mwblog.org

MWBLOG.ORG


Virus Malware and Threat News for 20090628



VBS.Sasan

- VBS.Sasan at Norton Symantec

VBS.Sasan is a worm that spreads by copying itself to other drives.
...

Troj/Dloadr-CPE

- Troj/Dloadr-CPE at Sophos

...

Troj/Agent-KIS

- Troj/Agent-KIS at Sophos

...

Troj/FakeAV-UQ

- Troj/FakeAV-UQ at Sophos

...

Troj/Inject-HW

- Troj/Inject-HW at Sophos

...

Troj/Mdrop-CDJ

- Troj/Mdrop-CDJ at Sophos

...

Troj/AdClick-FO

- Troj/AdClick-FO at Sophos

Troj/AdClick-FO is a Trojan for the Windows platform. Troj/AdClick-FO
copies itself to <System>\net.net and sets the following registry entries:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run net <System>\net.net\
HK...

Troj/Agent-KIR

- Troj/Agent-KIR at Sophos

Troj/Agent-KIR is a Trojan for the Windows platform. When run
Troj/Agent-KIR creates the files: <Temp>\bassmod.dll - can be safely deleted
<Temp>\keygen.exe - detected as Troj/Agent-KIR <Temp>\nzm.exe - detected as
Troj/Agent-KIR <S...

Troj/FakeAV-UP

- Troj/FakeAV-UP at Sophos

Troj/FakeAV-UP is a Trojan for the Windows platform. When run
Troj/FakeAV-UP copies itself to <Windows>\sysguard.exe and sets the following registry entries:
HKCU\Software\Microsoft\Internet Explorer\Download CheckExeSignatures no
...

Troj/Agent-KIP

- Troj/Agent-KIP at Sophos

...

Troj/Agent-KIQ

- Troj/Agent-KIQ at Sophos

...

Bloodhound.Exploit.257

- Bloodhound.Exploit.257 at Norton Symantec

Bloodhound.Exploit.257 is a heuristic detection for potentially malicious files that may exploit
vulnerabilities in order to perform further malicious actions.
...

W32.Slegon

- W32.Slegon at Norton Symantec

W32.Slegon is a worm that spreads by copying itself to removable and mapped drives. It may also download files
on to the compromised computer.
...

WORM_IRCBOT.GAT

- WORM_IRCBOT.GAT at Trend Micro

This worm uses social engineering methods to lure users into performing certain actions that may, directly or
indirectly, cause malicious routines to be performed. Specifically, it makes use of MSN Messenger to send
copies of itself.It may be downloaded from remote sites by other malware.It may be downloaded unknowingly by a
user whe...

WORM_BLAZEBOT.A

- WORM_BLAZEBOT.A at Trend Micro

This worm may be downloaded from remote sites by other malware. It may be dropped by other malware. It may be
downloaded unknowingly by a user when visiting malicious Web sites.It locates the download directory for
certain peer to peer applications where it drops a copy of itself. This worm uses enticing file names for its
dropped co...

WORM_KOOBFACE.JG

- WORM_KOOBFACE.JG at Trend Micro

This worm has received attention from independent media sources and/or other security firms.It may be
downloaded from remote sites by other malware. It may be installed manually by a user.When executed, it
accesses a certain website where it downloads another worm, which Trend Micro detects as WORM_KOOBFACE.CV. As
a result, malicious...

OSX_JAHLAV.C

- OSX_JAHLAV.C at Trend Micro

This Trojan may be downloaded unknowingly by a user when visiting malicious Web sites. It may arrive as a
specific file. It comes as a MAC OS X mountable Disk Image file that contains INSTALL.PKG installer package
file. The said installer package file contains its malicious script and its component files. Upon execution of
this packa...

Mal/Behav-274

- Mal/Behav-274 at Sophos

...

Mal/Bifrose-U

- Mal/Bifrose-U at Sophos

...

Mal/DelpInj-A

- Mal/DelpInj-A at Sophos

...

Mal/EncPk-IU

- Mal/EncPk-IU at Sophos

...

Mal/Poeb-A

- Mal/Poeb-A at Sophos

...

Mal/PWS-AA

- Mal/PWS-AA at Sophos

...

Mal/SillyFDC-A

- Mal/SillyFDC-A at Sophos

Members of Mal/SillyFDC-A are worms which attempt to spread via removeable shared drives.
...

Troj/Agent-KJE

- Troj/Agent-KJE at Sophos

...

Troj/Bckdr-QWD

- Troj/Bckdr-QWD at Sophos

...

Troj/Dloadr-COU

- Troj/Dloadr-COU at Sophos

...

0 writebacks [06/29/2009 21:41] [] permanent link



July 2010
Sun Mon Tue Wed Thu Fri Sat
       

Rss version