W32.Korgo.E
Aliases: WORM_KORGO.E
Port: 113, 3067, 6667
Size: 17kb
Created: JUN 2004
OS: Windows
Location: HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\Software\Microsoft\Wireless\
Infection: avserve.exe, avserve2.exe
Wall
Created: NOV 1994
OS: Windows
Location: TBD
Wallpaper Killer
Created: APR 2001
OS: Windows
Location: TBD
WAN Remote
Created: MAR 2000
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Wanadoo
Created: SEP 2002
OS: Windows
Location: TBD
War
Created: JUL 1999
OS: Windows
Location: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
War Factory
Created: MAY 1999
OS: Windows
Location: TBD
WarDoor
Created: APR 2002
OS: Windows
Location: TBD
Warfair
Created: NOV 2000
OS: Windows
Location: TBD
WarpCom
Created: OCT 1990
OS: Windows
Location: TBD
Wassup TF
Created: JUL 2002
OS: Windows
Location: TBD
Waster.c
Created: SEP 1997
OS: Windows
Location: TBD
Watcheador
Created: MAY 2000
OS: Windows
Location: TBD
Watching
Created: APR 2004
OS: Windows
Location: TBD
WaveWash
Created: DEC 1993
OS: Windows
Location: TBD
Way
Created: MAY 2001
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
Way 2002
Created: OCT 2002
OS: Windows
Location: TBD
WC RAT
Created: DEC 1999
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Web Asylum
Created: SEP 2001
OS: Windows
Location: TBD
Web Cache
Created: SEP 2001
OS: Windows
Location: TBD
Web Downloader
Created: JUL 2000
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WebEx
Created: JAN 1999
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Web Remote
Created: FEB 2002
OS: Windows
Location: TBD
Web Server
Created: APR 2005
OS: Windows
Location: TBD
Web Server CT
Created: AUG 2000
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
Web Server Lite
Created: JUN 2002
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Web Server Matrix
Created: JUN 2002
OS: Windows
Location: TBD
WebCam
Created: APR 2002
OS: Windows
Location: TBD
WebCamNow Jacker
Created: JUN 2003
OS: Windows
Location: TBD
WebCompiler
Created: JUL 2002
OS: Windows
Location: TBD
WebHead
Created: APR 2001
OS: Windows
Location: TBD
WebRSH
Created: MAY 1998
OS: Windows
Location: TBD
Webs
Created: APR 1996
OS: Windows
Location: TBD
Websters
Created: MAR 2004
OS: Windows
Location: TBD
Weia-Meia
Created: DEC 2000
OS: Windows
Location: TBD
Welcome
Created: FEB 1996
OS: Windows
Location: TBD
WGateScan
Created: FEB
OS: Windows
Location: TBD
Wh-CrewSpy
Created: JUL 2001
OS: Windows
Location: TBD
Whale
Created: APR 2001
OS: Windows
Location: TBD
What are you doing?
