<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>BDS/IRC-M33</title>
    <link>http://forum.geizhals.at/feed.jsp?id=195182</link>
    <description>Geizhals-Forum</description>
    <item>
      <title>Re(2): BDS/IRC-M33</title>
      <link>http://forum.geizhals.at/t195182,1086832.html#1086832</link>
      <description>Body:&lt;br&gt;October 06, 2003&lt;br&gt;Intruder Alert 4.1 W32_Webb_Worm Policy &lt;br&gt;This policy detects the propagation of the W32.SobigF.Worm through &lt;br&gt;changes in the registry.&lt;br&gt;&lt;br&gt;W32.Webb.F@mm is a mass-mailing, network-aware worm that sends &lt;br&gt;itself to all the email addresses it finds in various files. &lt;br&gt;The worm uses its own SMTP engine to propagate and attempts &lt;br&gt;to create a copy of itself on accessible network shares, but &lt;br&gt;fails due to bugs in the code.&lt;br&gt;&lt;br&gt;In attachment you can find program that update your Norton Antivirus to&lt;br&gt;Norton Antivirus 2004. ----&lt;br&gt;&lt;br&gt;Attachment: nav32.zip&lt;br&gt;&lt;br&gt;So that it gets run each time a user restart their computer the following registry keys get added:&lt;br&gt;&lt;br&gt;- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run&lt;br&gt;"windowsupdate"="RPCX1sq23.exe"&lt;br&gt;&lt;br&gt;- HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices&lt;br&gt;"windowsupdate"="RPCX1sq23.exe"&lt;br&gt;&lt;br/&gt;</description>
      <pubDate>Wed, 22 Oct 2003 10:19:30 GMT</pubDate>
      <guid>http://forum.geizhals.at/t195182,1086832.html#1086832</guid>
      <dc:creator>Funki</dc:creator>
      <dc:date>2003-10-22T10:19:30Z</dc:date>
    </item>
    <item>
      <title>Re: BDS/IRC-M33</title>
      <link>http://forum.geizhals.at/t195182,1086831.html#1086831</link>
      <description>Details:&lt;br&gt;--------&lt;br&gt;Name: BDS/IRCBot.Gen&lt;br&gt;Alias: Troj/Ircbot-M, W32.IRCBot.B, W32/Sdbot.worm.gen, Win32.SdBot.18976, Backdoor.IRCBot.gen&lt;br&gt;Type: Backdoor&lt;br&gt;Discovered: October 7, 2003&lt;br&gt;Size: 18.976KB&lt;br&gt;Platform: Windows 95/98/ME/NT/2000/XP&lt;br&gt;&lt;br&gt;&lt;br&gt;Description:&lt;br&gt;------------&lt;br&gt;BDS/IRCBot.Gen has been seen to be originally sent out by email but has no ability to spread itself by its own routines. After the user extracts the attached zip file and executes the UPX packed .exe file, this Backdoor connects to an IRC server on port 31337. The infected computer can then be controlled from the IRC channel. It copies itself in the as "RPCX1sq23.exe" under \windows\%sysdir%\.&lt;br&gt;&lt;br&gt;The sent out email will have the following characteristics:&lt;br&gt;&lt;br&gt;From: updates@symantec.com&lt;br&gt;Subject: Last Update.&lt;br&gt;&lt;br/&gt;</description>
      <pubDate>Wed, 22 Oct 2003 10:18:49 GMT</pubDate>
      <guid>http://forum.geizhals.at/t195182,1086831.html#1086831</guid>
      <dc:creator>Funki</dc:creator>
      <dc:date>2003-10-22T10:18:49Z</dc:date>
    </item>
    <item>
      <title>BDS/IRC-M33</title>
      <link>http://forum.geizhals.at/t195182,1086745.html#1086745</link>
      <description>Hi!&lt;br&gt;&lt;br&gt;Heute hat ein Anit-Virenprogramm den obigen Virus aufm Computer gefunden. Weiß jemand genaueres darüber? Wie verbreitet sich der?&lt;br&gt;Er war in der Datei msmngr32.exe. Und das AV-Programm hat irgendwas von Backdoor gesagt.&lt;br&gt;&lt;br&gt;bimpf&lt;br/&gt;</description>
      <pubDate>Wed, 22 Oct 2003 08:59:24 GMT</pubDate>
      <guid>http://forum.geizhals.at/t195182,1086745.html#1086745</guid>
      <dc:creator>bimpf</dc:creator>
      <dc:date>2003-10-22T08:59:24Z</dc:date>
    </item>
  </channel>
</rss>
