1/25: Dldr-DB Steals Confidential Information--And Other Malware You Should Know About
W32.Zimuse Copies to Removable Drives
W32.Zimuse is a worm that spreads by copying itself to removable drives. More information can be found at this Symantec page.
Bloodhound.Exploit.280 Heuristic Detection
Bloodhound.Exploit.280 is a heuristic detection for files attempting to exploit the Adobe Acrobat Reader Remote Code Execution Vulnerability. More information can be found at this Symantec page.
Pinkslipbot!pk Downloaded Over Network Shares
Pinkslipbot!pk is a detection for a component of the Pinkslipbot family. This is a password protected PK zipped archive which may either be downloaded or copied over network shares. More information can be found at this McAfee page.
Autorun.worm.gj Installs to Registry
Autorun.worm.gj will attempt to infect available drives. Upon execution, it will install itself to the registry. More information can be found at this McAfee page.
Backdoor.Noppuca!inf Affects Windows
Backdoor.Noppuca!inf is a detection for files that are infected by Backdoor.Noppuca. More information can be found at this Symantec page.
Backdoor.Noppuca Trojan Horse
Backdoor.Noppuca is a Trojan horse that opens a back door on the compromised computer. More information can be found at this Symantec page.
Iframe-Gen Malicious JavaScript Trojans
Iframe-Gen is a family of malicious JavaScript Trojans embedded in web pages. It is likely to be detected in legitimate Web pages that have been compromised in order to download further malicious code. More information can be found at this Sophos page.
PDFJs-N Drops More Malware
PDFJs-N uses JavaScript to install other malicious software. More information can be found at this Sophos page.
Dldr-DB Steals Confidential Information
Dldr-DB is a Trojan for the Windows platform. It includes functionality to steal confidential information, access the Internet, and communicate with a remote server via HTTP. More information can be found at this Sophos page.
Iframe-DQ Malicious JavaScript
Iframe-DQ is a malicious JavaScript embedded in Web pages. When a page containing Iframe-DQ is viewed in a browser, the script attempts to load malicious content from a remote Web site. More information can be found at this Sophos page.
Tiotua-CA Windows Worm
Tiotua-CA is a worm for the Windows platform. When installed it creates the file <System>csrcs.exe. More information can be found at this Sophos page.