Created: AUG 2002
OS: Windows
Location: TBD
Whirlpool
Created: SEP 2002
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Whomp
Created: JUN 2002
OS: Windows
Location: TBD
WIC
Created: DEC 2000
OS: Windows
Location: TBD
Wicked Bot
Created: MAR 2001
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Wild Thing
Created: AUG 2003
OS: Windows
Location: TBD
Wildek
Created: JAN 2002
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
Win32.Stwoyle.B
Aliases: Downloader-ABZ, Win32/Stwoyle!generic, Trojan-Downloader.Win32.Delf.pa
Size: 14kb
Created: AUG 2005
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2\DLLName\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2\lock\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2\logoff\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2\logon\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2\shutdown\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2\startscreensaver\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2\startshell\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2\startup\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2\stopscreensaver\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\style2\unlock\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler\
Infection: winstyle3.dll, regsvr32.exe
Win32.Zlob.A
Aliases: Win32/Agent.BU.Downloader.Trojan, W32/Agent.BU@dl, StartPage-EH, Trojan.StartPage, TrojanDownloader.Win32.Agent.bh
Created: NOV 2004
OS: Windows
Location: HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\ HKLM\SOFTWARE\Policies\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ranges\ HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost\netsvcs\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\DNSCache\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\DNSCache\ HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\pnpsvc\(Default)\ HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\pnpsvc\(Default)\ HKLM\SYSTEM\CurrentControlSet\Services\Pnpsvc\Start\ HKLM\SYSTEM\CurrentControlSet\Services\Pnpsvc\Type\ HKLM\SYSTEM\CurrentControlSet\Services\Pnpsvc\Errorcontrol\ HKLM\SYSTEM\CurrentControlSet\Services\Pnpsvc\ImagePath\ HKLM\SYSTEM\CurrentControlSet\Services\Pnpsvc\ObjectName\ HKLM\SYSTEM\CurrentControlSet\Services\Pnpsvc\Description\ HKLM\SYSTEM\CurrentControlSet\Services\Pnpsvc\DisplayName\ HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Pnpsvc\EventMessageFile\ HKLM\SYSTEM\CurrentControlSet\Services\EventLog\Application\Pnpsvc\TypesSupported\ HKLM\SYSTEM\CurrentControlSet\Services\Pnpsvc\Parameters\ServiceDll\
Win32/FakeAlert.KL
Aliases: Trojan:Win32/FakePowav, Downloader.MisleadApp
Created: NOV 2008
OS: Windows
Location: HKCU\Software\Microsoft\Internet Explorer\Main\Search Bar\ HKCU\Software\Microsoft\Internet Explorer\Main\Search Page\ HKCU\Software\Microsoft\Internet Explorer\Main\Start Page\ HKCU\Software\Microsoft\Security Center\AntiVirusDisableNotify\ HKCU\Software\Microsoft\Security Center\FirewallDisableNotify\ HKCU\Software\Microsoft\Security Center\UpdatesDisableNotify\ HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Default_Search_URL\ HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Search Page\ HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page\ HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\SearchAssistant\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1201\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1804\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\1201\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1\2500\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2\1201\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1201\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\1208\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3\2500\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1200\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1201\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1608\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1804\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\1208\ HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4\2500\ HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\EnableFirewall\
Infection: brastk.exe, Installer.exe, wini1088x.exe
Win32/Karwnlam.E
Aliases: Trojan:Win32/Laqma.B
Created: JUL 2008
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ HKLM\SYSTEM\CurrentControlSet\Services\lanmandrv\Type\ HKLM\SYSTEM\CurrentControlSet\Services\lanmandrv\Start\ HKLM\SYSTEM\CurrentControlSet\Services\lanmandrv\ErrorControl\ HKLM\SYSTEM\CurrentControlSet\Services\lanmandrv\ImagePath\ HKLM\SYSTEM\CurrentControlSet\Services\lanmandrv\DisplayName\ HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LANMANDRV\ HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LANMANDRV\0000\Service\ HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LANMANDRV\0000\Service\Legacy\ HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LANMANDRV\0000\Service\ConfigFlags\ HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LANMANDRV\0000\Service\Class\ HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LANMANDRV\0000\Service\ClassGUID\ HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_LANMANDRV\0000\Service\DeviceDesc\
