mwblog.org

MWBLOG.ORG


Virus Malware and Threat News for 20081128



Worm:W32/Autorun.KK

- Worm:W32/Autorun.KK at F-Secure

A standalone malicious program which uses computer or network resources to make complete copies of itself. May
include code or other malware to damage both the system and the network.
...

Worm:W32/AutoIt.Q

- Worm:W32/AutoIt.Q at F-Secure

This malware spreads by copying itself to removable devices and replacing the autorun.inf of the device with
its own copy to ensure automatic execution.
...

Nakhatar.A

- Nakhatar.A at Panda

It carries out several modifications in the Windows Registry, which prevent the computer from working
properly. It disables several options such as the Task Manager and the Folder Options, among others. It
spreads making copies of itself in all the available system drives.
...

Mal/VidHtml-F

- Mal/VidHtml-F at Sophos

Mal/VidHtml-F is a malicious script that attempts to redirect to a malicious executable file.
The script is often found in a page pretending to be YouTube or another video site. The
malicious executable often pretends to be related to a video codec or a Flash update.
...

Troj/Dialer-FW

- Troj/Dialer-FW at Sophos

...

Troj/PSW-GA

- Troj/PSW-GA at Sophos

...

W32/Insom-A

- W32/Insom-A at Sophos

...

W32/Jeff-A

- W32/Jeff-A at Sophos

W32/Jeff-A may overwite file data during infection. As a result, some files may not be recoverable.
...

Mal/Trakil-A

- Mal/Trakil-A at Sophos

...

Mal/VidHtml-A

- Mal/VidHtml-A at Sophos

Mal/VidHtml-A is a malicious script that attempts to redirect to a malicious executable file.
The script is often found in a page pretending to be YouTube or another video site. The
malicious executable often pretends to be related to a video codec or a Flash update.
...

Mal/WnSpyProt-A

- Mal/WnSpyProt-A at Sophos

Mal/WnSpyProt-A is a family of fake Anti-Virus programs.
...

Troj/BDoor-Gen

- Troj/BDoor-Gen at Sophos

...

Bloodhound.PDF.1

- Bloodhound.PDF.1 at Norton Symantec

Bloodhound.PDF.1 is a heuristic detection for reporting PDF files that contain JavaScript that may have been
obfuscated or encrypted to conceal it from antivirus software.
...

W32.Delezium!inf

- W32.Delezium!inf at Norton Symantec

W32.Delezium!inf is a detection for files infected by W32.Delezium.
...

W32.Delezium

- W32.Delezium at Norton Symantec

W32.Delezium is a virus that infects executable files and deletes certain files on the compromised computer.
...

Troj/Dloadr-CBF

- Troj/Dloadr-CBF at Sophos

Troj/Dloadr-CBF is a Trojan for the Windows platform. Troj/Dloadr-CBF
contacts malicious websites and may attempt to download additional malware detected as Mal/Behav-300.
Troj/Dloadr-CBF sets the following registry entry to run on startup
   HKCU\So...

Troj/Dloadr-CBG

- Troj/Dloadr-CBG at Sophos

...

Troj/Renos-BQ

- Troj/Renos-BQ at Sophos

Troj/Renos-BQ is a downloader Trojan for the Windows platform.
...

Troj/Renos-BR

- Troj/Renos-BR at Sophos

Troj/Renos-BR is a downloader Trojan for the Windows platform.
...

Troj/Renos-BS

- Troj/Renos-BS at Sophos

Troj/Renos-BS is a downloader Trojan for the Windows platform.
...

Troj/Renos-BT

- Troj/Renos-BT at Sophos

Troj/Renos-BT is a downloader Trojan for the Windows platform.
Troj/Renos-BT is a DLL which is typically installed as a Browser Helper Object (BHO) for Microsoft Internet
Explorer....

Mal/ObfJS-AJ

- Mal/ObfJS-AJ at Sophos

Mal/ObfJS-AJ is a script obfuscated in a manner typical of malware.
...

Troj/Agent-IJJ

- Troj/Agent-IJJ at Sophos

Troj/Agent-IJJ is a Trojan for the Windows platform. When first run
Troj/Agent-IJJ copies itself to <Windows>\msauc.exe and creates the file <System>\shell31.dll.
This is a text file and can be safely deleted. The following registry entry is created
to run msauc.ex...

0 writebacks [11/29/2008 05:41] [] permanent link



July 2010
Sun Mon Tue Wed Thu Fri Sat
       

Rss version