tasklist.org
A comprehensive list of processes running in your computer
tasklist
|
attachlist
bookmark this website!
total tasks: 16297
AttachList is a list of email attachment files that viruses usually send in email. It contains the attached file names, typical subjects and messages, the name of the viruses that send them, and instruction on how to remove these viruses.
search
most requested
ISUSPM.exe
ctfmon.exe
svchost.exe
AresLite.exe
alg.exe
gcasDtServ.exe
csrss.exe
ccApp.exe
jusched.exe
csrss.exe
Browse
attach
list
by file name
:
|
a
|
b
|
c
|
d
|
e
|
f
|
g
|
h
|
i
|
j
|
k
|
l
|
m
|
n
|
o
|
p
|
q
|
r
|
s
|
t
|
u
|
v
|
w
|
x
|
y
|
z
|
Name:
W32.HLLW.Morb
Sender:
Varies.
Subject:
bi**h ;), btw, download this, B-ville did it again ... Check this out Check this out, Come on honey! Company information F**k this, Free porn at Hahaha, Here you go, I recall you asked for this. hey go to, Hey sweety, check the attachement. hmmmm, HOLY S**T, How come this happened? How do you feel about this? I admit it ... I love you I love this funny game, check it out. Is this possible? is this you? I wanted to show you this, Keep it a secret please! lol, Microsoft Windows Security Update omg omg omg I found the best app, please check out, Please do not make this public, thank you. Please install this update, its required rofl, S*x me up S*x me up baby See if you can get this to work See if you can get this to work, This guy is a moron, this is cool, this is funny, This is me, This is me naked, This is what you wanted, right? This is so funny This is the stock information you wanted. To be or not to be? weird, What have they done with you? whats this? Whats wrong with? With love from b-ville! WOW CHECK THIS OUT, wtf?
Message:
(chosen from same list as subject line) bi**h ;), btw, download this, B-ville did it again ... Check this out Check this out, Come on honey! Company information F**k this, Free porn at Hahaha, Here you go, I recall you asked for this. hey go to, Hey sweety, check the attachement. hmmmm, HOLY S**T, How come this happened? How do you feel about this? I admit it ... I love you I love this funny game, check it out. Is this possible? is this you? I wanted to show you this, Keep it a secret please! lol, Microsoft Windows Security Update omg omg omg I found the best app, please check out, Please do not make this public, thank you. Please install this update, its required rofl, S*x me up S*x me up baby See if you can get this to work See if you can get this to work, This guy is a moron, this is cool, this is funny, This is me, This is me naked, This is what you wanted, right? This is so funny This is the stock information you wanted. To be or not to be? weird, What have they done with you? whats this? Whats wrong with? With love from b-ville! WOW CHECK THIS OUT, wtf?
Attachment:
Attachement.exe B-ville.exe FreeSex.exe I_Love_U.exe information.DOC.exe NakedPics.JPG.exe Q349247.exe Saddam_Game.exe SecretFile.exe StockInformation.XLS.exe
Comments:
A MAPI worm that replies to all the messages in your Email Inbox folder and drops theBackdoor.Sdbot Trojan into the infected system. This worm also attempts to spread itselfthrough the KaZaA file-sharing network.
Symptoms:
Copies itself as: %Windir%svchost.exe and %Windir%Servicessetup.exe where %Windir% is the default installation directory. Creates a file, %Windir%Servicesindex.html. This file is not viral by itself. Therefore, manually delete this file if your computer is infected with this worm. Adds the value: svchost %Windir%svchost.exe to the registry keys: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun and HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun so that the worm runs when you start Windows. May create a subfolder, %Windir%explorer, and copies itself as the following if you have KaZaA installed: Command & Conquer Generals.exe, Command & Conquer Generals Crack.exe, Gods & Generals.exe, Gods & Generals Crack.exe, The Sims 4.exe, The Sims 4 Crack.exe, Splinter Cell.exe, Splinter Cell Crack.exe, Raven Shield - Crack.exe, Raven Shield Keygenerator - WORKS ONLINE.exe, Mortal Kombat - Deadly Alliance.exe, GTA 4 - BETA.exe. Unreal 2 Crack.exe, Unreal 2 - The Awakening.exe and Warcraft III - The Frozen Throne.exe Adds the values: WinSyst32 winsyst32.exe to the registry keys: HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRun HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunServices HKEY_LOCAL_MACHINESoftwareMicrosoftWindowsCurrentVersionRunOnce HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRun HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunOnce Adds the following values if you have KaZaA installed: Dir0 012345C:%Windir%explorerDisableSharing 0 to the registry key: HKEY_CURRENT_USERSoftwareKaZaALocalcontent so that other KaZaA users can download the worm from the folder, %Windir%explorer. Decreases the security level of the KaZaA file-sharing software (if you have KaZaA installed), by adding or modifying the following values: ScanFolder 0x00000001 in the registry key: HKEY_CURRENT_USERSoftwareKaZaAAdvanced and AutoConnected 0x00000001 in the registry key: HKEY_CURRENT_USERSoftwareKaZaAUserDetails and Virus_filter 0x00000000 in the registry key: HKEY_CURRENT_USERSoftwareKaZaAResultsFilter
Recommended Cleanup Software:
We found that
Easy SpyRemover
is the most effective tool for removing this file.
Manual Removal Instructions:
Update the virus definitions.
Restart the computer in Safe mode.
Run a full system scan and delete all the files detected asW32.HLLW.Morb@mm or Backdoor.Sdbot.
Delete the values that the worm adds to the registry.
© Copyright 2004, TaskList.org. All rights reserved. Portions copyright by
Paul Collins
(Pacs Portal).
Disclaimer
.
Links