32/Mydoom is similar to previous variants, it bears the
following characteristics:&lt;br&gt;
&lt;br&gt;
mass-mailing worm constructing messages using its own SMTP engine &lt;br&gt;
harvests email addresses from the victim machine &lt;br&gt;
spoofs the From: address &lt;br&gt;
&lt;br&gt;
This virus attempts to download the BackDoor-CEB.f trojan from the
following list of websites:&lt;br&gt;
&lt;br&gt;
http://www.newgenerationcomics.net/banner/(neutered).jpg &lt;br&gt;
http://www.aartanridge.org.uk/YaBBImages/(neutered).gif &lt;br&gt;
http://www.eastcoastchoons.co.uk/4play/(neutered).JPG &lt;br&gt;
http://www.foxalpha.com/charte/(neutered).jpg &lt;br&gt;
http://www.sundayriders.co.uk/images/(neutered).gif &lt;br&gt;
http://www.foxalpha.com/charte/(neutered).jpg &lt;br&gt;
http://www.hooping.org/archives/(neutered).JPG &lt;br&gt;
http://www.ribaforada.net/banners/(neutered).gif &lt;br&gt;
ics.net/banner/(neutered).jpg &lt;br&gt;</description><link>http://www.sybari.com/VirusAlerts/VirusAlertView.aspx?Alias=Rainbow&amp;TabId=0&amp;Lang=en-US&amp;mid=10659&amp;ItemID=96</link><pubDate>2/21/2005 12:00:00 AM</pubDate></item><item><title>W32/Sober.k@MM</title><description>contains its own SMTP engine &lt;br&gt;
source/target email addresses are harvested from the victim machine &lt;br&gt;
outgoing messages maybe in English or German &lt;br&gt;
Mail Propagation &lt;br&gt;
spoofs the "From" header of constructed messages &lt;br&gt;
The worm is packed with UPX.&lt;br&gt;
&lt;br&gt;
Mail Propagation &lt;br&gt;
&lt;br&gt;
The worm extracts target email addresses from the victim machine, and
writes them to the file DATAMX.DAM in the %SysDir% . For example: &lt;br&gt;
&lt;br&gt;
C:\WINNT\SYSTEM32\DATAMX.DAM &lt;br&gt;
&lt;br&gt;
The worm will construct messages using German or English text,
depending upon the recipient email address. For recipient addresses
containing any of the following, German text is used:&lt;br&gt;
&lt;br&gt;
.de &lt;br&gt;
.at &lt;br&gt;
.ch &lt;br&gt;
&lt;br&gt;
The worm carries a pool of strings which it uses to construct the
filename and Registry keys it uses for installing itself on the victim
machine:&lt;br&gt;
&lt;br&gt;
sys &lt;br&gt;
host &lt;br&gt;
dir &lt;br&gt;
expoler &lt;br&gt;
win &lt;br&gt;
run &lt;br&gt;
log &lt;br&gt;
32 &lt;br&gt;
disc &lt;br&gt;
crypt &lt;br&gt;
data &lt;br&gt;
diag &lt;br&gt;
spool &lt;br&gt;
service &lt;br&gt;
smss32 &lt;br&gt;
The constructed filename always has an EXE extension. The worm installs
itself into the Windows system directory using this constructed
filename, for example:&lt;br&gt;
&lt;br&gt;
C:\WINDOWS\SYSTEM32\SYSSPOOLDISC.EXE &lt;br&gt;
The following files are also dropped into %SysDir%:&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
DATAMX.DAM&amp;nbsp; (contains harvested email addresses) &lt;br&gt;
DGSFZIPP.GMX (59.504 bytes, copy of the worm in a ZIP and base64
encoded) &lt;br&gt;
Additionally the following 0 byte files are dropped:&lt;br&gt;
&lt;br&gt;
dgssxy.yoi (0 bytes) &lt;br&gt;
nonrunso.ber (0 bytes) &lt;br&gt;
Odin-Anon.Ger (0 bytes) &lt;br&gt;
sysmms32.lla (0 bytes) &lt;br&gt;
The worm adds two Registry keys to run the copy of itself at system
startup. The name of the key is also constructed from the pool of
strings the worm carries. For example:&lt;br&gt;
&lt;br&gt;
HKEY_CURRENT_USER\Software\Microsoft\Windows&lt;br&gt;
