tasklist.org
A comprehensive list of processes running in your computer
tasklist
|
attachlist
bookmark this website!
total tasks: 16297
AttachList is a list of email attachment files that viruses usually send in email. It contains the attached file names, typical subjects and messages, the name of the viruses that send them, and instruction on how to remove these viruses.
search
most requested
ISUSPM.exe
ctfmon.exe
svchost.exe
AresLite.exe
alg.exe
gcasDtServ.exe
csrss.exe
ccApp.exe
jusched.exe
csrss.exe
Browse
attach
list
by file name
:
|
a
|
b
|
c
|
d
|
e
|
f
|
g
|
h
|
i
|
j
|
k
|
l
|
m
|
n
|
o
|
p
|
q
|
r
|
s
|
t
|
u
|
v
|
w
|
x
|
y
|
z
|
Name:
W32.Naco
Sender:
Varies
Subject:
Acheh Issue: What Solution! Alert! New Variant Anacon.D has been detected! (C) Alert! New Variant W32/Naco.F@mm has been detected! (D) Alert! W32.HLLW.Anacon@mm Worm Has been detected! Al-Jazeera: AQTE Come back! Al-Qaeda News: Bombing Mission Success! Al-Qaeda Team Entertainment News [AQTE News] [Blank Subject] (D) Brittish Air Way will backcrupt (D) Check This Out! Crack for Nokia LogoManager 1.3 (CD) Do you happy? Download New 256-Bit Encryption Software FoxNews Reporter: There are no Solution for SARS? (C) FoxNews Reporter: What (D) Free SMS Via NACO SMS! (C) Get Free SMTP Server at Click Here! (CD) Get free update Microsoft Windows Media Player Get Your Free XXX Password! (C) Gotcha baby! (CD) Help Me plz? (CD) Hi, may I read your mind? How to Protect you PC from Hackers! Iraqi people don't want US Control. Less and More (D) Let's Iraqi people build their country. Microsoft Windows LONGHORN XP (D) Nelly Furtado! (C) New! Dragon Ball Fx (C) News: US Goverment try to make wars with Tehran. (CD) Osama Bin Laden Come Back! Out of my heart? (C) Patch for Microsoft Windows XP 64bit (CD) Re: are you married?(3) (C) Re: can mali can! Register you Windows Now! Riyadh Issue: Al-Qaeda vs FBI Saddam Hussein Still alive Seagate Baracuda 80GB for $??? (CD) Small And Destrucive! (CD) TechTV: New Anti Virus Software (CD) TIPs: CODE FOR CRACKING EB SERVER (D) TIPs: HOW TO DEFACE A WEBSERVER? (C) TIPS: How to hide your IP Address! What New in The ScreenSaver! (C) Your FTP Password: iuahdf7d8hf (C) You r a chichy boy, You r a chicky girl (D) Your XXX Password: ud78sd8df (D)
Message:
Attention! (blank) Fall In Love, Great to see you again babe! This is file you want las week. Please don't distribute itto other. Hello dear, Hi babe, Still missing me! I have send to you a special gift I made it my own. Just foryou. Check it out the attachment. Hi dear, I'm gonna missed you babe, hope we can see again! In Love, Once I was first saw you, I was fall in love! Even you are already has special friend! Please do not eat pork! The SARS virus may come from the pig. So becareful. For moreinformation check the attachment. Regard, Regard, WTO (C,D) Rekcahlem (C,D) Rekcahlem ~=~ Anacon Rekcahlem ~~ Anacon (C,D) V.C. (C,D) You may not see the message because the message has been convert to the attachment. Pleaseopen an attachment to see the message. (C,D) Your Love,
Attachment:
Anacon.exe ANACON32.EXE CSRSS32.EXE
Comments:
A mass-mailing worm that can spread via email, peer-to-peer file-sharing applications, suchas KaZaA, as well as network shares. Also contains a functionality to run as a BackdoorTrojan Horse. It can also replace HTML files on Microsoft IIS servers. Emails itself to allthe contacts in the Outlook Address Book.
Symptoms:
Creates a copy of itself as %System%Anacon.exe (where %System% is a variable). The worm locates the System folder and copies itself to that location. By default, this is C:WindowsSystem (Windows 95/98/Me), C:WinntSystem32 (Windows NT/2000), or C:WindowsSystem32 (Windows XP). Overwrite the following files with this content: WARNING! YOUR WEB SERVER HAS BEEN HACKED BY ANACON MELHACKER. Anacon G0t ya! By Melhacker -dA r34L #4(k3R! files: Anacon 6 (D) Anacon 6 WOrm default.asp default.htm default.html index.asp (C) index.htm index.html Create the following registry keys to cause the worm to execute when Windows is started: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun, set to: AHU = "%system%Anacon.exe" HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunServices set to: Hvewsveqmg = "%system%Anacon.exe" HKEY_CURRENT_USER.DEFAULTSoftwareMicrosoftWindowsCurrentVersionRun set to: Cvfjx = "%system%Anacon.exe" The worm will also add the following keys to share the C: drive. HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceslanmanserverShares, HACKERz HKEY_LOCAL_MACHINESYSTEMControlSet001ServiceslanmanserverShares, HACKERz HKEY_LOCAL_MACHINESYSTEMControlSet002ServiceslanmanserverShares, HACKERz
Recommended Cleanup Software:
We found that
Easy SpyRemover
is the most effective tool for removing this file.
Manual Removal Instructions:
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Naco@mm.
Delete the values that were added to the registry.
© Copyright 2004, TaskList.org. All rights reserved. Portions copyright by
Paul Collins
(Pacs Portal).
Disclaimer
.
Links