WitchDoc
This malware was reported by: Network Associates Inc
BackDoor-CIL
This malware was reported by: Network Associates Inc
Mydoom.X
This malware was reported by: Panda Software
Mydoom.X is a worm that connects to several websites in order to download and installs a file belonging to a backdoor, on the affected computer.Mydoom.X spreads via e-mail in a message with variable characteristics.
SdBot
This malware was reported by: F-Secure
Bot disinfection
This malware was reported by: F-Secure
Sdbot.RPC.A
This malware was reported by: F-Secure
Troj/Psyme-AS
This malware was reported by: Sophos
Bizex.E
This malware was reported by: F-Secure
This is a trojan that has spying and data stealing capabilities.
The web page were the original file (downloaded via ActiveX exploit)
was located is not available anymore.
W32/Mydoom.v@MM
This malware was reported by: Network Associates Inc
Trojan.Kreol
This malware was reported by: Symantec
Trojan.Kreol is a Trojan horse program that will terminate and block all the dial-up connections.
Backdoor.IRC.Lazz
This malware was reported by: Symantec
Backdoor.IRC.Lazz is a backdoor Trojan horse program that contacts a remote attacker through an IRC channel and attempts to create a copy of the W32.Randex worm in network shares protected by weak passwords.
W32.Mydoom.V@mm
This malware was reported by: Symantec
W32.Mydoom.V@mm is a mass-mailing worm that downloads an executable file.
Backdoor.Nemog.C
This malware was reported by: Symantec
Backdoor.Nemog.C is a back door Trojan horse program that allows a compromised system to be used as an email relay and http proxy. The Trojan also blocks access to several security related Web sites.
W32.Sykel
This malware was reported by: Symantec
W32.Sykel is a worm that attempts to exploit the Microsoft Windows LSASS Buffer Overrun Vulnerability described in Microsoft Security Bulletin MS04-011. It also attempts to propagate through the KaZaA file sharing networks.
W32.HLLW.Zusha
This malware was reported by: Symantec
W32.HLLW.Zusha is is a worm that attempts to exploit the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011) using TCP port 445.
This worm propagates by scanning randomly selecte
Mydoom.Y
This malware was reported by: Computer Associates
Win32.Mydoom.Y is a worm that spreads via e-mail. It has been distributed as a 18,432-byte, UPX-packed Win32 executable and may be included in a ZIP archive
TrojanDownloader.JS.Gen
This malware was reported by: F-Secure
W32/Rbot-JC
This malware was reported by: Sophos
W32/Mydoom.w@MM
This malware was reported by: Network Associates Inc
W32/MyDoom-W
This malware was reported by: Sophos
Linux/Cassini
This malware was reported by: Network Associates Inc
Downloader-ND
This malware was reported by: Network Associates Inc
IPSpoofer-B
This malware was reported by: Network Associates Inc
W32/Alizado.worm
This malware was reported by: Network Associates Inc
PWS-IT
This malware was reported by: Network Associates Inc
W32/Bagle-AM
This malware was reported by: Sophos
Linux/BackDoor-Rooted
This malware was reported by: Network Associates Inc
Wootbot
This malware was reported by: F-Secure
W32.Spybot.DNB
This malware was reported by: Symantec
W32.Spybot.DNB is a worm that may be remotely controlled via IRC channels. The worm has the ability to perform distributed denial of service (DDoS) attacks and open a backdoor on the infected computers. It also attempts to steal CD keys from some compu
W32.Spybot.DNC
This malware was reported by: Symantec
W32.Spybot.DNC is a worm that may be remotely controlled via IRC channels. The worm has the ability to perform distributed denial of service (DDoS) attacks and open a backdoor on the infected computers. It also attempts to steal CD keys from some comput
W32/Amus.a@MM
This malware was reported by: Network Associates Inc
W32.Multex.B
This malware was reported by: Symantec
W32.Multex.B is a worm that attempts to exploit the Microsoft Windows LSASS Buffer Overrun Vulnerability (described in Microsoft Security Bulletin MS04-011). It also attempts to propagate through the Kazaa file-sharing network.
