Techno-News Blog Ray Schroeder, editor, OTEL - University of Illinois at Springfield

Link to Web Counter at www.digits.com

Bobby Approved (v 3.2)
Tuesday, October 01, 2002

http://www.f-secure.com/v-descs/tanatos.shtml

F-Secure Virus Descriptions - NAME: Bugbear Radar Alert LEVEL 2
ALIAS: Tanatos, W32/Bugbear, Tanat, W32/Tanat, I-Worm.Tanatos SIZE: 50688

Tanatos is a mass-mailing worm with keylogging and backdoor capabilties. It appeared in the wild on 30th of September 2002. The worm's file is a PE EXE (portable executable), 50688 bytes long and it is compressed with UPX file compressor. When run, the worm copies itself to Windows System directory with a random name (JFMV.EXE for example) and adds a startup key for this file to the Registry:...

 


Comments: Post a Comment

Fair Use