March 14, 2010

1/25: Dldr-DB Steals Confidential Information--And Other Malware You Should Know About

W32.Zimuse Copies to Removable Drives

W32.Zimuse is a worm that spreads by copying itself to removable drives. More information can be found at this Symantec page.

Bloodhound.Exploit.280 Heuristic Detection

Bloodhound.Exploit.280 is a heuristic detection for files attempting to exploit the Adobe Acrobat Reader Remote Code Execution Vulnerability. More information can be found at this Symantec page.

Pinkslipbot!pk Downloaded Over Network Shares

Pinkslipbot!pk is a detection for a component of the  Pinkslipbot family. This is a password protected PK zipped archive which may either be downloaded or copied over network shares. More information can be found at this McAfee page.

Autorun.worm.gj Installs to Registry

Autorun.worm.gj will attempt to infect available drives. Upon execution, it will install itself to the registry.  More information can be found at this McAfee page.

Backdoor.Noppuca!inf Affects Windows

Backdoor.Noppuca!inf is a detection for files that are infected by Backdoor.Noppuca. More information can be found at this Symantec page.

Backdoor.Noppuca Trojan Horse

Backdoor.Noppuca is a Trojan horse that opens a back door on the compromised computer. More information can be found at this Symantec page.

Iframe-Gen Malicious JavaScript Trojans

Iframe-Gen is a family of malicious JavaScript Trojans embedded in web pages. It is likely to be detected in legitimate Web pages that have been compromised in order to download further malicious code. More information can be found at this Sophos page.

PDFJs-N Drops More Malware

PDFJs-N uses JavaScript to install other malicious software. More information can be found at this Sophos page.

Dldr-DB Steals Confidential Information

Dldr-DB is a Trojan for the Windows platform. It includes functionality to steal confidential information, access the Internet, and communicate with a remote server via HTTP. More information can be found at this Sophos page.

Iframe-DQ Malicious JavaScript

Iframe-DQ is a malicious JavaScript embedded in Web pages. When a page containing Iframe-DQ is viewed in a browser, the script attempts to load malicious content from a remote Web site. More information can be found at this Sophos page.

Tiotua-CA Windows Worm

Tiotua-CA is a worm for the Windows platform. When installed it creates the file <System>csrcs.exe. More information can be found at this Sophos page.

1
IT Offers

Partners