tasklist.org
A comprehensive list of processes running in your computer
tasklist
|
attachlist
bookmark this website!
total tasks: 16297
AttachList is a list of email attachment files that viruses usually send in email. It contains the attached file names, typical subjects and messages, the name of the viruses that send them, and instruction on how to remove these viruses.
search
most requested
ISUSPM.exe
ctfmon.exe
svchost.exe
AresLite.exe
alg.exe
gcasDtServ.exe
csrss.exe
ccApp.exe
jusched.exe
csrss.exe
Browse
attach
list
by file name
:
|
a
|
b
|
c
|
d
|
e
|
f
|
g
|
h
|
i
|
j
|
k
|
l
|
m
|
n
|
o
|
p
|
q
|
r
|
s
|
t
|
u
|
v
|
w
|
x
|
y
|
z
|
Name:
W32.Lirva
Sender:
The worm uses the default SMTP server of the infected computer, and then adds eitherthe address of the sender or a randomly selected email address to the "From:" line ofthe email.
Subject:
Fw: Avril Lavigne - the best (A) Fw: Avril Lavigne - CHART ATTACK! (C) Fw: F. M. Dostoyevsky "Crime and Punishment" (C) Fw: Prohibited customers... (A) Fw: Redirection error notification (C) Fwd: Re: Admission procedure (A) Fwd: Re: Have U requested Avril Lavigne bio? (C) Fwd: Re: Reply on account for Incorrect MIME-header (A) Fwd: RFC-0245 Specification requested... (C) Fwd: RFC-0841 Specification requested... (C) Re: According to Daos Summit (A) Re: According to Purge's Statement (C) Re: ACTR/ACCELS Transcriptions (AC) Re: Brigade Ocho Free membership (AC) Re: Ha perduto qualque cosa signora? (C) Re: IREX admits you to take in FSAU 2003 (C) Re: Junior Achievement (C) Re: Reply on account for IFRAME-Security breach (A) Re: Reply on account for IIS-Security (AC) Re: Reply on account for IIS-Security Breach (TFTP) (C) Re: The real estate plunger (A) Re: Vote seniors masters - don't miss it! (C)
Message:
Avril fans subscription FanList admits you to take in Avril Lavigne 2003 Billboard awardsceremony Vote for I'm with you! Admission form attached below (AC) AVRIL LAVIGNE - THE BEST Avril Lavigne's popularity increases:> SO: First, Vote onTRL for I'm With U! Next, Update your pics database! Chart attack active list .>.> (C) Chart attack active list: Vote fo4r I'm with you! Vote fo4r Sk8er Boi!Vote fo4rComplicated!AVRIL LAVIGNE - THE CHART ATTACK! (C) Microsoft has identified a security vulnerability in Microsoft(R) IIS 4.0 and 5.0 thatis eliminated by a previously-released patch. Customers who have applied that patch arealready protected against the vulnerability and do not need to take additional action.to apply the patch immediately. Microsoft strongly urges all customers using IIS 4.0 and 5.0who have not already done so Patch is also provided to subscribed list of Microsoft TechSupport: (A) Network Associates weekly report: Microsoft has identified a security vulnerability inMicrosoft IIS 4.0 and 5.0 that is eliminated by a previously-released patch.Customers who have applied that patch are already protected against the vulnerability anddo not need to take additional action...to apply the patch immediately. Microsoft stronglyurges all customers using IIS 4.0 and 5.0 who have not already done so Patch is alsoprovided to subscribed list of Microsoft Tech Support: Patch: Date (C) Original message: (C) Restricted area response team (RART) Attachment you sent to %s is intended to overwrite startaddress at 0000:HH4F To prevent from the further buffer overflow attacks apply the MSO-patch (AC)
Attachment:
ADialer.exe (C) ALavigne.exe (C) AvrilLavigne.exe (AC) AvrilSmiles.exe (AC) BioData.exe (C) CERT-Vuln-Info.exe (AC) Cogito_Ergo_Sum.exe (AC) Complicated.exe (AC) Download.exe (A) EntradoDePer.exe (C) IAmWiThYoU.exe (AC) MSO-Patch-0035.exe (AC) MSO-Patch-0071.exe (AC) Phantom.exe (C) Readme.exe (AC) Resume.exe (AC) SiamoDiTe.exe (C) Singles.exe (AC) Sk8erBoi.exe (AC) Sophos.exe (AC) Transcripts.exe (AC) TrickerTape.exe (C) Two-Up-Secretly.exe (AC) (random).TXT (C) (random).DOC (C)
Comments:
A mass-mailing worm that also spreads by IRC, ICQ, KaZaA, and open network shares.This worm attempts to terminate antivirus and firewall products. It also emailsthe cached Windows 95/98/Me dial-up networking passwords to the virus writer.
Symptoms:
Copies itself to Recycled.exe on each local hard drive and modifies the Autoexec.bat file (adding the line: @win .exe), so that the worm runs when you start Windows (on Windows 95/98/Me computers only). (A) If the day of the month is the 7th, 11th, or 24th, the worm will launch your Web browser to www.avril-lavigne.com and display a graphic animation on the Windows desktop. (A) The worm will search the %My Documents% directory for filenames with the extension .TXT or .DOC and attach one to the outgoing message. (C)
Recommended Cleanup Software:
We found that
Easy SpyRemover
is the most effective tool for removing this file.
Manual Removal Instructions:
Restart the computer in Safe mode.
Remove the value that the worm added to the registry and restart in Normal mode.
Update the virus definitions.
Run a full system scan and delete all the files detected as W32.Lirva.A@mm.
© Copyright 2004, TaskList.org. All rights reserved. Portions copyright by
Paul Collins
(Pacs Portal).
Disclaimer
.
Links