mwblog.org

MWBLOG.ORG


Virus Malware and Threat News for 20090530



Troj/Agent-KAU

- Troj/Agent-KAU at Sophos

...

Troj/Agent-KAV

- Troj/Agent-KAV at Sophos

...

Troj/Bdoor-AVI

- Troj/Bdoor-AVI at Sophos

...

Troj/Mdrop-CCT

- Troj/Mdrop-CCT at Sophos

...

Troj/Nebule-B

- Troj/Nebule-B at Sophos

Troj/Nebule-B is a Trojan for the Windows platform. Troj/Nebule-B drops a
malicious dll into the System folder when executed, for example:
<System>\winxyl32.dll (also detected as Troj/Nebule-B) The following Registry
entries are set to subsequently...

Troj/PWS-BAX

- Troj/PWS-BAX at Sophos

...

Troj/Agent-KAR

- Troj/Agent-KAR at Sophos

...

Troj/Agent-KAS

- Troj/Agent-KAS at Sophos

...

Troj/Agent-KAT

- Troj/Agent-KAT at Sophos

...

Troj/Delf-FCF

- Troj/Delf-FCF at Sophos

...

Troj/Agent-KAW

- Troj/Agent-KAW at Sophos

...

Troj/Agent-KAX

- Troj/Agent-KAX at Sophos

...

Troj/Dloadr-CNH

- Troj/Dloadr-CNH at Sophos

...

Mal/FakeAV-AX

- Mal/FakeAV-AX at Sophos

...

Troj/Bancos-BFR

- Troj/Bancos-BFR at Sophos

Troj/Bancos-BFR is a Trojan for the Windows platform. Troj/Bancos-BFR
includes functionality to access the internet and communicate with a remote server via HTTP.
When first run Troj/Bancos copies itself to <Windows>\ballon.exe.
...

Troj/Dloadr-CNG

- Troj/Dloadr-CNG at Sophos

Troj/Dloadr-CNG is a Trojan for the Windows platform. When Troj/Dloadr-CNG
is installed the following files are created: <System>\drivers\iofilter.sys
<System>\version.dll <System>\inf\layout.inf where
version32.d...

Troj/Lineag-CK

- Troj/Lineag-CK at Sophos

Troj/Lineag-CK is a Trojan for the Windows platform. When Troj/Lineag-CK is
installed the following files are created: <Current Folder>\35097del.bat
<System>\ro.dll The file ro.dll is also detected as Troj/Lineag-CK.
...

Troj/Nebule-Gen

- Troj/Nebule-Gen at Sophos

Troj/Nebule-Gen is a family of Trojans for the Windows platform.Members of Troj/Nebule-Gen may gather details
relating to dialup services and send collected information to a remote site via HTTP. The Trojans may inject
code into other processes in an attempt to remain hidden.
...

Troj/SwfDldr-H

- Troj/SwfDldr-H at Sophos

...

W32/AutoRun-AIR

- W32/AutoRun-AIR at Sophos

W32/AutoRun-AIR is a worm for the Windows platform. W32/AutoRun-AIR
includes functionality to access the internet and communicate with a remote server via HTTP.
When W32/AutoRun-AIR is installed the following files are created: <User>\My
Documents\...

0 writebacks [05/31/2009 21:41] [] permanent link



July 2010
Sun Mon Tue Wed Thu Fri Sat
       

Rss version