Worm Library

Online security reference library for public worm releases, from January 1st 2005



14/09/05

Esbot.D

W32.Esbot.D is a worm that exploits the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-039) and opens a back door that allows a remote attacker access to the compromised computer.

Permalink

09/14/05

Kelvir.II

W32.Kelvir.II is a worm that spreads through MSN Messenger and downloads a copy of another threat, which is a Backdoor.Sdbot variant.

Permalink

09/13/05

Inker.B

VBS.Inker.B@mm is a mass-mailing worm that changes icons, swaps mouse buttons, and lowers computer secuirty settings.

Permalink
Wayi

PWSteal.Wayi is a Trojan horse that attempts to steal passwords for the Rexue Jianghu online game offered by wayi.com.tw. The Trojan sends the stolen information to a predetermined email address.

Permalink

09/12/05

Starimp

W32.Starimp is a worm that spreads through peer to peer networks, steals password details, and can download and execute remote files.

Permalink

09/07/05

Spybot.WON

W32.Spybot.WON is a worm that has distributed denial of service and back door capabilities. The worm spreads by exploiting numerous vulnerabilities, including the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (as described in Microsoft Security Bulletin MS05-039).

Permalink
Spybot.WOE

W32.Spybot.WOE is a worm with back door capabilities that can be used to launch a distributed denial of service attack. The worm spreads by exploiting numerous vulnerabilities, including the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (as described in Microsoft Security Bulletin MS05-039).

Permalink

09/01/05

Mailbancos

W32.Mailbancos@mm is a worm that downloads and executes a copy of PWSteal.Bancos and sends emails to addresses gathered from the compromised computer.

Permalink

08/29/05

Mytob.JH

W32.Mytob.JH@mm is a mass-mailing worm the opens a back door and lowers security settings on the compromised computer.

Permalink
Bobax.AH

W32.Bobax.AH@mm is a mass-mailing worm that attempts to use the compromised computer as a covert proxy. The worm spreads by exploiting the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (as described in Microsoft Security Bulletin MS05-039) and by sending a copy of itself to email addresses gathered.

Permalink

08/01/05

Reatle.D

W32.Reatle.D@mm is a mass-mailing worm that opens a back door and attempts to spread by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (as described in Microsoft Security Bulletin MS04-011).

Also Known As: W32/Lebreat-D [Sophos], WORM_REATLE.D [Trend Micro]

Permalink

07/31/05

Falsu.A

W32.Falsu.A is a worm that spreads through file sharing networks and mIRC.

Permalink
Bratle.A

W32.Bratle.A is a worm that attempts to propagate by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (as described in Microsoft Security Bulletin MS04-011). It also opens a FTP server on the compromised computer.

Permalink
Incef

W32.Incef is a worm that spreads through file sharing networks and mIRC.

Permalink

07/06/05

Netsky.AL

W32.Netsky.AL@mm is a mass-mailing worm that sends itself to email addresses it gathers from the compromised computer. The worm also ends some security-related processes.

Also Known As: Trojan-Proxy.Win32.Daemonize.aw [Kaspersky Lab], W32/Mydoom.bs@MM [McAfee], W32/Tame-A [Sophos], PE_FINALDO.B [Trend Micro]

Permalink

07/04/05

Alcra.C

W32.Alcra.C is a worm that spreads through file-share networks and attempts to disable several programs on the compromised computer.

Also Known As: Worm.Win32.VB.an [Kaspersky Lab], Generic VB.b [McAfee], WORM_VB.AQ [Trend Micro]

Permalink
Bobax.AA

W32.Bobax.AA is a mass-mailing worm that sends itself to addresses gathered from the compromised computer and from search results on www.google.com and www.accoona.com. It also operates as a covert proxy.

Also Known As: Backdoor.Win32.Surila.t [Kaspersky Lab], W32/Mydoom.gen@MM [McAfee], W32/MyDoom-Gen [Sophos], WORM_MYDOOM.BG [Trend Micro]

Permalink
Opanki.C

W32.Opanki.C is an IRC threat that may spread through AOL Instant Messenger.

