tasklist.org
A comprehensive list of processes running in your computer
tasklist
|
attachlist
bookmark this website!
total tasks: 16297
AttachList is a list of email attachment files that viruses usually send in email. It contains the attached file names, typical subjects and messages, the name of the viruses that send them, and instruction on how to remove these viruses.
search
most requested
ISUSPM.exe
ctfmon.exe
svchost.exe
AresLite.exe
alg.exe
gcasDtServ.exe
csrss.exe
ccApp.exe
jusched.exe
csrss.exe
Browse
attach
list
by file name
:
|
a
|
b
|
c
|
d
|
e
|
f
|
g
|
h
|
i
|
j
|
k
|
l
|
m
|
n
|
o
|
p
|
q
|
r
|
s
|
t
|
u
|
v
|
w
|
x
|
y
|
z
|
Name:
W32.Sobig
Sender:
Spoofed address (which means that the sender in the "From" field is most likely not the real sender).The worm may use the address admin@internet.com as the sender. (ACF) or big@boss (A) bill@microsoft.com (CDE) support@microsoft.com (B)
Subject:
Approved (CDE) Approved (Ref: 38446-263) (B) Cool screensaver (B) Re: 45443-343556 (CDE) Re: Application (CDE) Re: Approved (CDEF) Re: Approved (Ref: 3394-65467) (B) Re: Details (F) Re: Document (A) Re: Here is that sample (A) Re: Movies (ABCDE) Re: My application (B) Re: My details (B) Re: Re: My details (F) Re: Sample (A) Re: Submited (004756-3463) (CDE) Re: Thank you! (F) Re: That movie (F) Re: Wicked screensaver (F) Re: Your application (CDEF) Screensaver (B) Thank you! (F) Your details (BF) Your password (B)
Message:
varies (A) All information is in the attached file (B) Please see the attached file for details (F) See the attached file for details (F)
Attachment:
45443.pif (CDE) application.pif (BCDEF) approved.pif (BC) Details.pif (B) details.pif (F) doc_details.pif (B) document.pif (CDE) document_9446.pif (F) document_all.pif (F) Document003.pif (A) documents.pif (CDE) movie.pif (CDE) Movie_0074.mpeg.pif (A) movie0045.pif (F) movie28.pif (B) password.pif (B) ref-394755.pif (B) Sample.pif (A) screen_doc.pif (B) screen_temp.pif (B) screensaver.scr (CDE) submited.pif (CDE) thank_you.pif (F) Untitled1.pif (A) wicked_scr.scr (F) your_details.pif (F) your_document.pif (F)
Comments:
A very efficient and active worm that sends itself to all the addresses it finds in the .txt,.eml, .html, .htm, .dbx, and .wab files. Different variations search different types of files.
Symptoms:
Attempts to copy itself to the following folders on all the open network shares: WindowsAll UsersStart MenuProgramsStartUp Documents and SettingsAll UsersStart MenuProgramsStartup Copies itself as %Windir%Winmgm32.exe. Adds the value: WindowsMGM %Windir%Winmgm32.exe to the registry key: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun
Recommended Cleanup Software:
We found that
Easy SpyRemover
is the most effective tool for removing this file.
Manual Removal Instructions:
Update the virus definitions.
Restart the computer or end the Worm process, by performing the following:
Windows 95/98/Me: Restart the computer in Safe mode.
Windows NT/2000/XP: End the Worm process.
Run a full system scan and delete all the files detected as W32.Sobig.A@mm.
Reverse the changes that the Worm made to the registry.
Find and delete the data files created by the worm.
© Copyright 2004, TaskList.org. All rights reserved. Portions copyright by
Paul Collins
(Pacs Portal).
Disclaimer
.
Links