Skip to main content
Skip to main content
Microsoft Security Intelligence
1047 entries found. Displaying page 1 of 53.
Updated on Nov 27, 2005
Windows Defender Antivirus detects and removes this threat.
 
Win32/Bofra is a mass-mailing worm that can infect computers running Microsoft Windows. The worm creates a Web server on the infected computer. It sends a copy of itself to any user who connects to the server and requests a URL containing a certain string. The worm also connects to an IRC server to receive commands from attackers. Win32/Bofra terminates immediately if the system time is after December 15, 2004, 02:28:57.
Alert level: severe
Updated on Sep 07, 2007
Storm Worm, or Win32/Nuwar, refers to a family of Trojan droppers that install a distributed peer-to-peer (P2P) downloader Trojan. This downloader Trojan in turn downloads a copy of the email worm component of Storm Worm.
Alert level: high
Updated on Sep 05, 2007
Backdoor:Win32/Nuwar.A is a backdoor Trojan that allows unauthorized access to an infected computer. The Trojan receives commands indirectly from a remote attacker via its connection to a malicious peer-to-peer network. This Trojan also contains advanced stealth functionality that allows it to hide particular files, registry entries and registry values.
Alert level: severe
Updated on Sep 07, 2007
Win32/Nuwar refers to a family of Trojan droppers that install a distributed peer-to-peer (P2P) downloader Trojan. This downloader Trojan in turn downloads a copy of the email worm component of Win32/Nuwar.
Alert level: high
Updated on May 21, 2007
Worm:Win32/Culler.D is an instant messaging worm that spreads by sending links to copies of itself via MSN Messenger. Worm:Win32/Culler.D continually terminates processes related to Task Manager, Registry Editor and System Restore.
Alert level: severe
Updated on Apr 03, 2008
Worm:Win32/VB.CD is a worm that spreads to removable drives, modifies system settings and may delete files.
Alert level: severe
Updated on Jan 19, 2005
Win32/Korgo is a family of worms that spread by exploiting vulnerabilities in certain versions of Microsoft Windows that do not have Microsoft Security Bulletin MS04-011 installed. Some variants of this worm open a backdoor component to gain unauthorized access to other computers.
Alert level: severe
Updated on Dec 08, 2006

Windows Defender detects and removes this threat.

It is a mass-mailing worm that sends a copy of itself as an email attachment to your email contacts. It attempts to download files, including other malware, to your computer.

It also spreads by copying itself to removable drives such as USB sticks.

Alert level: severe
Updated on Oct 26, 2007
Worm:Win32/RJump.F is a worm that attempts to spread by copying itself to local, removable and network drives. It also contains functionality that allows an attacker to download and execute arbitrary files, including additional malicious software, on the user’s machine.
Alert level: severe
Updated on Feb 20, 2008
Worm:Win32/Wukill.J@mm is a mass-mailing e-mail worm that also spreads by copying itself to drives A:, C:, D:, E:, G: and H:. This worm may also disable viewing of file extensions and paths in Windows Explorer.
Alert level: severe
Updated on Mar 04, 2008
Worm:Win32/Brontok.AR@mm is detection for a group of variants of the Win32/Brontok worm family.
 
This worm spreads by sending a copy of itself as an e-mail attachment to e-mail addresses that it gathers from files on the infected computer. It can also copy itself to USB and pen drives. Win32/Brontok can disable antivirus and security software, immediately terminate certain applications, and cause Windows to restart immediately when certain applications run. The worm may also conduct denial of service (DoS) attacks against certain Web sites.
Alert level: severe
Updated on Apr 25, 2008
Worm:Win32/Autorun.BO is a worm that may drop a backdoor trojan (identified as Backdoor:Win32/Bifrose.gen!A) and connect with remote Web sites.
Alert level: severe
Updated on May 14, 2008
Worm:Win32/Brontok.AB@mm is a worm that spreads via e-mail and removable drives. The worm spreads by sending a copy of itself as an e-mail attachment to e-mail addresses that it gathers from files on the infected computer. It can also copy itself to USB and pen drives. Win32/Brontok can disable antivirus and security software, immediately terminate certain applications, and cause Windows to restart immediately when certain applications run. The worm may also conduct Denial of Service (DoS) attacks against certain web sites.
Alert level: severe
Updated on May 16, 2008
TrojanSpy:Win32/VBStat.AD is dropped as a component of Worm:Win32/RJump.F. Its purpose is to execute Win32/RJump.F at each Windows start.
Alert level: severe
Updated on Jun 23, 2005
Worm:Win32/Swen.A@mm is a network and mass-mailing worm that targets certain versions of Microsoft Windows. The worm spreads in several ways and terminates security-related processes running on an infected computer. Win32/Swen masquerades as a patch for Microsoft Internet Explorer, and may pretend to download and install software.
Alert level: severe
Updated on Sep 21, 2005
Win32/Mywife is a family of mass-mailing network worms that targets certain versions of Microsoft Windows. The worm spreads through e-mail attachments and writeable network shares.
Alert level: severe
Updated on Jan 05, 2005
Windows Defender Antivirus detects and removes this threat.
 
Win32/Zafi is a family of mass-mailing worms. The worm sends itself to email addresses that it finds on the infected PC.
 
It may terminate processes that relate to system utilities and security products. It may change security-related registry key values. Some variants also copy the worm to network-share folders.
Alert level: severe
Updated on Sep 09, 2005
Win32/Gael is a parasitic virus that targets certain versions of Microsoft Windows. The virus infects Win32 PE .exe files locally and on writeable network shares. The virus can also download TrojanDownloader:Win32/Small from a Web site and run the file.
Alert level: high
Updated on Feb 27, 2008
Worm:Win32/Bagz.D@mm is a worm that sends e-mails to gathered e-mail addresses, with an attached copy of itself. Win32/Bagz may also block access to certain Web sites and delete services.
Alert level: severe
Updated on Dec 07, 2006
Worm:Win32/Roron.AA@mm is a worm that attempts to send personal information to a remote address. It may spread via e-mail, network shares, or peer-to-peer file sharing.
Alert level: severe