\CurrentVersion\Run "adisccrypt" = %SYSDIR%\sysspooldisc.exe &lt;br&gt;
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows&lt;br&gt;
\CurrentVersion\Run " dircryptlog" = %SYSDIR%\sysspooldisc.exe &lt;br&gt;
(where %SYSDIR% is C:\Windows\System32 or C:\Winnt\System32) &lt;br&gt;
&lt;br&gt;
Network Traffic &lt;br&gt;
&lt;br&gt;
Symptoms indicating the worm's presence on a network include:&lt;br&gt;
&lt;br&gt;
outgoing messages matching the characteristics described here &lt;br&gt;
unexpected NTP traffic on port 37 TCP &lt;br&gt;
unexpected attempts to log into several GMX accounts (POP3) &lt;br&gt;
unexpected outgoing DNS queries DNS servers on the internet to one or
more of the following domains:&lt;br&gt;
microsoft.com &lt;br&gt;
bigfoot.com &lt;br&gt;
yahoo.com &lt;br&gt;
t-online.de &lt;br&gt;
google.com &lt;br&gt;
hotmail.com &lt;br&gt;
&lt;br&gt;</description><link>http://www.sybari.com/VirusAlerts/VirusAlertView.aspx?Alias=Rainbow&amp;TabId=0&amp;Lang=en-US&amp;mid=10659&amp;ItemID=95</link><pubDate>1/31/2005 12:00:00 AM</pubDate></item><item><title>W32/Bagle.bj@MM</title><description>This is a mass-mailing worm with the following characteristics:&lt;br&gt;
&lt;br&gt;
contains its own SMTP engine to construct outgoing messages &lt;br&gt;
harvests email addresses from the victim machine &lt;br&gt;
the From: address of messages is spoofed &lt;br&gt;
contains a remote access component (notification is sent to hacker) &lt;br&gt;
copies itself to folders that have the phrase shar in the name (such as
common peer-to-peer applications; KaZaa, Bearshare, Limewire, etc) &lt;br&gt;
Mail Propagation &lt;br&gt;
&lt;br&gt;
The virus copies itself into the Windows System directory as
sysformat.exe. For example:&lt;br&gt;
&lt;br&gt;
C:\WINNT\SYSTEM32\sysformat.exe &lt;br&gt;
It also creates other files in this directory to perform its functions:&lt;br&gt;
&lt;br&gt;
C:\WINNT\SYSTEM32\sysformat.exeopen &lt;br&gt;
C:\WINNT\SYSTEM32\sysformat.exeopenopen &lt;br&gt;
The following Registry key is added to hook system startup:&lt;br&gt;
&lt;br&gt;
HKEY_CURRENT_USER\Software\Microsoft\Windows\&lt;br&gt;
CurrentVersion\Run "sysformat" = C:\WINNT\SYSTEM32\sysformat.exe &lt;br&gt;
Additionally, the following Registry keys are added:&lt;br&gt;
&lt;br&gt;
HKEY_CURRENT_USER\Software\Microsoft\Params "TimeKey" &lt;br&gt;
It deletes these values&lt;br&gt;
&lt;br&gt;
"My AV" &lt;br&gt;
"ICQ Net" &lt;br&gt;
from the following Registry keys, if they are present:&lt;br&gt;
&lt;br&gt;
HKEY_CURRENT_USER\Software\Microsoft\Windows\&lt;br&gt;
CurrentVersion\Run &lt;br&gt;
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\&lt;br&gt;
CurrentVersion\Run &lt;br&gt;
A mutex is created to ensure only one instance of the worm is running
at a time.&amp;nbsp; One of the following mutex names is used in an attempt
to stop particular variants of W32/Netsky running on the infected
machine:&lt;br&gt;
&lt;br&gt;
MuXxXxTENYKSDesignedAsTheFollowerOfSkynet-D &lt;br&gt;
_-oO]xX|-S-k-y-N-e-t-|Xx[Oo-_ &lt;br&gt;
This worm attempts to terminate the process of security programs with
the the following filenames:&lt;br&gt;
&lt;br&gt;
mcagent.exe &lt;br&gt;
mcvsshld.exe &lt;br&gt;
mcshield.exe &lt;br&gt;
mcvsescn.exe &lt;br&gt;
mcvsrte.exe &lt;br&gt;
DefWatch.exe &lt;br&gt;
Rtvscan.exe &lt;br&gt;
ccEvtMgr.exe &lt;br&gt;
NISUM.EXE &lt;br&gt;