Infection: lanmanwrk.exe, qmopt.dll, lanmandrv.sys
Winallap
Created: MAY 1999
OS: Windows
Location: TBD
Winbach
Created: APR 2005
OS: Windows
Location: TBD
WinBoot
Created: JAN 2001
OS: Windows
Location: TBD
WinCom
Created: OCT 2002
OS: Windows
Location: TBD
WinControl
Created: AUG 1998
OS: Windows
Location: TBD
WinCrash
Created: JAN 1999
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WinCrosser
Created: DEC 2003
OS: Windows
Location: TBD
Wind Prank
Created: JUN 2002
OS: Windows
Location: TBD
Windows AnonIRC
Created: JUN 1999
OS: Windows
Location: TBD
Windows Mite
Created: JUL 2000
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Windows Remote Registry
Created: JAN 2003
OS: Windows
Location: TBD
Windows Remote Shell
Created: SEP 2001
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
Windows Total Controller
Created: APR 2003
OS: Windows
Location: TBD
Windows Washer
Created: FEB 2001
OS: Windows
Location: TBD
WinEggDrop Shell
Created: DEC 2002
OS: Windows
Location: TBD
WinFiles
Created: APR 2005
OS: Windows
Location: TBD
WinFucker
Created: FEB 2000
OS: Windows
Location: TBD
WingKill
Created: AUG 1999
OS: Windows
Location: TBD
WinGrab
Created: FEB 2000
OS: Windows
Location: TBD
Wini
Created: JUN 2002
OS: Windows
Location: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
WinINF DelReg
Created: NOV 2003
OS: Windows
Location: TBD
Winker
Created: APR 2005
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WinLL
Created: DEC 1995
OS: Windows
Location: TBD
WinLog
Created: JUN 2003
OS: Windows
Location: TBD
Winmgts
Created: AUG 2003
OS: Windows
Location: TBD
Winny
Created: DEC 2002
OS: Windows
Location: TBD
WinParkin
Created: FEB 2000
OS: Windows
Location: TBD
WinPC
Created: FEB 1999
OS: Windows
Location: DNR
WinPhreak
Created: JAN 1995
OS: Windows
Location: TBD
WinProtector
Created: JAN 2001
OS: Windows
Location: TBD
WinRAT
Created: JAN 2002
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WinRemoteShell
Created: APR 2005
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WinSatan
Created: MAY 1999
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WinShadow
Created: JUL 2002
OS: Windows
Location: TBD
WinShell
Created: OCT 2001
OS: Windows
Location: TBD
WinSpy
Created: JUL 2003
OS: Windows
Location: TBD
WinStart
Created: AUG 1995
OS: Windows
Location: TBD
WinTheKill
Created: APR 2005
OS: Windows
Location: TBD
WinTrix
Created: OCT 2001
OS: Windows
Location: TBD
Wintro
Created: NOV 2003
OS: Windows
Location: TBD
WinZapper
Created: SEP 2000
OS: Windows
Location: TBD
Wipe
Created: AUG 2001
OS: Windows
Location: TBD
Wipe the Fucker’s HD
Created: MAR 1995
OS: Windows
Location: TBD
WipeDisk
Created: APR 2004
OS: Windows
Location: TBD
Witch Control
Created: APR 2004
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WLF
Created: FEB 2001
OS: Windows
Location: TBD
WM Chat System
Created: NOV 2001
OS: Windows
Location: TBD
WM Remote Keylogger
Created: JAN 1998
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WM FTP
Created: TBD
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WMFA
Created: JAN 2002
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
WolfCheat
Created: APR 2004
OS: Windows
Location: TBD
Wollf Remote Manager
Created: DEC 2001
OS: Windows
Location: HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
Wooden Ox
Created: APR 2005
OS: Windows
Location: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
Woot
Created: AUG 2001
OS: Windows
Location: TBD
WowHack
Created:
OS: Windows
Location: HKCU\Software\Microsoft\Windows\CurrentVersion\Run\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices\
Wpkr
Created: MAY 2002
OS: Windows
Location: TBD
WriteFile
Created: FEB 1998
OS: Windows
Location: TBD
Infection: writef~1.cab
WTF Voice Stealer
Created: OCT 2002
OS: Windows
Location: TBD
Wu-FTPD
Created: FEB 2000
OS: Windows
Location: TBD
Wukaz
Created: APR 2005
OS: Windows
Location: TBD
WUPC
Aliases: “Web is Under Parental Control”
Author: ALSEDI Group
Created: JUN 2006
OS: Windows
Location: HKLM\software\alsedi\pguard\ HKLM\software\microsoft\windows\currentversion\uninstall\wupc\
Infection: uninstall.exe, alsediwebcontrol.exe, license.txt, 1.gif, 1.html, 2.html, 3.gif, 3.html, 4.gif, 4.html, 5.gif, 5.html, 6.html, main.css, n1.gif, n2.gif, wupc4.exe, uninstall.lnk, wupc.lnk, uninstall.exe, wupc4.exe, alsediwebcontrol.exe
WWW PW
Created: MAY 2000
OS: Windows
Location: TBD
WWW Count
Created: MAR 1999
OS: Windows
Location: TBD



