mwblog.org

MWBLOG.ORG


Virus Malware and Threat News for 20090225



Worm:SymbOS/Yxe

- Worm:SymbOS/Yxe at F-Secure

Worm:SymbOS/Yxe is malicious software for Symbian S60 3rd Edition Phones.
...

P2P-Worm:W32/Bacteraloh.H

- P2P-Worm:W32/Bacteraloh.H at F-Secure

A type of worm that spreads over Peer-to-Peer (P2P) networks.
...

Packed.Generic.210

- Packed.Generic.210 at Norton Symantec

Packed.Generic.210 is a heuristic detection for files that may have been obfuscated or encrypted in order to
conceal them from antivirus software.
...

W32.Ackantta.B@mm

- W32.Ackantta.B@mm at Norton Symantec

W32.Ackantta.B@mm is a mass-mailing worm that gathers email addresses from the compromised computer and
spreads by copying itself to removable drives and shared folders.
...

Backdoor.Syzoor

- Backdoor.Syzoor at Norton Symantec

Backdoor.Syzoor is a Trojan horse that opens a back door on the compromised computer.
...

BAT_DELWIN.AA

- BAT_DELWIN.AA at Trend Micro

This batch file may be downloaded unknowingly by a user when visiting malicious Web site(s).When executed, it
displays the following message box:It then removes the Hidden, System, and Read-only attributes from several
key system files. This removes the system's protection of the said files, making them easier to delete. It
then dele...

Werly.A

- Werly.A at Panda

It infects the files with an EXE extension it finds in the affected computer. It reaches the
computer by distributing the previously infected files.
...

Troj/Agent-JAS

- Troj/Agent-JAS at Sophos

...

Troj/Agent-JAT

- Troj/Agent-JAT at Sophos

...

Troj/Agent-JAU

- Troj/Agent-JAU at Sophos

...

Troj/Dloadr-CHL

- Troj/Dloadr-CHL at Sophos

...

W32/Autoit-BV

- W32/Autoit-BV at Sophos

...

Mal/Dropper-AL

- Mal/Dropper-AL at Sophos

Mal/Dropper-AL is a Trojan for the Windows platform. When executed, Mal/Dropper-AL will drop and
execute other malware on the system.
...

Mal/Dropper-AP

- Mal/Dropper-AP at Sophos

Mal/Dropper-AP is a malicious program for the Windows platform.
...

Mal/GameDll-A

- Mal/GameDll-A at Sophos

...

P2P-Worm:W32/Bacteraloh

- P2P-Worm:W32/Bacteraloh at F-Secure

A type of worm that spreads over Peer-to-Peer (P2P) networks.
...

Trojan:W32/Monderd.gen

- Trojan:W32/Monderd.gen at F-Secure

Trojan.Win32.Monderd.gen is a generic detection for the Vundo trojan family.
...

ThreatNuker

- ThreatNuker at Norton Symantec

BehaviorThreatNuker is a misleading application that may give exaggerated reports of threats on the computer.
...

JS_DLOADR.ACF

- JS_DLOADR.ACF at Trend Micro

This script may be downloaded from remote sites by JS_DLOADR.ABO. It may be downloaded from certain remote
sites.Once executed, it takes advantage of the vulnerability in Windows Media Encoder 9 ActiveX Control in an
attempt to connect to a certain URL to download a file.As of this writing, however, the download URL is
inaccessible.M...

JS_DLOADR.ACE

- JS_DLOADR.ACE at Trend Micro

This script may be downloaded from remote sites by JS_DLOADR.ABO. It may be downloaded from certain remote
sites.It takes advantage of the vulnerability in Microsoft Data Access Components (MDAC) in an attempt to
connect to a URL to download a file. As a result, malicious routines of the downloaded file are exhibited on
the affected...

JS_DLOADR.ABO

- JS_DLOADR.ABO at Trend Micro

This script arives on a system as a file downloaded by JS_AGENT.AMWU from a certain remote site.Once executed,
it attempts to connect to several URLs to download more script malware. It also checks for ActiveX controls
and downloads other malicious scripts based on the installed ActiveX controls. Trend Micro detects these
script malw...

JS_AGENT.AMWU

- JS_AGENT.AMWU at Trend Micro

This is the Trend Micro detection for script files that use an iFrame tag to redirect users to certain
malicious URLs.Once an unsuspecting user views an infected Web page, it attempts to connect to certain URLs to
download files. Trend Micro detectes one of these downloaded files as JS_DLOADR.ABO. As a result, malicious
routines of t...

Mal/EncPk-HD

- Mal/EncPk-HD at Sophos

...

Troj/Agent-JBE

- Troj/Agent-JBE at Sophos

...

Troj/Bdoor-ATE

- Troj/Bdoor-ATE at Sophos

...

Troj/Cavzopa-A

- Troj/Cavzopa-A at Sophos

...

Troj/PWS-AYW

- Troj/PWS-AYW at Sophos

...

Troj/PWS-AYX

- Troj/PWS-AYX at Sophos

...

Troj/PWS-AYY

- Troj/PWS-AYY at Sophos

...

W32/Autoit-BW

- W32/Autoit-BW at Sophos

...

W32/Autorun-ZK

- W32/Autorun-ZK at Sophos

W32/Autorun-ZK is a worm for the Windows platform. When the application is
installed the following files are created: <System>\drivers\sysdrv32.sys -
detected as W32/Rbot-GXM <System>\wmisys.exe - copy of W32/Autorun-ZK
W32/Autorun...

Troj/Agent-JAZ

- Troj/Agent-JAZ at Sophos

...

0 writebacks [02/26/2009 22:41] [] permanent link



July 2010
Sun Mon Tue Wed Thu Fri Sat
       

Rss version