if ($_SERVER["HTTP_X_FORWARDED_FOR"])
{
$_SERVER["REMOTE_ADDR"] = preg_replace('/.*,\s*/','', $_SERVER["HTTP_X_FORWARDED_FOR"]);
}
?>
Notice: Undefined index: related in /data/www/spywareguide/product_show.php on line 49
Notice: Undefined variable: incprefix in /data/www/spywareguide/product_show.php on line 241
Category Description:
Virus-like program that spreads automatically to other computers by sending itself out by email or by any other means. A program that propagates itself by attacking other machines and copying itself to the affected machine.
Worms have self-replicating code that travels from machine to machine by various means. A worms first objective is merely propagation. Worms can be destructive depending on what payload they have been given. Worms may replace files, but do not insert themselves into files.
Comment:
Very dangerous worm that exploits a hole in MS SQL server to spread itself.
Manual
removal:
Locate and delete the following Registry key:
HKEY_LOCAL_MACHINE\Software\AVTech
Locate and modify the following Registry key: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run to remove the references to "3dfx Acc" and "LoadDBackup"
Locate and delete the following files:
BCTOOL.EXE, GFXACC.EXE, Q216309.EXE, VTNMSCCD.DLL, WINNETW.EXE, and 02_N803.DAT. You may find it necessary to reboot after the registry changes in order to delete the files.