tasklist.org
A comprehensive list of processes running in your computer
tasklist
|
attachlist
bookmark this website!
total tasks: 16297
AttachList is a list of email attachment files that viruses usually send in email. It contains the attached file names, typical subjects and messages, the name of the viruses that send them, and instruction on how to remove these viruses.
search
most requested
ISUSPM.exe
ctfmon.exe
svchost.exe
AresLite.exe
alg.exe
gcasDtServ.exe
csrss.exe
ccApp.exe
jusched.exe
csrss.exe
Browse
attach
list
by file name
:
|
a
|
b
|
c
|
d
|
e
|
f
|
g
|
h
|
i
|
j
|
k
|
l
|
m
|
n
|
o
|
p
|
q
|
r
|
s
|
t
|
u
|
v
|
w
|
x
|
y
|
z
|
Name:
W32.Noomy
Sender:
Varies.
Subject:
Bad Request Server not found! Don't spam!!!!! Extended Mail System ERROR: I call spam POLICE! STOP!!! ID: New eCard in your inbox! ID: You got one VoiceMail! See online! Information!You spam this email: irc.afternet.org Last chance!STOP SPAM THIS EMAIL: Last notice! Regard ! Please read... Mail Delivery (error Num: One new eCard from Num: One new VoiceMail from One new eCard! ID: One new VoiceMail! ID: Protected Mail Server invalid! Question about YOUR SPAM!! Re: Mail System Error - Returned Mail Re: Bad Request Server not found! Re: eCard Delivery Error: Re: Mail Delivery Error! Re: Mail Delivery: - Error Re: MAIL Error num: - Returned mail: see transcript for details Re: Message Error! mail: Re: VoiceMail to - Delivery Error This is not OK ! Warning!!! Why you SPAM? You`ve got 1 new eCard!
Message:
Dear Customer!You`ve got 1 eCard VoiceMessage from ecards.com website!You can listen your Virtual VoiceMessage at the following link:http:/ /see.ecards.com/or by clicking the attached link:Send eCard VoiceMessage! Try our new eCard VoiceMessage Empire!Best regards: eCard.com Team (R). Dear Sir,According to our cognitions you have done next:The emails are still arriving...Stop to doing that,i call Spam Police!actually you have been buring our network and our right is to protect our users.Accourding to that you have been informed about this by phone by our System engineer,with this letter we want to point you to next facts:1) Your personal account is not restricted in any way and our right is to protect our users and servers;2) Serverhas been shuted down beacouse large amount of emails that have beenarricing to our servers and beacouse of adequacy suspicion that it is a spam ramp.3) Unsubscribing system is not functioning!On unsubscribing attempt result is next:According to part 10 of Personal servie terms of use we are authorized to warn you about this.As an evidence we have a LOG file fromour server that is clearly showing date and time when youI send you LOG File , to see your IP Adress!have been sending spam emails, your IP address and your username!Please accept this warnning about sending informations to users and wrongly interpret our actions taken in your case as seriously as possible.If you don't accept this warning we will be forced to refer to our lawyers so we could protect our company intersts.If you don't understand anything in this email, please contact us via email or by phone for aditional explanations.According to computer criminal law of USA, act 168v, act you have done is judget tojail (1-8 years).Best regards,Office Manager Dear User!You have one new eCard Pic to your inbox at eCard.comLogin ID:You can see your eCard at the following link:https:/ /pics.ecard.com/Or by clicking the attached link:Thank you Delivery Failed ! Error:The original message was included as attachment----- The following addresses had permanent fatal errors -----DATA or400-aturner; %MAIL-E-OPENOUT, error opening !AS as output--- From Server:MAILTo:400-aturner; -RMS-E-CRE, ACP file create failed400-aturner; -SYSTEM-F-EXDISKQUOTA, disk quota exceeded400--- Attachment:---Attachment: No Virus foundKaspersky AntiVirus - www.kaspersky.com One new Voice Message for you!From:Can see online: http:/ /voice.ecard.com/or by clicking the attached link:Test our new service! Send you one voice message http://voice.ecards.comBest regards: eCard.com Team (R). Your message [was not or could not be] delivered because the destination''wasreachable within the allowed queue period. The amount of timeFrom:a message is queued before it is returned depends on local configuration parameters.---------------it is also possible that the computer is turned off, or does not have a mail system running right now.Your message [was not or could not be] delivered within 3 days.is not responding.Please reply to postmaster!400 if you feel this message to be in error.Automatic message from:
Attachment:
-hotmail.exe -hotmail.pif -hotmail.scr -mailmail.exe -mailmail.pif -mailmail.scr -servise.error.exe -servise.error.pif -servise.error.scr -www.aol.abuse.co.com -www.aol.com -www.nic.uk.com -www.police.spam.com -www.pttusa.com -www.scg.net.com -www.telekom.com -www.usaeunet.com -www.usapolice.com -www.webhosting.com Dde.view.exe Dde.view.pif Dde.view.scr e-mail.exe e-mail.pif e-mail.scr ecardID.ecards.com Error.MSG.exe Error.MSG.pif Error.MSG.scr FdfsECcdsaA.error.exe FdfsECcdsaA.error.pif FdfsECcdsaA.error.scr file.logs..exe file.logs..pif file.logs..scr file.URL.view.fDEd.exe file.URL.view.fDEd.pif file.URL.view.fDEd.scr Index.php.sEeeDSAD.not.found.exe Index.php.sEeeDSAD.not.found.pif Index.php.sEeeDSAD.not.found.scr link.index.php.seeHere.exe link.index.php.seeHere.pif link.index.php.seeHere.scr LIVE.show.URL.see.phpAsVEd.exe LIVE.show.URL.see.phpAsVEd.pif LIVE.show.URL.see.phpAsVEd.scr log.file.exe log.file.pif log.file.scr logs.exe logs.pif logs.scr mail.exe mail.log..exe mail.log..pif mail.log..scr mail.pif mail.scr msg.exe msg.pif msg.scr Nude.only.viewDFereS.exe Nude.only.viewDFereS.pif Nude.only.viewDFereS.scr online.ecard.com onlineSee.cards.com pics.ecards.com pics.online.see.com private.mail.error2222442.exe private.mail.error2222442.pif private.mail.error2222442.scr secpics.ecards.com secure.ecards.com see.ecards.com Sending.www.ecards.com smtp.serverLog.exe smtp.serverLog.pif smtp.serverLog.scr unsent.mail.exe unsent.mail.pif unsent.mail.scr URL.ecard.php.SSEcxcsd.exe URL.ecard.php.SSEcxcsd.pif URL.ecard.php.SSEcxcsd.scr URL.Picture.php.Seeonline.exe URL.Picture.php.Seeonline.pif URL.Picture.php.Seeonline.scr vk.Only.error.found.exe vk.Only.error.found.pif vk.Only.error.found.scr voice.ecards.com yahoo.exe yahoo.pif yahoo.scr
Comments:
A worm that sends itself by email, creates an HTTP server on port 8800/TCP and sendsmessages to IRC chat rooms inviting users to download the worm from the HTTP server
Symptoms:
Drops the following files in the directory from where the threat was executed: ReAd_ThiS_ShiT.txt StpLogs.vbs Adds the value: "Windows HTML file reader "="%Windir%Sysconf32.exe" to the registry key: HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRun so that the worm runs when you start Windows. Creates the folder %System%SystemBck and copies itself to that folder with the following file names: 1001nesroms.exe adness2.exe Ageofempires2crack.exe AgeOfMythologyISO.exe AliciaSilverstonePayboyNude.scr AnaKurnikovaVirualGirl2004.scr AngelinaRealScreenSaver.scr AquaNox2crack.exe AVPCrackNEW.exe Battlefield1942Bloodpatch.exe Battlefield1942bloodpatch.exe BattlenetkeygeneratorWORKS.exe Bingo.exe BritneySpearsDanceBeat.scr BritneyspearsNude.scr Burnout2CarRacing.exe Cablemodemuncapper.exe CloneCDallversionskeygenerator.exe CloneCDcrack.exe Copyprotectionremover.exe counterstrikeaim_bot.exe CounterStrikeHLDSv1.1.0.9.exe counterstrikemaphack.exe counterstrikerkeygen2004.exe Crazytaxicrack.exe CuteFTPPro30.exe DDosClient2005.exe deadaim4.0.exe deadaim4.0serial.exe DivXcodecv6.0.exe DivXnewestversion.exe DivXpatch-Increasesquality.exe DivXprokeygenerator.exe Doom3Beta.exe DragonballZCOMPLETEepisodeguide.exe DragonballZepisode1.exe DragonballZshootout.exe DVDCoppierv1.5.7byCrash2004.exe DVDRipperv1.3.2byCrash2004.exe EmailBomber447.exe EvidenceEraserbyCrash2004.exe FIFA2004crack.exe FileServer.exe FlashGolf.exe FreeMpegsLists.pif FreePicsList.pif FreePornLists.pif FunnyBush2004movieSeptember.scr GamecubeEmulatorWORKS.exe Generalscrack.exe GrandPrix4crack.exe Grandtheftauto3CD1crack.exe GTA3crack.exe Hackintoanycomputer.exe Half-lifeONLINEkeygenerator.exe Half-lifeWONkeygenerator.exe HoesForYouSolitare.exe iWormMymoonremovetool2.5.exe J-LONudeREAL.scr J.LoBikiniScreensaver.scr JediKnight2crack.exe JennaJamisonDildoHumping.scr KamaSutraTetris.exe KazaaClone.exe KaZaAhack.exe KaZaAmediadesktopv2.0UNOFFICIAL.exe KaZaAspywareremover.exe KeygeneratorforallwindowsXPversions.exe Keygeneratorforoverreally.exe McAffeeUtilitiesv3.11byR2P2K.exe McAffeeUtilitiesv3.11FinalbyR2P2K.exe Mirc7.0Crack.exe N0RT0NANTIVIRUS2004.exe NapsterClone.exe NBA2004crack.exe NeroBurningROMv5.5.8.2byCooKie.exe NeroBurningROMv5.5.8.2Keygen.exe NeroBurningROMv5.5.8.2Serial.exe Neverwinternightscrack.exe Nokiasimlockremoverincludesnewmodels.exe Nortonantivirus2002.exe PlayGamesOnlineForFREE.exe Ps2Emulator.exe Ps2Iso2RomConverter.exe Rayman2Full.exe ResidentEvilDivX.exe ShakiraDancing.scr SoldierOfFortune2MutiplayerSerialHack.exe SpyAgentRemoteControl1.05.exe SpyCamv6.32.exe SpyTechSpyAgentPersonalv3.00.00byAmoK.exe StarCraftBroodWarv1.09byFR.exe Starwarsepisode2downloader.exe SystemMonitor.exe TheSimsGameCrack.exe TotalImmersionRacingISO.exe UniversalGameCrack.exe Unreal2bloodpatch.exe UnrealTournament2004Bloodpatch.exe UnrealTournament2bloodpatch.exe UT2003bloodpatch.exe Warcraft3Battle.netCrack.exe Warcraft3battlenetserialgenerator.exe warcraft3keygen.exe Warcraft3ONLINEkeygenerator.exe WinAPs2.exe Windows2004Keygen.exe WindowsXPKeyGen.exe windowsxpkeygen.exe WindowsXPkeygenerator.exe WindowsXPserialgenerator.exe WindowsXPSP1key-Crack.exe Winrarandcrack.exe Winzip80serial.exe WorkingIsoBurner.exe XboxEmulator.exe XBOXemulatorWORKS.exe Xboxinfo.exe XboxIso2RomConverter.exe YahooPasswordHacker2004BF.exe ZoneAlarmProv3.0.2.6byOrion.exe zoneallarmprocrack2004.exe
Recommended Cleanup Software:
We found that
Easy SpyRemover
is the most effective tool for removing this file.
Manual Removal Instructions:
none
© Copyright 2004, TaskList.org. All rights reserved. Portions copyright by
Paul Collins
(Pacs Portal).
Disclaimer
.
Links