mwblog.org

MWBLOG.ORG


Virus Malware and Threat News for 20090728



Hacktool.Stonedbootkit

- Hacktool.Stonedbootkit at Norton Symantec

Hacktool.Stonedbootkit is a Trojan horse that installs Boot.Stonedbootkit on the compromised computer.
...

Boot.Stonedbootkit

- Boot.Stonedbootkit at Norton Symantec

Boot.Stonedbootkit is a virus that infects the master boot record (MBR) on the compromised computer.
...

Troj/Bankr-E

- Troj/Bankr-E at Sophos

...

Troj/FakeAle-OS

- Troj/FakeAle-OS at Sophos

...

Troj/Mdrop-CEI

- Troj/Mdrop-CEI at Sophos

...

Troj/NTRoot-E

- Troj/NTRoot-E at Sophos

...

Troj/SFCHck-A

- Troj/SFCHck-A at Sophos

...

W32/AutoIt-FH

- W32/AutoIt-FH at Sophos

...

Troj/DarkMoon-B

- Troj/DarkMoon-B at Sophos

...

Troj/PDFEx-BN

- Troj/PDFEx-BN at Sophos

...

Troj/PWS-BCP

- Troj/PWS-BCP at Sophos

...

Troj/Zbot-GX

- Troj/Zbot-GX at Sophos

...

RegistryEasy

- RegistryEasy at Norton Symantec

BehaviorRegistryEasy is a potentially unwanted application that is being promoted through aggressive means.
...

JS_OWCREF.A

- JS_OWCREF.A at Trend Micro

...

Troj/FakeAV-WP

- Troj/FakeAV-WP at Sophos

...

Troj/Mdrop-CEK

- Troj/Mdrop-CEK at Sophos

...

W32/AutoRun-AMZ

- W32/AutoRun-AMZ at Sophos

...

W32/Autorun-ANA

- W32/Autorun-ANA at Sophos

W32/Autorun-ANA spreads by copying itself to removable devices such as USB sticks.
W32/Autorun-ANA copies itself to the <profile> folder as a hidden file and creates the following
registry entry to run itself on system restart:
HKCU\Software\Microsoft\Windows\CurrentVers...

W32/AutoRun-ANB

- W32/AutoRun-ANB at Sophos

...

W32/Autorun-ANC

- W32/Autorun-ANC at Sophos

...

JS/Agent-KRL

- JS/Agent-KRL at Sophos

...

Troj/Agent-KRM

- Troj/Agent-KRM at Sophos

...

Troj/Clicker-FK

- Troj/Clicker-FK at Sophos

...

XM/Laroux-AP

- XM/Laroux-AP at Sophos

XM/Laroux-AP is a variant of XM/Laroux which uses the file ECSYSTEM.XLS to store itself.
...

0 writebacks [07/29/2009 21:42] [] permanent link



July 2010
Sun Mon Tue Wed Thu Fri Sat
       

Rss version