mwblog.org

MWBLOG.ORG


Virus Malware and Threat News for 20081230



Trojan.Downexec.C!inf

- Trojan.Downexec.C!inf at Norton Symantec

Trojan.Downexec.C!inf is a detection for files infected by Trojan.Downexec.C.
...

Infostealer.Tremzi

- Infostealer.Tremzi at Norton Symantec

Infostealer.Tremzi is a generic detection for polymorphic Trojan .dll files.
...

Troj/AdClick-FH

- Troj/AdClick-FH at Sophos

Troj/AdClick-FH is a Trojan for the Windows platform. Troj/AdClick-FH
copies itself to the system folder as prunnet.exe and adds registry entries under
HKLM\Software\Microsoft\CurrentVersion\Run\prunnet
HKCU\Software\Microsoft\CurrentVersion\Run\prunnet
HKLM\SO...

Troj/MDrop-BUY

- Troj/MDrop-BUY at Sophos

...

Troj/Tidola-Gen

- Troj/Tidola-Gen at Sophos

...

Troj/Dloadr-CDP

- Troj/Dloadr-CDP at Sophos

...

Troj/Dloadr-CDQ

- Troj/Dloadr-CDQ at Sophos

...

Troj/Drop-Q

- Troj/Drop-Q at Sophos

...

Troj/FakeVir-IV

- Troj/FakeVir-IV at Sophos

...

W32/Waled-D

- W32/Waled-D at Sophos

W32/Waled-D is a worm for the Windows platform. W32/Waled-D includes
functionality to access the internet and communicate with a remote server via HTTP and send itself out using
built-in SMTP client. The worm creates the following registry values to run itself on
Windows start...

Mal/Armada-A

- Mal/Armada-A at Sophos

Mal/Armada-A is a Trojan which may gather system information and send it to a remote attacker.
...

Troj/Agent-IMG

- Troj/Agent-IMG at Sophos

Troj/Agent-IMG is a Trojan for the Windows platform. Troj/Agent-IMG runs
continuously in the background, providing a backdoor server which allows a remote intruder to gain access and
control over the computer via IRC channels. When first run Troj/Agent-IMG copies itself
to <...

Exploit:SymbOS/SMSCurse.A

- Exploit:SymbOS/SMSCurse.A at F-Secure

Exploit:/SymbOS/SMSCurse.A is a Denial-of-Service (DoS) exploit that affects messaging components of phones
that use Symbian Series 60 versions 2.6, 2.8, 3.0, 3.1, and Sony Ericsson UiQ devices. When the exploit
crashes SMS messaging on a phone, the phone remains otherwise completely functional. The only effect is that
it cannot rec...

W32.Downadup.B

- W32.Downadup.B at Norton Symantec

W32.Downadup.B is a worm that spreads by exploiting the Microsoft Windows Server Service RPC Handling Remote
Code Execution Vulnerability (BID 31874). It also attempts to spread to network shares protected by weak
passwords and blocks access to security-related Web sites.
...

Trojan.Downexec.C

- Trojan.Downexec.C at Norton Symantec

Trojan.Downexec.C is a Trojan horse that may download files and steal information from the compromised
computer....

WORM_DOWNAD.AD

- WORM_DOWNAD.AD at Trend Micro

This worm may be downloaded from remote sites by other malware. It may be dropped by other malware. It may
arrive bundled with malware packages as a malware component.It drops copies of itself. This technique prevents
dropping of several copies of itself on already affected systems. It also locks its dropped copy to prevent
users fro...

Troj/Agent-IMR

- Troj/Agent-IMR at Sophos

...

Troj/Agent-IMS

- Troj/Agent-IMS at Sophos

...

Troj/Agent-IMT

- Troj/Agent-IMT at Sophos

...

Troj/FakeVir-IZ

- Troj/FakeVir-IZ at Sophos

...

Troj/Renos-CF

- Troj/Renos-CF at Sophos

Troj/Renos-CF is a Trojan for the Windows platform. When run Troj/Renos-CF
creates the file <System>\msxml71.dll (detected as Troj/Renos-CF) and creates the following registry
entries: HKCR\CLSID\{500BCA15-57A7-4eaf-8143-8C619470B13D}\InprocServer32
...

W32/Confick-C

- W32/Confick-C at Sophos

...

Troj/Agent-IMO

- Troj/Agent-IMO at Sophos

...

Troj/Agent-IMQ

- Troj/Agent-IMQ at Sophos

...

Troj/BHO-IY

- Troj/BHO-IY at Sophos

...

Troj/Dloadr-CDU

- Troj/Dloadr-CDU at Sophos

...

0 writebacks [12/31/2008 05:43] [] permanent link



July 2010
Sun Mon Tue Wed Thu Fri Sat
       

Rss version