Note: Virus definitions
W32/MyDoom-X
This malware was reported by: Sophos
Proxy-Speednet
This malware was reported by: Network Associates Inc
ProcKill-BX
This malware was reported by: Network Associates Inc
Downloader-OO
This malware was reported by: Network Associates Inc
Downloader-OE
This malware was reported by: Network Associates Inc
W32/Forbot-V
This malware was reported by: Sophos
BackDoor-CGU
This malware was reported by: Network Associates Inc
IdentDaemon
This malware was reported by: Network Associates Inc
Downloader-NW
This malware was reported by: Network Associates Inc
W32.Mydoom.W@mm
This malware was reported by: Symantec
W32.Mydoom.W@mm is a mass-mailing worm that attempts to perform a Distributed Denial of Service (DDoS) attack against www.symantec.com.
Kaland
This malware was reported by: Network Associates Inc
BackDoor-CHA
This malware was reported by: Network Associates Inc
BackDoor-CIO
This malware was reported by: Network Associates Inc
W32/Mydoom.z@MM
This malware was reported by: Network Associates Inc
MS04-028_JPEG_GDI
This malware was reported by: Trendmicro
This vulnerability lies in the way the affected components, as listed below, process JPEG image files. An unchecked buffer within this process is the cause of the vulnerability.
MyDoom.Y
This malware was reported by: F-Secure
A new variant of MyDoom worm - Mydoom.Y, was found on September
14th, 2004. It spreads in e-mails with different subject and body
texts, downloads and activates a backdoor.
This variant was already detected generically as I-Worm.MyDoom.gen.
This var
MS Vulnerability MS04-028
This malware was reported by: Network Associates Inc
MS Vulnerability MS04-027
This malware was reported by: Network Associates Inc
Slinbot.LY
This malware was reported by: Computer Associates
Win32.Slinbot.LY is a worm that spreads via network shares using a primitive dictionary attack. It also contains an IRC-controlled backdoor that allows for
Adware-CnsMin
This malware was reported by: Network Associates Inc
Mydoom.Z
This malware was reported by: Panda Software
Mydoom.Z is a worm that connects to several websites in order to download and install a file belonging to a backdoor, on the affected computer.In addition, Mydoom.Z ends processes belonging to several antivirus programs and firewalls, among other securit
StartPage-DX
This malware was reported by: Network Associates Inc
W32/Mydoom.ab@MM
This malware was reported by: Network Associates Inc
Hacktool.IPCscan
This malware was reported by: Symantec
Hacktool.IPCscan is a hack tool that scans for network shares and attempts to log on to them.
W32.Spybot.CYM
This malware was reported by: Symantec
W32.Spybot.CYM is a worm that may be remotely controlled using IRC. The worm includes Distributed Denial of Service (DDoS) and backdoor capabilities. It also tries to steal CD keys for a number of games.
Backdoor.Sdbot.AA
This malware was reported by: Symantec
Backdoor.Sdbot.AA is a backdoor Trojan horse program that allows a remote attacker to have unauthorized access to the infected computer.
Trojan.Webus
This malware was reported by: Symantec
Trojan.Webus is a Trojan horse program that kills antivirus services and launches Distributed Denial of Service (DDoS) attacks against a list of remote servers.
W32.Aizu
This malware was reported by: Symantec
W32.Aizu is a worm that attempts to exploit the Microsoft Windows Local Security Authority Service Remote Buffer Overflow (described in Microsoft Security Bulletin MS04-011) using TCP port 445. This worm propagates by scanning randomly selected IP addres
Mydoom.Z
This malware was reported by: Computer Associates
Win32.Mydoom.Z is a worm that spreads via e-mail and Peer-to-Peer file sharing networks using the Kazaa application. It has been distributed as a 88,640-byt
Mitglieder.cc
This malware was reported by: F-Secure
Mitglieder.cc is a proxy trojan. However, the update published on
September 14th 2004 (2004-09-14_02) had a false alarm on file
U2FHTML.DLL which is part of Crystal Reports. This false alarm has
been fixed in the update 2004-09-15_01.
W32/Forbot-W
This malware was reported by: Sophos
Mydoom.AA
This malware was reported by: Computer Associates
Win32.Mydoom.AA is a worm that spreads via e-mail, the KaZaA peer to peer network, ICQ and by exploiting the LSASS buffer overflow vulnerability. It has bee
W32/Myfip-A
This malware was reported by: Sophos
PWS-ATM
This malware was reported by: Network Associates Inc
StartPage-EF
This malware was reported by: Network Associates Inc
E2Give
This malware was reported by: Network Associates Inc
Adware-E2Give
This malware was reported by: Network Associates Inc
BackDoor-CEB.d
This malware was reported by: Network Associates Inc
W32/Mydoom.y@MM
This malware was reported by: Network Associates Inc
-- Update September 15th, 2004 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://news.zdnet.co.uk/communications/networks/0,39020345,39166546,00.htm
--
This Mydoom variant is pac
Bagle.AL
This malware was reported by: Computer Associates
Remadmin.A
This malware was reported by: Computer Associates
Win32.Remadmin.A is a worm that spreads via Windows file sharing, and installs a backdoor allowing complete control of an affected system. It consists of mu
W32.Mexer.E@mm
This malware was reported by: Symantec
W32.Mexer.E@mm is a mass-mailing worm that also spreads through several file-sharing networks.
