March 21, 2010

1/22: ScrLd-B Malicious JavaScript--and other Malware Threats

Packed.Generic.280 Heuristic Detection

Packed.Generic.280 is a heuristic detection for files that may have been obfuscated or encrypted in order to conceal them from antivirus software. More information can be found at this Symantec page.

Trojan.FakeAV!gen16 Heuristic Detection

Trojan.FakeAV!gen16 is a heuristic detection used to detect threats associated with the Trojan.FakeAV family. More information can be found at this Symantec page.

W32.Gammima.AG!gen3 Heuristic Detection

W32.Gammima.AG!gen3 is a heuristic detection used to detect threats associated with the W32.Gammima.AG family. More information can be found at this Symantec page.

W32.Fujacks.CC Infects Executable Files

W32.Fujacks.CC is a virus that infects executable files. More information can be found at this Symantec page.

ScrLd-B Malicious JavaScript

ScrLd-B is a malicious JavaScript embedded in web pages. When a page containing ScrLd-B is viewed, the malicious JavaScript attempts to download additional malicious script content. More information can be found at this Sophos page.

TDSSRt-A Affects Rootkits

TDSSRt-A exhibits malicious behavior common to rootkits. More information can be found at this Sophos page.

Agent-MGI Windows Trojan

Agent-MGI is a Trojan for the Windows platform. More information can be found at this Sophos page.

Fudge-A Installs in Registry

Fudge-A is a Trojan for the Windows platform. When installed, the following files are created <Temp>gur3.exe and <System>xxxxxxxx.dll, where xxxxxxxx.dll is a random filename. More information can be found at this Sophos page.

PcClien-WI Drops More Malware

PcClien-WI is a Trojan for the Windows platform. It includes functionality to access the Internet and communicate with a remote server via HTTP. It includes stealth code in order to hide files and processes. More information can be found at this Sophos page.

Zbot-LM Installs Itself in Registry

Zbot-LM is a Trojan for the Windows platform. It includes functionality to run automatically. When Zbot-LM is installed the following files are created <System>sdra64.exe and <Temp>incognito.exe. More information can be found at this Sophos page.

Autoit-II Installs in Registry

Autoit-II is a worm for the Windows platform. Registry entries are created under HKLMSYSTEM. More information can be found at this Sophos page.

1
IT Offers

Partners