ccPxySvc.exe &lt;br&gt;
navapsvc.exe &lt;br&gt;
NPROTECT.EXE &lt;br&gt;
nopdb.exe &lt;br&gt;
ccApp.exe &lt;br&gt;
Avsynmgr.exe &lt;br&gt;
VsStat.exe &lt;br&gt;
Vshwin32.exe &lt;br&gt;
alogserv.exe &lt;br&gt;
RuLaunch.exe &lt;br&gt;
Avconsol.exe &lt;br&gt;
PavFires.exe &lt;br&gt;
FIREWALL.EXE &lt;br&gt;
ATUPDATER.EXE &lt;br&gt;
LUALL.EXE &lt;br&gt;
DRWEBUPW.EXE &lt;br&gt;
AUTODOWN.EXE &lt;br&gt;
NUPGRADE.EXE &lt;br&gt;
OUTPOST.EXE &lt;br&gt;
ICSSUPPNT.EXE &lt;br&gt;
ICSUPP95.EXE &lt;br&gt;
ESCANH95.EXE &lt;br&gt;
AVXQUAR.EXE &lt;br&gt;
ESCANHNT.EXE &lt;br&gt;
ATUPDATER.EXE &lt;br&gt;
AUPDATE.EXE &lt;br&gt;
AUTOTRACE.EXE &lt;br&gt;
AUTOUPDATE.EXE &lt;br&gt;
AVXQUAR.EXE &lt;br&gt;
AVWUPD32.EXE &lt;br&gt;
AVPUPD.EXE &lt;br&gt;
CFIAUDIT.EXE &lt;br&gt;
UPDATE.EXE &lt;br&gt;
NUPGRADE.EXE &lt;br&gt;
MCUPDATE.EXE &lt;br&gt;
pavsrv50.exe &lt;br&gt;
AVENGINE.EXE &lt;br&gt;
APVXDWIN.EXE &lt;br&gt;
pavProxy.exe &lt;br&gt;
navapw32.exe &lt;br&gt;
navapsvc.exe &lt;br&gt;
ccProxy.exe &lt;br&gt;
navapsvc.exe &lt;br&gt;
NPROTECT.EXE &lt;br&gt;
SAVScan.exe &lt;br&gt;
SNDSrvc.exe &lt;br&gt;
symlcsvc.exe &lt;br&gt;
LUCOMS~1.EXE &lt;br&gt;
blackd.exe &lt;br&gt;
bawindo.exe &lt;br&gt;
FrameworkService.exe &lt;br&gt;
VsTskMgr.exe &lt;br&gt;
SHSTAT.EXE &lt;br&gt;
UpdaterUI.exe &lt;br&gt;
The worm opens random ports starting with 2339 (TCP) on the victim
machine.&lt;br&gt;</description><link>http://www.sybari.com/VirusAlerts/VirusAlertView.aspx?Alias=Rainbow&amp;TabId=0&amp;Lang=en-US&amp;mid=10659&amp;ItemID=94</link><pubDate>1/27/2005 12:00:00 AM</pubDate></item><item><title>W32/Zafi.d@MM</title><description>This new variant contains the following characteristics:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;contains its own SMTP engine to construct outgoing messages &lt;/li&gt;
&lt;li&gt;spoofs the From: address &lt;/li&gt;
&lt;li&gt;harvests target email addresses from the victim&amp;nbsp; machine &lt;/li&gt;
&lt;li&gt;outgoing email message body is either in Hungarian or English &lt;/li&gt;
&lt;li&gt;displays p2p worm&amp;nbsp;behaviour &lt;/li&gt;
&lt;li&gt;shuts down security services &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Mail Propagation&lt;/strong&gt; &lt;/p&gt;
&lt;p&gt;Email addresses are harvested from the following file extensions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;htm &lt;/li&gt;
&lt;li&gt;wab &lt;/li&gt;
&lt;li&gt;txt &lt;/li&gt;
&lt;li&gt;dbx &lt;/li&gt;
&lt;li&gt;tbb &lt;/li&gt;
&lt;li&gt;asp &lt;/li&gt;
&lt;li&gt;php &lt;/li&gt;
&lt;li&gt;sht &lt;/li&gt;
&lt;li&gt;adb &lt;/li&gt;
&lt;li&gt;mbx &lt;/li&gt;
&lt;li&gt;eml &lt;/li&gt;
&lt;li&gt;pmr &lt;/li&gt;
&lt;li&gt;fpt &lt;/li&gt;
&lt;li&gt;inb &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Harvested addresses are stored in five files in the system32 folder
using random names and the file extension .DLL. For example:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;c:\WINDOWS\SYSTEM\ckolieqt.dll &lt;/li&gt;
&lt;li&gt;c:\WINDOWS\SYSTEM\fktnxowp.dll &lt;/li&gt;
&lt;li&gt;c:\WINDOWS\SYSTEM\gczomkgr.dll &lt;/li&gt;
&lt;li&gt;c:\WINDOWS\SYSTEM\hgtmrsvo.dll &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The worm avoids sending itself to certain email addresses, those
containing any of the following strings:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;yaho &lt;/li&gt;
&lt;li&gt;google &lt;/li&gt;
