Worm
worm Worm derived from ’tapeworm’ in John Brunner’s novel "The Shockwave Rider", via XEROX PARC. A program that propagates itself over a network, reproducing itself as it goes. Compare virus. Nowadays the term has ...

Worm
A worm is a program which reproduces by copying itself over and over, system to system. Worms are self-contained and generally use networks to spread.

Network Worms
A network worm is usually a standalone program that tries to copy itself to other computers connected to the same LAN (Local Area Network). Such worms travel from one computer to another using shares. A ...

Worm Infects Computers With Buffer Overflow Vulnerabilities
Worm Infects Computers With Buffer Overflow Vulnerabilities The worm which spreads to computers at random IP addresses that are infected with virus to the following Microsoft buffer overflow vulnerabilities: DCOM RPC, WebDAV, IIS5/WEBDAV and Locator Service. For ...

MICROSOFT’S Virus/Worm Writer Bounty Pays Off?
MICROSOFT’S Virus/Worm Writer Bounty Pays Off? Microsoft’s offer of a $250,000 dollar reward for information leading to the arrest of the Sasser worm author appears to have paid off. A ring of virus writers ...

Worm that targets virus researchers
Worm that targets virus researchers The W32 / Gatt virus was first detected earlier this month. It infects all .idc files, a format that is used for scripts for the Interactive Disassembler Pro application commonly used ...

Zotob worm infects CNN, ABC and other Media ...
Zotob worm infects CNN, ABC and others It was reported that ABC news writers had to resorted to typewriters to prepare copy for the "World News Tonight" broadcast on Tuesday, as the network and other media ...

Sober.N!Zip Worm
Sober.N!Zip Worm This virus comes as an attachment in the form of a .zip file that contains an executable file named ’winzipped-text_data.txt.pif’. The filename contains a dual extension: the first is .txt, followed by many spaces ...

Storm Worm Botnet Computer Virus
Storm Worm Botnet Computer Virus The FBI issued a warning today about e-mails that purport to link readers to an article about the "FBI Verses Facebook". The FBI Agent says the link is a virus, ...

Removal of Blaster Worm ( MSBlast + Nachi ) virus
W32.Blaster.Worm (Worm/Lovsan.A) is only able to infect Windows NT/2000/XP systems. Computer Virus Outbreak News So is your computer infected? Right click on the 'task bar' and select 'Task Manager'. Click on the 'Processes' tab. If you can find a ...

Zindos Computer Virus
Zindos Computer Virus Win32 / Zindos is a worm that targets computers running Windows. The worm spreads to computers that are already infected by the mass-mailer worm Win32 / Mydoom.O@mm. Win32 / Zindos may perform ...

SQL Slammer Computer Virus
SQL Slammer The Slammer worm targets versions of Microsoft SQL Server 2000 products, as well as MSDE 2000 and related packages. The outbreak began on 25 January 2003 (GMT). According to early reports, the worm ...

Blaster Computer Virus
Blaster Computer Virus Discovered on: August 11, 2003 Systems infected: Windows 2000, Windows XP. Systems not infected: Linux, Macintosh, OS/2, UNIX, Windows 95, Windows 98, Windows Me, Windows NT. W32.Blaster.Worm is a worm that exploits the DCOM RPC vulnerability ...

Atak Computer Virus
Atak Computer Virus Also known as Atak.A worm, Atak.B. Affects only PCs running Windows 95 through Windows XP. Atak is a mass-mailing worm that tries to turn off the most popular antivirus and firewall applications and then ...

Lovgate Computer Virus
Lovgate Computer Virus Lovgate Computer Virus is mass mailing and network worm which also has a backdoor component. Apart form the mass mailing functionality this worm can spread through windows shares and steal users´ ...

Nachi Computer Virus
Nachi Computer Virus Win32 / Nachi is a family of network worms that spread across network connections by exploiting one or more vulnerabilities in Windows. These worms can also spread using backdoors opened by other ...

Removal of W32.Bugbear.b@MM
The worm uses the Incorrect MIME Header Can Cause IE to Execute E-mail Attachment vulnerability to cause unpatched systems to auto-execute the worm when reading or previewing an infected message.

In addition, the worm contains routines ...

Code Red Computer Virus
Code Red The Code Red worm is self-replicating malicious code that exploits a known vulnerability in Microsoft IIS servers.  The "Code Red" worm attack proceeds as follows: The "Code Red" worm attempts to connect to TCP port ...

Download
Stinger is a small (about 800kb, that can easily copied into a floppy) stand-alone utility from Mcafee for all version of Microsoft Windows. It is a fast and quick way to detect and remove specific ...

DRVDDLL.EXE
DRVDDLL.EXE W32.Beagle.AP@mm is a mass-mailing worm that spreads via email, using its own SMTP engine. It copies itself as the following files: drvddll.exe; drvddll.exeopen; drvddll.exeopenopen; drvddll.exeopenopenopen. Alias: I-Worm/Bagle.AB, Win32:Beagle-Z, Worm/Bagle.AA, Win32/Bagle.AB, W32/Bagle.aa @MM, W32.Beagle.X @mm, I-Worm.Bagle.z, Win32/Bagle.Z ...

