bright.net Anti-Virus Page
Navigation
Recent Entries
¤ "Fake Antivirus" - Removal Tool Now Available
¤ Scheduled Maintenance - Scam Message
¤ XP Antivirus 2008 - Trojan
¤ MSNBC Spam
¤ CNN Scam Mail
¤ View All
¤ Scheduled Maintenance - Scam Message
¤ XP Antivirus 2008 - Trojan
¤ MSNBC Spam
¤ CNN Scam Mail
¤ View All
Links
Antivirus Programs
¤ Avast Antivirus
¤ AVG - Free Anti-Virus
¤ Avira AntiVir
Information
¤ Syamantec Virus Info
¤ Unwantedlinks.com
¤ Virus Encyclopedia
¤ Virus Hoax
Misc/Patches
¤ Mozilla Firefox (Browser)
¤ Sasser Patch - 2000/XP
¤ Zobot Patch
Removal Tools
¤ Avast! Removal Tool
¤ Beagel Removal
¤ Mytob Removal Tool
¤ Netsky Fix Tool
¤ Sasser Removal Tool
¤ Sober (Choose version)
¤ Sober.C Removal (NEW)
¤ Sober.X Removal
¤ Stinger - Virus Removal Tool
¤ Virus Removal Tool List
¤ Virus Utilities
¤ Zobot Removal Tool
Spyware Removal
¤ Ad-Aware
¤ CW Shredder
¤ Hijackthis
¤ Malwarebytes
¤ SpyBot - Search & Destroy
¤ Windows Defender
¤ Avast Antivirus
¤ AVG - Free Anti-Virus
¤ Avira AntiVir
Information
¤ Syamantec Virus Info
¤ Unwantedlinks.com
¤ Virus Encyclopedia
¤ Virus Hoax
Misc/Patches
¤ Mozilla Firefox (Browser)
¤ Sasser Patch - 2000/XP
¤ Zobot Patch
Removal Tools
¤ Avast! Removal Tool
¤ Beagel Removal
¤ Mytob Removal Tool
¤ Netsky Fix Tool
¤ Sasser Removal Tool
¤ Sober (Choose version)
¤ Sober.C Removal (NEW)
¤ Sober.X Removal
¤ Stinger - Virus Removal Tool
¤ Virus Removal Tool List
¤ Virus Utilities
¤ Zobot Removal Tool
Spyware Removal
¤ Ad-Aware
¤ CW Shredder
¤ Hijackthis
¤ Malwarebytes
¤ SpyBot - Search & Destroy
¤ Windows Defender
Virus News
W32/Peacomm!ZIP / WORM_NUWAR.AOP
W32/Peacomm!ZIP is a Trojan. The Trojan will infect Windows systems and spreads through email.
The subject of the infected mail will be any of the following;
ATTN!
Virus Alert!
Worm Alert!
Spyware Detected!
Virus Activity Detected!
Warning!
The body of the infected mail will be the combination of two strings mentioned below;
First string will be any one of the following;
Report
Warning
AutoComplaint
AbuseNotice
UrgentNotice
Notice
Second string will be;
Dear Customer,
Our robot has detected an abnormal activity from your IP address on sending e-mails. Probably it is connected with the last epedemic of a worm which does not have official patches at the moment.
We recommend you to install this patch to remove worm files and stop email sending, otherwise your account will be blocked.
We had archived the patch because the worm can modify upoacked exe files. You should open the archive file, enter the password and run the patch immediately.
Password: [random characters]
Customer Support Center Robot
The above mentioned second string will be in the image format.
The name of the infected attachment will be any of the following;
removal-[random number].zip
patch-[random number].zip
hotfix-[random number].zip
bugfix-[random number].zip
The said files may be password protected archives. The password of which will be sent in the body of the mail.
Upon execution, the trojan copies wincom32.sys (detected as W32/Peacomm.CQ) file in Windows System folder.
This Trojan is also known as Trojan.Peacomm!zip, WORM_NUWAR.AOP
Original source information found at:
http://www.pspl.com/virus_info/trojans/peacommzip.htm
Additional information can be found here
The subject of the infected mail will be any of the following;
ATTN!
Virus Alert!
Worm Alert!
Spyware Detected!
Virus Activity Detected!
Warning!
The body of the infected mail will be the combination of two strings mentioned below;
First string will be any one of the following;
Report
Warning
AutoComplaint
AbuseNotice
UrgentNotice
Notice
Second string will be;
Dear Customer,
Our robot has detected an abnormal activity from your IP address on sending e-mails. Probably it is connected with the last epedemic of a worm which does not have official patches at the moment.
We recommend you to install this patch to remove worm files and stop email sending, otherwise your account will be blocked.
We had archived the patch because the worm can modify upoacked exe files. You should open the archive file, enter the password and run the patch immediately.
Password: [random characters]
Customer Support Center Robot
The above mentioned second string will be in the image format.
The name of the infected attachment will be any of the following;
removal-[random number].zip
patch-[random number].zip
hotfix-[random number].zip
bugfix-[random number].zip
The said files may be password protected archives. The password of which will be sent in the body of the mail.
Upon execution, the trojan copies wincom32.sys (detected as W32/Peacomm.CQ) file in Windows System folder.
This Trojan is also known as Trojan.Peacomm!zip, WORM_NUWAR.AOP
Original source information found at:
http://www.pspl.com/virus_info/trojans/peacommzip.htm
Additional information can be found here
July 10th, 2007
bright.net does not support nor endorse these programs but have found some of them helpful. Many of the programs and links found on this page are for third-party applications and are to be used at your own risk. Should you encounter problems with the tools, you may need to consult a computer technician for further assistance.