&lt;li&gt;win &lt;/li&gt;
&lt;li&gt;use &lt;/li&gt;
&lt;li&gt;info &lt;/li&gt;
&lt;li&gt;help &lt;/li&gt;
&lt;li&gt;admi &lt;/li&gt;
&lt;li&gt;webm &lt;/li&gt;
&lt;li&gt;micro &lt;/li&gt;
&lt;li&gt;msn &lt;/li&gt;
&lt;li&gt;hotm &lt;/li&gt;
&lt;li&gt;suppor &lt;/li&gt;
&lt;li&gt;syman &lt;/li&gt;
&lt;li&gt;viru &lt;/li&gt;
&lt;li&gt;trend &lt;/li&gt;
&lt;li&gt;secur &lt;/li&gt;
&lt;li&gt;panda &lt;/li&gt;
&lt;li&gt;cafee &lt;/li&gt;
&lt;li&gt;sopho &lt;/li&gt;
&lt;li&gt;kasper &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The body of the email sent by the worm are in the form of Christmas
greetings. Like previous variants, the worm sends itself out in
different languages depending on the Top Level Domain (TLD) of the
recipient's address. For example, a user with a .COM mail address, will
receive the English mail body, while someone with an .DE Mail address
will receive the German body.&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-weight: normal;"&gt;P2P Propagation&lt;/span&gt;&lt;u&gt;
&lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;The worm copies itself to directories on the C: drive containing one
of the following strings:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;share &lt;/li&gt;
&lt;li&gt;upload &lt;/li&gt;
&lt;li&gt;music &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It copies itself using the below filenames:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;winamp 5.7 new!.exe &lt;/li&gt;
&lt;li&gt;ICQ 2005a new!.exe&lt;br&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;&lt;span style="font-weight: normal;"&gt;Payload&lt;/span&gt;&lt;u&gt; &lt;/u&gt;&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;In an attempt to thwart manual identification and cleaning of an
infected machine, the worm will attempt to render the following
processes containing the following strings unavailable:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;reged &lt;/li&gt;
&lt;li&gt;msconfig &lt;/li&gt;
&lt;li&gt;task &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The worm also attempts to shutdown security services like firewalls,
and AV software upon execution.&lt;br&gt;
&lt;/p&gt;
&lt;p&gt;The worm drops the following files to the %windir%\system32 folder:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;C:\WINNT\system32\&lt;RANDOM&gt; .EXE - 11,745 bytes &lt;/RANDOM&gt;&lt;/li&gt;
&lt;li&gt;C:\WINNT\system32\&lt;RANDOM.DLL li="" ytes="" -=""&gt; &lt;/RANDOM.DLL&gt;&lt;/li&gt;
&lt;li&gt;C:\WINNT\system32\Norton Update.exe - 11,745 bytes &lt;/li&gt;
&lt;li&gt;C:\WINNT\system32\&lt;RANDOM&gt; .DLL - (worm zipped up) &lt;/RANDOM&gt;&lt;/li&gt;
&lt;li&gt;C:\s.cm - 20,552 bytes (winzip dll module) &lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;It creates a registry key, so the file gets executed every time the
machine starts: &lt;/p&gt;
&lt;p&gt;HKEY_LOCAL_MACHINE\Software\Microsoft\Windows&lt;br&gt;
\CurrentVersion\Run "Wxp4" = C:\WINDOWS\SYSTEM32\Norton Update.exe &lt;/p&gt;
&lt;p&gt;It creates the following registry key to store information of the
worm: &lt;/p&gt;
&lt;p&gt;HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wxp4&lt;/p&gt;</description><link>http://www.sybari.com/VirusAlerts/VirusAlertView.aspx?Alias=Rainbow&amp;TabId=0&amp;Lang=en-US&amp;mid=10659&amp;ItemID=93</link><pubDate>12/14/2004 12:00:00 AM</pubDate></item></channel></rss>