SQL.Spida Computer Virus
SQL Spida Computer Virus > Source IP: 203.125.96.38
> Time Zone: UTC
>
> Event Date Time, Destination IP, IP Protocol, Target
> Port, Issue
> Description, Source Port, Event Count
> EventRecord: 6 Dec ...

Novarg Computer Virus
Novarg Computer Virus Discovered on: January 26, 2004 Systems infected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP System not infected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x ...

WIN.exe
WIN.exe W32/Agobot-KN is an IRC backdoor Trojan and network worm which establishes an IRC channel to a remote server in order to grant an intruder access to the compromised computer.  This worm will move itself into ...

SirCam Computer Virus
SirCam.worm SirCam virus send out random files and personal documents from infected PCs, not all of the information that spread with Win32/SirCam was spread by the worm itself. Almost as soon as updated descriptions of ...

New iPod RJump Virus
New iPod RJump Virus The W32 / RJump.worm, which was discovered June 20, 2006, recently reappeared on video iPod devices released by Apple late September 2006. RJump Worm uses the Python scripting language and is ...

Nyxem Computer Virus
Nyxem Computer Virus Nyxem Computer Virus is a new e-mail worm that spreads under the guise of pornographic content, thus aka Kama Sutra Worm. When run on a Windows PC, the worm copies itself to ...

wintcp.exe
wintcp.exe System may have been infected with W32 / Agobot-ZH. W32 / Agobot-ZH copies itself to network shares with weak passwords and attempts to spread to computers using the DCOM RPC and RPC locator vulnerabilities. ...

Mytob is Top
Mytob is Top Mytob worm account for 14 of the top 20 most commonly reported viruses in the past week. E-mail sent by the new versions of the Mytob worm masquerade as a seemingly legitimate message from ...

NetSky is Virus of the year for 2004
NetSky is Virus of the year for 2004 NetSky worm continued to dominate the anti-virus charts in 2005. This mass-mailing worm rides on social engineering computer users penchant for opening attachment of email messages from ...

AVG Virus Remover
AVG Virus Remover Download the remover vcleaner.exe. Restart your computer in Safe mode and run the remover on the infected computer. Link to Grisoft.com site - maker of AVG Virus Remover.  This is a very small ...

SQLSnake Computer Virus
SQLSnake Computer Virus The SQLSnake Worm Computer Virus which is also known as the Spida worm, SQLSpida, and Digispid.B.Worm uses a brute-force password attack on the sa SQL Server administrator’s account. TCP port 1433 is ...

Randex Computer Virus
Randex Computer Virus AKA: W32.Sluter.B, Randex.Worm, Backdoor.Sdbot.gen Randex is a modified variant of Sluter worm, spreads using network shares. Sluter worm scans for IP addresses and infects systems with weak password or no password. ...

Removal of Trojan
Randon Virus I was slack and this virus hit our web server pool. All our 3 web servers were infected. Luckily, I noticed a day after the trojan was installed and my anti-virus prevented the ...

Evaman Computer Virus
Evaman Computer Virus Evaman is another mass mailer worm.  It is like the MyDoom worm that cost businesses hundreds of millions of dollars in January.  Evaman reportedly uses a false email address to generate messages with an attachment that carries ...

Zafi.D Virus
Zafi.D Virus The new variant of Zafi worm - Zafi.D - is spreading. While the original Zafi.A uses only Hungarian, the new Zafi.D spreads in email in English, Italian, Spanish, Russian, Swedish and several other languages. ...

Welchia Computer Virus
Welchia.Worm Computer Virus Discovered on: August 18, 2003 Systems infected: Microsoft IIS, Windows 2000, Windows XP. Systems not infected: Linux, Macintosh, OS/2, UNIX, Windows 3.x, Windows 95, Windows 98, Windows Me. Patches and fixes: To ...

winxp.exe
winxp.exe winxp or winxp.exe with the process name of W32.Beagle.AG@mm. The winxp.exe is a process which is registered as the W32.Beagle.AG@mm. This virus is distributed via the Internet through e-mail and comes in the form of ...

How virus harvest e-mail addresses
How virus harvest e-mail addresses. The worm scans files with certain extensions on all hard disks to harvest e-mail addresses. Files with the following extensions are scanned:  ini log mdb tbb abd adb pl rtf doc ...

Nopir Computer Virus
Nopir Computer Virus Nopir Virus was designed to look like a DVD-cracking program, to fool people looking for a program that will circumvent copy-restriction technology on the discs. When the worm is downloaded and run, ...

