mwblog.org

MWBLOG.ORG


Virus Malware and Threat News for 20080826



Trojan:W32/Agent.FVO

- Trojan:W32/Agent.FVO at F-Secure

Trojans are malicious programs that pretend be to benign. Trojans do not replicate themselves.
...

SpywarePreventer

- SpywarePreventer at Norton Symantec

BehaviorSpywarePreventer is a misleading application that may give exaggerated reports of threats on the
computer....

Trojan.Tarodrop.G

- Trojan.Tarodrop.G at Norton Symantec

Trojan.Tarodrop.G is a Trojan horse that attempts to exploit the JustSystems Ichitaro Document Handling
Unspecified Code Execution Vulnerability (BID 30828) in the Justsystem Ichitaro Office Suite in order to drop
more malware on to the compromised computer.
...

Exploit-TaroDrop.e

- Exploit-TaroDrop.e at McAfee

Upon launching the document, it exploits a 0-day vulnerability in Ichitaro and executes an embedded executable.
The following file is installed when the document is opened:%Windr%\winnet.dllThe file is detected as
BackDoor-DRZ trojan....

BackDoor-DRZ

- BackDoor-DRZ at McAfee

There are several versions existed. This is a general description. Newer versions require the latest DATs for
detection and cleaning.Upon execution, the trojan drops itself to the following file.%Windr%\winnet.dllThe
trojan modifies the following registry keys:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Winlo...

Spy-Agent.bw.gen.f

- Spy-Agent.bw.gen.f at McAfee

When executed, this trojan drops the following files:%System%\ntos.exe [Copy of Trojan]%System%\wsnpoem\audio.
dll [Data File]%System%\wsnpoem\video.dll [Data File]Note:%System% is a variable that refers to the System
folder. In a Windows XP machine, this should by default refer to the “C:\Windows\System32” folderThe trojan
also modif...

Exchanger.AH

- Exchanger.AH at Panda

It downloads the adware program detected as RogueAntimalware2008 to the affected computer, which is a
fake antivirus which warns users of unexisting threats in the computer. It reaches the computer in an email
message about Paris Hilton.
...

KeyLogger.EA

- KeyLogger.EA at Panda

It logs the keystrokes and the activity of the mouse in order to steal all type of information about the user,
such as passwords, banking data and email addresses, among others. It does not spread automatically by
its own means....

OscarBot.UG

- OscarBot.UG at Panda

It receives remote instructions such as launching DDoS type denial of service attacks. It spreads
via the AOL instant messaging program AIM and through removable drives.
...

Troj/BDoor-ANJ

- Troj/BDoor-ANJ at Sophos

...

Troj/Dloadr-BRE

- Troj/Dloadr-BRE at Sophos

...

Troj/Mdrop-BVF

- Troj/Mdrop-BVF at Sophos

Troj/Mdrop-BVF drops the file <Windows>\System\<Random Name>.dll which is detected as
Mal/Delf-M.
...

Mal/EncPk-ER

- Mal/EncPk-ER at Sophos

...

Troj/BHO-GR

- Troj/BHO-GR at Sophos

...

Troj/Dloadr-BRC

- Troj/Dloadr-BRC at Sophos

...

Troj/Dloadr-BRD

- Troj/Dloadr-BRD at Sophos

...

Troj/Linea-C

- Troj/Linea-C at Sophos

...

Troj/Zlob-ANM

- Troj/Zlob-ANM at Sophos

...

0 writebacks [08/27/2008 04:44] [] permanent link



July 2010
Sun Mon Tue Wed Thu Fri Sat
       

Rss version