![]() |
![]() |
![]() |
||||
Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums. You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today! If you have any problems with the registration process or your account login, please contact us. |
![]() ![]() |
|
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed. |
|
Thread Tools |
![]() |
#1 |
Entrepreneur
Join Date: Oct 2002
Location: USA
Posts: 31,429
|
Nasty Sneaky Virus Propogating
A very high risk virus is circulating. I've had it try to come through 3 times already today. Be sure to update your virus protection .dats.
W32/Bugbear.b@MM This is a complex worm that contains many different elements: Mass-mailer Network Share Propagator Keylogger Remote Access Trojan Polymorphic Parasitic File Infector Security Software Terminator Full Details: http://vil.mcafee.com/dispVirus.asp?virus_k=100358 Keylogging The virus installs a keylogger DLL, which it uses to captured typed keystrokes. The name of this DLL is random, contains 7 characters followed by .dll and is placed in the SYSTEM (%SysDir%) directory. Two other files, using similar names, are also placed there. These other files contain encrypted, captured, information. A small randomly named .dat file is placed in the WINDOWS (%WinDir%) directory. Remote Access Trojan The worm listens on TCP Port 1080 for commands, allowing a remote attacker to gain access to the compromised system. Parasitic File Infecting The virus attempts to infect specific executables. It retrieves the path to the Program Files directory from the registry: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\ProgramFilesDir It also tries to infect the following files: hh.exe mplayer.exe notepad.exe regedit.exe scandskw.exe winhelp.exe ACDSee32\ACDSee32.exe Adobe\Acrobat 4.0\Reader\AcroRd32.exe adobe\acrobat5.0\reader\acrord32.exe AIM95\aim.exe CuteFTP\cutftp32.exe DAP\DAP.exe Far\Far.exe ICQ\Icq.exe Internet Explorer\iexplore.exe kazaa\kazaa.exe Lavasoft\Ad-aware 6\Ad-aware.exe MSN Messenger\msnmsgr.exe Outlook Express\msimn.exe QuickTime\QuickTimePlayer.exe Real\RealPlayer\realplay.exe StreamCast\Morpheus\Morpheus.exe Trillian\Trillian.exe Winamp\winamp.exe Windows Media Player\mplayer2.exe WinRAR\WinRAR.exe winzip\winzip32.exe WS_FTP\WS_FTP95.exe Zone Labs\ZoneAlarm\ZoneAlarm.exe Security Software Terminating ACKWIN32.exe ANTI-TROJAN.exe APVXDWIN.exe AUTODOWN.exe AVCONSOL.exe AVE32.exe AVGCTRL.exe AVKSERV.exe AVNT.exe AVP32.exe AVP32.exe AVPCC.exe AVPCC.exe AVPDOS32.exe AVPM.exe AVPM.exe AVPTC32.exe AVPUPD.exe AVSCHED32.exe AVWIN95.exe AVWUPD32.exe BLACKD.exe BLACKICE.exe CFIADMIN.exe CFIAUDIT.exe CFINET.exe CFINET32.exe CLAW95.exe CLAW95CF.exe CLEANER.exe CLEANER3.exe DVP95.exe DVP95_0.exe ECENGINE.exe ESAFE.exe ESPWATCH.exe F-AGNT95.exe FINDVIRU.exe FPROT.exe F-PROT.exe F-PROT95.exe F-STOPW.exe IAMAPP.exe IAMSERV.exe IBMASN.exe IBMAVSP.exe ICLOAD95.exe ICLOADNT.exe ICMON.exe ICSUPP95.exe ICSUPPNT.exe IFACE.exe IOMON98.exe JEDI.exe LOCKDOWN2000.exe LOOKOUT.exe LUALL.exe MOOLIVE.exe MPFTRAY.exe N32SCANW.exe NAVAPW32.exe NAVLU32.exe NAVNT.exe NAVW32.exe NAVWNT.exe NISUM.exe NMAIN.exe NORMIST.exe NUPGRADE.exe NVC95.exe OUTPOST.exe PADMIN.exe PAVCL.exe PAVSCHED.exe PAVW.exe PCCWIN98.exe PCFWALLICON.exe PERSFW.exe RAV7.exe RAV7WIN.exe RESCUE.exe SAFEWEB.exe SCAN32.exe SCAN95.exe SCANPM.exe SCRSCAN.exe SERV95.exe SPHINX.exe SWEEP95.exe TBSCAN.exe TDS2-98.exe TDS2-NT.exe VET95.exe VETTRAY.exe VSCAN40.exe VSECOMR.exe VSHWIN32.exe VSSTAT.exe WEBSCANX.exe WFINDV32.exe ZONEALARM.exe
__________________
![]() from the leaders in the field at iWebmasters.com TO LOWER YOUR COSTS AND INCREASE YOUR PRODUCTION! *** *** *** *** *** *** *** *** *** *** *** *** ![]() ![]() ![]() ![]() ![]() |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#2 |
Confirmed User
Join Date: Jun 2001
Location: Closer than you think
Posts: 9,535
|
They should kill the motherfuckers who write these programs. Fucking bullshit. I run mail lists and my accounts been flooded with various size file attachments caused by these viruses
![]()
__________________
Need Mainstream Content and SEO? SEO * Website Copy * Blogs Blogging - PR Work - Forum Marketing - Social Marketing - Link building - Articles 100% Guaranteed Content! |
![]() |
![]() ![]() ![]() ![]() ![]() |
![]() |
#3 |
Confirmed User
Join Date: Mar 2002
Location: : unknown
Posts: 3,377
|
jesus that looks like a nasty one.
updating AVG now - thanks for the heads up |
![]() |
![]() ![]() ![]() ![]() ![]() |