Can anyone please google what this virus does? (im capped)

boramk

Bammed
Joined
Mar 17, 2007
Messages
9,957
Reaction score
338
Location
Chicago
win32.p2p (ok, i thought my ant-virus would save the name but it didn't, it was either this or win.32p2p)

it seems to have no effect on XP pc's but completly ruins Windows 2000, costing my parents 1000's.

thanks
 
Win32/P2P.SpyBot.Wuaumqr.Worm is one of Backdoor spywares.
Finding it on your computer means that your computer is infected with Backdoor and crucial data could be endangered or even lost.
This Backdoor is also known as:
•Backdoor.Spyboter.gen - named by Kaspersky.
• W32/Spybot - named by Panda.
• Win32.Spybot.FQ - named by Computer Associates.
• Win32/SpyBot.DP worm - named by Eset.
• Win32/SpyBot.Wuaumqr!P2P!Worm - named by Computer Associates.

Seems to be spyware, I'll see if I can find anything else.
 
Sdbot

Last Update: 2004-10-01 05:28
Risk Rating: Very Low Risk
Very Low Risk
Aliases: Backdoor.IRC.SdBot
Backdoor.Sdbot
Backdoor.SdBot.gen
Backdoor/Sdbot
Backdoor_SdBot
BKDR_RAMDAM.A
BKDR_SDBOT.B
IRC-Sdbot
SdBot
Troj/Sdbot-B
W32.Kwbot.F.Worm
W32.Kwbot.Worm
W32/KWBot-E
W32/Randbot.worm
W32/Sdbot-GS
W32/Sddrop-B
W32/Sddrop-D
W32/Sddrop.worm.d!p2p
W32/Sddrop.worm.g
Win32.Sdbot
Win32.SdBot.14176
Win32.Sddrop.B
Win32.Sddrop.C
Win32.Sddrop.D
Win32/P2P.SdDrop.d.Worm
Worm.P2P.SdDrop.b
Worm.P2P.SdDrop.c
Worm.P2P.SdDrop.d
WORM_SDDROP.A
WORM_SDDROP.C
WORM_XMS.A
Information From AntiVirus Vendors


Below you will find virus information from different antivirus vendors included in this Secunia Virus Profile. Information about the virus along with links to removal tools will be listed below when available.

The information provided is sorted by the date on which the information first became publicy available on the antivirus vendors' websites. The earliest available reports are displayed first. Please note timestamps are in GMT+1.





#1 - SYMANTEC

W32.Kwbot.F.Worm
Severity:
2/5 File Size:
25,088 bytes + appended bytes
Reported:
- Last Update:
-
Description:
The W32.Kwbot.F.Worm is:
Full Report From Vendor


#2 - SYMANTEC

Backdoor.Sdbot
Severity:
2/5 File Size:
-
Reported:
- Last Update:
2004-10-01 04:23
Description:
Backdoor.Sdbot is a Backdoor Trojan horse that allows the Trojan's creator to control a computer by using Internet Relay Chat (IRC). Backdoor.Sdbot can update itself by checking for newer versions over the Internet.
Full Report From Vendor View/Hide ChangeLog

ChangeLog:

Changes are listed in chronological order with the latest changes first.


2004-09-01 04:21 Description was changed.

New:
"Backdoor.Sdbot is a Backdoor Trojan horse
that allows the Trojan's creator to control a
computer by using Internet Relay Chat (IRC).
Backdoor.Sdbot can update itself by checking
for newer versions over the Internet."

Old:
"Backdoor.Sdbot is a Backdoor Trojan Horse
that allows the Trojan's creator to control a
computer by using Internet Relay Chat (IRC).
Backdoor.Sdbot can update itself by checking
for newer versions over the Internet."


#3 - COMPUTER ASSOCIATES

Win32.Sddrop.D
Severity:
2/5 File Size:
-
Reported:
2004-09-09 09:37 Last Update:
-
Description:
Win32.Sddrop.D ia a worm that spreads via Peer-to-Peer file sharing networks and acts as an IRC-controlled backdoor that allows unauthorized access to an affected machine. When Win32.Sddrop.D is executed, it copies itself to %System%\xms32.exe (size: 30,000 bytes, compressed with ASPack) marked as 'hidden'.
Full Report From Vendor

...
 
And some more:

Win32.P2P.Lorrin.A@mm
( I-Worm.Mapson (KAV), W32/Mapson-A (Sophos) )
Raspandire : HIGH
Dauna : LOW
Size: 180736 bytes (packed with UPX 1.24)
Descoperit : 2005 May 31

