Left side top banner Digital Connection
Name:  Default    Version:  0.0    OS:  unknown     Browser   
Main Menu
 go to body
Gray Arrow  Home
Gray Arrow  ITC Login
Gray Arrow  ITC Staff
Gray Arrow  Locator
Gray Arrow  Memory
Gray Arrow  Gmail
 
Forms
 
Gray Arrow  Computer Service Request
Gray Arrow  ITC Audit
Gray Arrow  Repair Status
Gray Arrow  Account Management
Gray Arrow  Suggestion Box
 
Information
 
Gray Arrow  Black Board
Gray Arrow  Email
Gray Arrow  MS Internet Explorer
Gray Arrow  MS Windows
Gray Arrow  MS Word
Gray Arrow  Old Email
Gray Arrow  RSS Feed

May 9, 2008


Virus Education: Sober-N

Posted by Tom Brooks at [10:08:30 AM, 5/16/2005], tom.brooks@cvcc.edu

W32/Sober-N is a mass-mailing worm which sends itself to addresses harvested from the infected computer.

The email sent by W32/Sober-N depends on the recipient address. Emails sent to recipients whose email address is in the .de, .ch, .at, .li domains or contains the string "gmx." will receive an email as follows:

http://www.sophos.com/virusinfo/analyses/w32sobern.html


Virus Education: Agobot-PQ

Posted by Tom Brooks at [8:11:25 AM, 2/10/2005], tom.brooks@cvcc.edu

W32/Agobot-PQ is a network worm with backdoor functionality for the Windows platform.

W32/Agobot-PQ is capable of spreading to computers on the local network protected by weak passwords.

http://www.sophos.com/virusinfo/analyses/w32agobotpq.html


Virus Education: Agobot-PQ

Posted by Tom Brooks at [8:12:07 AM, 2/10/2005], tom.brooks@cvcc.edu

W32/Agobot-PQ is a network worm with backdoor functionality for the Windows platform.

W32/Agobot-PQ is capable of spreading to computers on the local network protected by weak passwords.

http://www.sophos.com/virusinfo/analyses/w32agobotpq.html


Virus Education: Rbot-VQ

Posted by Tom Brooks at [8:13:26 AM, 2/10/2005], tom.brooks@cvcc.edu

W32/Rbot-VQ is a network worm and IRC backdoor Trojan for the Windows platform.

W32/Rbot-VQ spreads using a variety of techniques including exploiting weak passwords on computers and SQL servers, exploiting operating system vulnerabilities (including DCOM-RPC, LSASS).


Virus Education: Sober-N

Posted by Tom Brooks at [9:57:16 AM, 5/16/2005], tom.brooks@cvcc.edu

W32/Sober-N is a mass-mailing worm which sends itself to addresses harvested from the infected computer.

The email sent by W32/Sober-N depends on the recipient address. Emails sent to recipients whose email address is in the .de, .ch, .at, .li domains or contains the string "gmx." will receive an email as follows:

http://www.sophos.com/virusinfo/analyses/w32sobern.html


Network Performance

Posted by Tom Brooks at [9:18:46 AM, 2/22/2005], tom.brooks@cvcc.edu

Just a quick note to inform everyone that we are currently addressing the slowness of the network and internet. Due to an outbrake of a trojan horse in the westwing area some services may respond slowly. We expect for this issue to be resolved Friday the 25th.


Virus Education: Agobot-PQ

Posted by Tom Brooks at [8:10:07 AM, 2/10/2005], tom.brooks@cvcc.edu



Virus Education: MyDoom-AR

Posted by Tom Brooks at [8:19:11 AM, 2/9/2005], tom.brooks@cvcc.edu

W32/MyDoom-AR is a mass-mailing and peer-to-peer worm which emails itself as an attachment to addresses found on the infected computer.

When run the W32/MyDoom-AR will launch notepad with garbage which serves as a decoy.

http://www.sophos.com/virusinfo/analyses/w32mydoomar.html


Virus Education: Rbot-ALO

Posted by Tom Brooks at [8:17:07 AM, 2/9/2005], tom.brooks@cvcc.edu

W32/Rbot-ALO is a network worm and IRC backdoor Trojan for the Windows platform.

http://www.sophos.com/virusinfo/analyses/w32rbotalo.html


Virus Education: Sober-J

Posted by Tom Brooks at [4:54:20 PM, 2/7/2005], tom.brooks@cvcc.edu

W32/Sober-J is a variant of the W32/Sober mass mailing worms family for the Windows platform that harvests email addresses from the infected computer's hard drive.

W32/Sober-J checks the country origin by the comparing the domain extension with those within a pre-defined list and will send its mail in either English or German depending on the domain.

http://www.sophos.com/virusinfo/analyses/w32soberj.html


Virus Education: Agobot-PI

Posted by Tom Brooks at [10:42:33 AM, 2/7/2005], tom.brooks@cvcc.edu

W32/Agobot-PI is a network worm with backdoor functionality for the Windows platform.

W32/Agobot-PI is capable of spreading to computers on the local network protected by weak passwords.

http://www.sophos.com/virusinfo/analyses/w32agobotpi.html


Virus Education: Agobot-PI

Posted by Tom Brooks at [10:40:22 AM, 2/7/2005], tom.brooks@cvcc.edu

W32/Agobot-PI is a network worm with backdoor functionality for the Windows platform.

W32/Agobot-PI is capable of spreading to computers on the local network protected by weak passwords.

http://www.sophos.com/virusinfo/analyses/w32agobotpi.html


Virus Education: Rbot-UC

Posted by Tom Brooks at [8:26:48 AM, 2/7/2005], tom.brooks@cvcc.edu

W32/Rbot-UC is a network worm and IRC backdoor Trojan for the Windows platform.

http://www.sophos.com/virusinfo/analyses/w32rbotuc.html


Virus Education: Rbot-TD

Posted by Tom Brooks at [8:59:49 AM, 1/10/2005], tom.brooks@cvcc.edu

W32/Rbot-TD is a worm which attempts to spread to remote network shares. It also contains backdoor Trojan functionality, allowing unauthorised remote access to the infected computer via IRC channels while running in the background as a service process.

W32/Rbot-TD spreads to network shares with weak passwords as a result of the backdoor Trojan element receiving the appropriate commands from a remote user.

http://www.sophos.com/virusinfo/analyses/w32rbottd.html


Virus Education: Forbot-DJ

Posted by Tom Brooks at [8:38:03 AM, 1/4/2005], tom.brooks@cvcc.edu

W32/Forbot-DJ is a Windows network worm which attempts to spread via network shares. The worm contains backdoor functions that allow unauthorised remote access to the infected computer via IRC channels.

Once installed, W32/Forbot-DJ attempts to setup an HTTP proxy server, remove connections to network shares, participate in denial-of-service (DOS) attacks and steal CD keys and email addresses when instructed to do so by a remote attacker.

The worm spreads to network shares with weak passwords and also by using the RPC-DCOM security exploit (MS03-039) and the LSASS security exploit (MS04-011).

http://www.sophos.com/virusinfo/analyses/w32forbotdj.html

Microsoft VBScript runtime error '800a004c'

Path not found

/tutorials/news.inc, line 71