SoftwareTipsandTricks.com
Home Forums Windows 7 Security Tips
Forums

Windows 7
Windows Vista
Windows XP

Security Tips
Troubleshooting
Keyboard Shortcuts
Encyclopedia


Drivers

Internet Terms
Computer Terms

File Extensions (75)
File Extensions (15K+)

Startup Applications
Necessary Files
Useless Files
At Your Option Files
Dangerous Files
Browser Objects

DLL Files
SYS Files
INF Files
OCX Files
VXD Files

Virus Database
Virus Warnings

Easter Eggs
Tips and Tricks
Articles
Hot Downloads


Privacy Policy
Contact Us







  %SysDir%\NvCpl.EXE

Name %SysDir%\NvCpl.EXE

Description

Worm W32.Yanz.B@mm
It is a mass-mailing worm that uses its own SMTP engine for spreading.
1. Adds to Windows startup.
It masks to NVIDIA control panel application NvCpl.exe.
2. Creates the files
%System%\Dong_Shi.exe
%System%\NvCpl.EXE
C:\Yanzi.htm
%Windir%\Sun_YanZI.zip (a zip file that contains a file Sun_Yan_Zi-Shen_Q1.mp3.pif - it is a copy of the worm)
%System%\Huai_Tian_Q1.sys ( an MIME-encoded zip file that contains a file Sun_Yan_Zi-Shen_Q1.mp3.pif - it is a copy of the worm)
%System%\I_am_Sun_Yanzi.sys. (an MIME-encoded worm)
YanZi.vbs. (this file is created in the current folder and it creates the file sun.exe)
When the file sun.exe runs, it creates three .jpg files under %Temp% folder. The file names have "SuN" as prefix.
One of these files is a Trojan that exploits the Microsoft GDI+ Library JPEG Segment Length Integer Underflow vulnerability (described in the Microsoft Security Bulletin MS04-028) to download and execute a file named m00.exe, from the domain sunyanzi.fastmail.cn. This file is also a Trojan.


Still have a problem? Ask for help at our discussion forum.



Search Dangerous Files :
 

: : Recent posts at Forums : :

Sexual pictures

Grown up purlieus

ВСЁ САМОЕ ИНТ&

Unencumbered galleries

My up to date website

dimensions of a standard size twin mattress

Как правильно

classical music for studying and concentration for kids

film music composers jobs

New Poke out

НАСКОЛЬКО ВАЖ

С одной блочн

Big Black Grls!Old Fat MILF !# 5223794

Black Fat - Ebony moms boobs# 9322028

Fat Pussy BBW!Black Girls photo!# 5222471

Callow Project

Смотреть филь

Hardcore Gay photo blogging service

Full-grown galleries

Mature purlieus

sortie de chemise de spyder

Sexual pictures

Pictures from collective networks

ozualay

wdgdccl

Open full-grown galleries

Новости строи

Протестируй н

Hardcore Gay photo blogging ritual

Free galleries




SoftwareTipsandTricks, All Rights Reserved.