Permalink

07/02/05

Kelvir.DY

W32.Kelvir.DY is a worm that spreads through MSN Messenger and downloads a variant of W32.Randex.

Also Known As: W32.Kelvir!gen, Win32.Kelvir.AK [Computer Associates], IM-Worm.Win32.Kelvir.ca [Kaspersky Lab], W32/Kelvir.worm.df [McAfee]

Permalink

06/30/05

Mytob.GP

W32.Mytob.GP@mm is a mass-mailing worm that opens a back door and lowers security settings on the compromised computer.

Also Known As: Win32.Mytob.GS [Computer Associates], Net-Worm.Win32.Mytob.bs [Kaspersky Lab], W32/Mytob.gen@MM [McAfee], W32/Mytob-CR [Sophos], WORM_MYTOB.GB [Trend Micro]

Permalink
Toxbot.C

W32.Toxbot.C is a worm that opens an IRC back door on the compromised computer and spreads by exploiting vulnerabilities.

Also Known As: Win32.Toxbot.AH [Computer Associates], Backdoor.Win32.Codbot.ag [Kaspersky Lab], W32/Sdbot.worm.gen.w [McAfee], WORM_SDBOT.BLH [Trend Micro]

Permalink

06/29/05

Spybot.RDW

W32.Spybot.RDW is a worm that has distributed denial of service and back door capabilities. The worm spreads to network shares protected by weak passwords and by exploiting computer vulnerabilities.

Permalink

06/28/05

Mydoom.CF

W32.Mydoom.CF@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

Permalink
Kelvir.DT

W32.Kelvir.DT is a worm that spreads through MSN Messenger and drops a W32.Randex variant.

Also Known As: IM-Worm.Win32.Prex.h [Kaspersky Lab], W32/Kelvir-AL [Sophos]

Permalink
Mytob.GJ

W32.Mytob.GJ@mm is a mass-mailing worm that opens a back door and lowers security settings on the compromised computer.

Also Known As: Win32.Mytob.GP [Computer Associates], WORM_MYTOB.BC [Trend Micro]

Permalink

06/27/05

Meetot

W32.Meetot is a worm that copies itself to mapped drives.

Permalink

06/15/05

Kalel.B

W32.Kalel.B@mm is a mass-mailing worm that uses its own SMTP engine to spread. It also attempts to spread through various peer-to-peer file-sharing networks. It typically arrives as an email attachment named mailbox_details.zip.

Permalink
Opanki.B

W32.Opanki.B is an IRC threat that may spread through AOL Instant Messenger.

Also Known As: IRC Trojan, IM-Worm.Win32.Opanki.d [Kaspersky Lab], W32/Opanki.worm.gen [McAfee]

Permalink

06/14/05

Kelvir.DD

W32.Kelvir.DD is a worm that spreads through MSN Messenger.

Also Known As: IM-Worm.Win32.Harwig.a [Kaspersky Lab], W32/Harwig.worm.gen [McAfee], Troj/Harwig-A [Sophos], WORM_HARWIG.B [Trend Micro]

Permalink
Mytob.ER

W32.Mytob.ER@mm is a mass-mailing worm that opens a back door and lowers security settings on the compromised computer.

Also Known As: Win32.Mytob.FV [Computer Associates], WORM_MYTOB.FM [Trend Micro]

Permalink

:: Next Page >>

Worm Library

Worm Library is a public reference library of malicious software releases known as "worms", which initiate mass-mailing infection across networks.

| Next >

More

Leased line UK prices
Discounted prices on UK leased lines for businesses.
Corner shower
Discounted corner showers & bath accessories
Repossession stopped
Stop repossession with a cash house sale.
caravan motorhome repairs Find caravan motorhome repairs.
Spy software
Spy software and hardware for use with home PC.

Syndicate this blog XML

 

This website copyright Worm Library 2005, All Rights Reserved