SYMPTOMS:
# Presence of one or more of the next files in Windows System folder (%SYSTEM%, e.g. C:\\Windows\\System32 for a Windows 9x/XP):

amigos.pif
amigototote.pif
amor-por-ti.pif
antiwinlogon.pif
antrox.scr
BigBrother.pif
bugmsn.pif
chistesgraficos.pif
chupamelo.pif
comotegustan.pif
CracksPPZ.pif
cristina-aguilera.pif
defaced-madonna-site.pif
eggbrother.exe
EICAX.COM
existeee.pif
financiamiento.pif
GEDZAC.PIF
grancarnal.exe
grande.pif
hackeahotmail.pif
historial.pif
hotmail.pif
kamasutra.pif
[email protected]
LatinCard.pif
linuxandmicrosoft.pif
Lorenaaaa.pif
Madonna_sEXY.pif
MariaVirgen.pif
Matrix-Trailer.pif
mujeres.pif
Musica.pif
No-Spam.exe
nuevovirus.txt.pif
Oradores.pif
osamabinhuevoback.exe
parejaideal.txt.pif
petardas.pif
porqueteamo.pif
projimo.pif
relacionsexual.pif
resetarios.pif
SARS.pif
seguridad_en_hotmail.pif
serhacker.pif
Shakira.pif
solo-a-ti.pif
Spamno.pif
teamo.exe
te-pido.scr
test-idiota.pif
testpasion.pif
thalialoca.pif
TutorialVBSvirus.pif
WindowsMediaPlayerBug.pif
www.mfernanda.com
www.vsantiviru.com
www.zonaviru.com
zorrotttas.pif

These file names are also used for attachments when spreading via mail.

Presence of one of the names mentioned above in the process list (visible in Task Manager).

# Presence of registry key:
[HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Lorraine = %SYSTEM%\\Lorraine.exe]

TECHNICAL DESCRIPTION:
The worm spreads itself via email, attached as mentioned before and also by sharing itself through the most common P2P programs as follows:

eDonkey 2000
Gnucleus
ICQ
KaZaA
LimeWire
Morpheus
Grokster

It copies itself in listed below folders:

\\edonkey2000\\incoming\\
\\gnucleus\\downloads\\
\\icq\\shared files\\
\\KaZaA\\My Shared Folder\\
\\kazaa lite\\my shared folders\\
\\limewire\\shared\\
\\morpheus\\my shared folder\\
\\Grokster\\My Grokster\\

with different combinations of the following names (all names generated end with .EXE):

Desnuda en la playa
las pelotas de
Nude Pic
Sexo en la playa con
Sexy Beach
Sexy Bikini
Alejandra Guzman
Angelica Vale
Brenda
Britney Spears
Cameron dias
Celine Dion
Francini
Galilea Montijo
Halle berry
Kylie Minogue
Laura Pausini
Lili Brillanti
Lorena
Paulina Rubio
Pink
Shakira
Thalia
Ad-aware
Adobe Acrobat Reader (32-bit)
AOL Instant Messenger (AIM)
Biromsoft WebCam
Copernic Agent
Delphi 6
Diet Kaza
DirectDVD
DivX Video Bundle
Download Accelerator Plus
FireWorks 4
FIreWorks MX
Global DiVX Player
Grokster
ICQ Lite
ICQ Pro 2003a beta
iMesh
JetAudio Basic
Kaspersky Antivirus
Kazaa Download Accelerator
Kazaa Media Desktop
Matrix Movie
McAfee Antivirus
Microsoft Internet Explorer
Microsoft Office XP
Microsoft Windows Media Player
Microsoft Windows 2003
Morpheus
msn hack
MSN Messenger (Windows NT/2000)
Nero Burning ROM
NetPumper
Network Cable e ADSL Speed
Norton Antivirus
Office 2003
Panda Antivirus
PerAntivirus
Pop-Up Stopper
QuickTime
RealOne Free Player
Registry Mechanic
SnagIt
SolSuite 2003: Solitaire Card Games Suite
Spybot - Search & Destroy
Trillian
Virtual Girl Sofia
Visual Studio Net
Winamp
WinMX
WinRAR
WinZip
WS_FTP LE (32-bit)
XoloX Ultra
ZoneAlarm
crack all versions
Cracked
Full version
KeyGen

The mail addresses are collected from the MSN Messenger contact list.

As a payload the malware displays two message boxes in july containing information about the author and the worm.

Removal instructions:
BitDefender can disinfect or delete automatically the files infected by this particular virus. The modified registry entries should be corrected manually.

1. If you don\'t have BitDefender installed click here to download an evaluation version;

2. Make sure that you have the latest updates using BitDefender Live!;

3. Make the following changes in the windows registry:

Note: Please make sure to modify only the values that are specified. It is also recommended to backup the windows registry before proceeding with these changes. For more information on backing the registry please read the FAQ.

1. Select Run... from Start, then type regedit and press Enter;

2. Delete the following key:
[HKLM\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\Lorraine = %SYSTEM%\\Lorraine.exe]

4. Reboot the computer

5. Perform a full scan of your system (selecting, from the Action tab, the option Prompt user for action). Choose to delete all the files infected with Win32.P2P.Lorrin.A@mm.
 
There seem to be different versions with a similar name, anyway, good luck. ;)
 
*sigh* it happned twice
2nd time this morning

costed my parents R1000 first time, R1000 second time, get these viruses from memory cards and bluetooth my parents work with :(
 
Seems to be spyware, I'll see if I can find anything else.

Im sure u saw the same thing i did aswell: maybe include this for those infected....

Manual Win32/P2P.SpyBot.Wuaumqr.Worm removal:
Kill process wuaumqr.exe
Delete file wuaumqr.exe
 
Top
Sign up to the MyBroadband newsletter
X