Backdoor.Sdbot.AB
This malware was reported by: Symantec
Backdoor.Sdbot.AB is a Trojan horse program with backdoor capabilities that spreads to network shares and allows a remote attacker to gain unauthorized access to an infected computer.
Unknown
This malware was reported by: Computer Associates
VBS.Vabi@mm
This malware was reported by: Symantec
VBS.Vabi@mm is a mass-mailing worm that infects .frm, .cpp, and .pas files.
StartPage-EF.dll
This malware was reported by: Network Associates Inc
Bloodhound.Exploit.13
This malware was reported by: Symantec
Bloodhound.Exploit.13 is a heuristic detection for malformed JPEG files that are potentially related to the GDI+ integer overflow, described in Microsoft Security Bulletin MS04-028.
The files detected as Bloodhound.Exploit.13 may be malicious, or they m
W32.Mydoom.Y@mm
This malware was reported by: Symantec
W32.MyDoom.Y@mm is a mass-mailing worm.
W32/Sdbot-PG
This malware was reported by: Sophos
W32.Mydoom.AB@mm
This malware was reported by: Symantec
W32.MyDoom.AB@mm is a mass-mailing worm that downloads a copy of Backdoor.Nemog.D and spreads via ICQ and the Kazaa file-sharing network.
Evaman.E
This malware was reported by: Computer Associates
Win32.Evaman.E is a worm that spreads via e-mail. It has been distributed as a 23,040-byte, PECompact-packed Win32 executable and may also arrive attached t
Evaman.D
This malware was reported by: Computer Associates
Win32.Evaman.D is a worm that spreads via e-mail. It has been distributed as a 22,016-byte, PECompact-packed Win32 executable and may also arrive attached t
Evaman.D
This malware was reported by: Panda Software
Evaman.D is a worm that checks every 5 seconds if processes containing certain text strings are active in memory, and ends them. Some processes that include those text strings belong to antivirus programs and system tools, among others, and ending them w
W32/Lovgate-X
This malware was reported by: Sophos
Exploit-MS04-028
This malware was reported by: Network Associates Inc
W32/Rbot-JR
This malware was reported by: Sophos
MyDoom.AB
This malware was reported by: F-Secure
A new variant of MyDoom worm - Mydoom.AB, was found on September
16th, 2004. This worm variant is similar to previous variants.
It spreads in e-mails with different subject and body texts, downloads and
activates a backdoor.
W32/Fightrub@MM
This malware was reported by: Network Associates Inc
This worm is designed to propagate through peer-to-peer file-sharing networks and email.
When run, the worm displays a bogus message:
It creates the folder C:Sysnet and copies itself to this folder with the following file names :
WORM_SDBOT.VQ
This malware was reported by: Trendmicro
This memory-resident worm spreads via network shares. It exploits certain vulnerabilities to propagate across networks. It takes advantage of the following Windows vulnerabilities:
W32/MyDoom-Z
This malware was reported by: Sophos
BackDoor-CIV
This malware was reported by: Network Associates Inc
Mydoom.AB
This malware was reported by: Panda Software
Mydoom.AB is a worm that connects to several websites in order to download and install a file belonging to a backdoor on the affected computer.In addition, Mydoom.AB ends processes belonging to several antivirus programs and firewalls, among other securi
Trojan.Anits
This malware was reported by: Symantec
Trojan.Anits is a Trojan horse program that downloads and executes remote files from the Internet.
Backdoor.Nemog.D
This malware was reported by: Symantec
Backdoor.Nemog.D is a backdoor Trojan horse program that allows an infected computer to be used as an email relay and http proxy. It also blocks access to several security-related Web sites.
W32/Sdbot-PI
This malware was reported by: Sophos
BackDoor-CIM
This malware was reported by: Network Associates Inc
W32/Sdbot-PJ
This malware was reported by: Sophos
Downloader-LU
This malware was reported by: Network Associates Inc