Mcafee Log
Review Mcafee Scan Log: 9/4/2003 3:03:59 PM  C:\WINXP\system32\wins\DLLHOST.EXE W32/Nachi.worm
C:\System Volume Information\_restore{51AA6DBF-81DD-4C9D-A65D-E26C6DD1D3D5}\RP138\A0034475.EXE W32/Nachi.worm 6/8/2004 11:02:21 AM Move failed (Delete failed)   C:\Documents and Settings\SGNLW\Local Settings\Temp\ps_install-mt.exe Adware-PurityScan
C:\WINXP\system32\wintsu.exe Adware-PurityScan
C:\WINXP\system32\NAVSCAN32.exe W32/Sdbot.worm.gen.m
C:\WINXP\system32\NAVSCAN32.exe W32/Sdbot.worm.gen.m
C:\WINXP\system32\NAVSCAN32.exe W32/Sdbot.worm.gen.m
C:\WINXP\system32\NAVSCAN32.exe W32/Sdbot.worm.gen.m
C:\WINXP\system32\NAVSCAN32.exe W32/Sdbot.worm.gen.m
C:\WINXP\system32\NAVSCAN32.exe W32/Sdbot.worm.gen.m 6/14/2004 2:57:41 PM C:\Documents and Settings\SGNLW\Local Settings\Temp\VVSN_CLIC0404Inst.exe Adware-SaveNow
C:\WINXP\system32\wintsu.exe Adware-PurityScan
C:\Program Files\VVSN\URL1\SAVE-SYNCm-WHSE_sb.min.g2Inst.exe Adware-SaveNow
C:\Documents and Settings\SGNLW\Local Settings\Temp\B7C.WUT\WUSearch.cab\Search.exe Adware-SaveNow
6/14/2004 2:58:51 PM Move failed (Delete failed)  HAGGLUNDS\SGNLW C:\Program Files\WhenUSearch\SET15.tmp Adware-SaveNow
6/14/2004 2:58:53 PM Move failed (Delete failed)  HAGGLUNDS\SGNLW C:\Program Files\WhenUSearch\SET16.tmp Adware-SaveNow
6/14/2004 2:59:41 ...

systemse.exe
systemse.exe W32 / Rbot-BD is a member of the W32 / Rbot family of worms with backdoor capabilities. In order to run automatically when Windows starts up the worm copies itself to the file systemse.exe ...

Dumaru Computer Virus
Dumaru Computer Virus Discovered on: January 25, 2004 Systems infected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows XP System not infected: DOS, Linux, Macintosh, OS/2, UNIX, Windows 3.x
W32.Dumaru.Z@mm is a multi-threaded, ...

Basic instincts 2
Here are some more viruses:
W95/Spaces.1445
I-Worm/Netsky.B/C/D
I-Worm/Mydoom.F
I-Worm/Bagle.C/D/E/F The following list will help you to learn how to identify if the mail you have received is indeed a bad e-mail in disguised. Line 1: Subject
Line 2: Body Text
Line 3: Attachement Generating ...

WINGO.EXE
WINGO.EXE When executed (as an Or bawindo.EXE or Wingo.EXE), the worm installs itself to the victim machine with the Windows system folder as WINGO.EXE (C: \ WINNT \ SYSTEM32 \ WINGO.EXE). If the worm is ...

Gammima Computer Virus
Gammima Computer Virus On July 2008, the Gammima virus that was intended to steal passwords and send them to a remote server infected laptops in the International Space Station. And according to NASA, this wasn't ...

Doomjuice Computer Virus
Doomjuice Computer Virus Win32 / Doomjuice is a family of worms that target machines infected with Win32 / Mydoom. Win32 / Doomjuice scans for systems listening on the TCP port opened by the backdoor component ...

Rjump Computer Virus
Rjump Computer Virus W32 Rjump.worm is a worm target USB memory drives and disk devices. It attempts to spread by coping itself to mapped and removable storage drives and also opens a backdoor on an ...

Mytob Computer Virus
Mytob Computer Virus W32.Mytob is a mass-mailing worm with back door capabilities that uses its own SMTP engine to send email to addresses that it gathers from the compromised computer. Mytob virus comes as ...

Cellery Computer Virus
Cellery Computer Virus A new virus dubed Cellery-A (W32 / Cellery-A). The game hides as a playable version of the classic game Tetris. The Cellery worm, which gets its name from a message it displays saying ...

Rbot Computer Virus
Rbot Computer Virus Win32.Rbot is an IRC controlled backdoor or "bot" that can be used to gain unauthorized access to a victim’s machine. It also exhibit worm-like functionality by exploiting weak passwords on administrative shares ...

Deloder Computer Virus
W32/Deloder.worm (raddrv.dll) Deloder (w32.deloder.a) does not spread using e-mail; rather, it scans the Internet looking for open 445 TCP/IP ports.  Deloder carries an infected version of a commonly available network remote administration tool, and an Internet ...

Sober Computer Virus
Sober Virus The worm sends e-mail messages with German and English texts. When sending a message to an e-mail address, that has domain suffix DE, CH, AT, LI, NL or BE as well as the ...

Port Probe TCP Port : 135
Port Probe TCP Port : 135 DCE endpoint resolution If you see port scan on 135, someone on your subnet mask must have got virus on their computer. The Blaster virus worm packed with the run time compression ...

IMAD.EXE
IMAD.EXE Suspected virus, trojan, or worm file

Wallon Computer Virus
Wallon Computer Virus A new mass mailing worm, Wallon, attempts to destroy Windows Media player when an .mp3 file or video files is played on an infected PC. Instead of arriving as an attachment ...