March 14, 2010

2/1: W32.Imaut.F Affects IM Clients--And Other Malware You Should Know About

Trojan.Zbot!gen4 Heuristic Detection

Trojan.Zbot!gen4 is a heuristic detection used to detect threats associated with the Trojan.Zbot family. More information can be found at this Symantec page.

Suspicious.BredoLab Detects Malicious Software

Suspicious.BredoLab is a detection technology designed to detect entirely new malware threats without traditional signatures. This technology is aimed at detecting malicious software that has been intentionally mutated or morphed by attackers. More information can be found at this Symantec page.

Suspicious.Vundo.5 Detects Malicious Software

Suspicious.Vundo.5 is a detection technology designed to detect entirely new malware threats without traditional signatures. This technology is aimed at detecting malicious software that has been intentionally mutated or morphed by attackers. More information can be found at this Symantec page.

Packed.Generic.283 Heuristic Detection

Packed.Generic.283 is a heuristic detection for files that may have been obfuscated or encrypted in order to conceal them from antivirus software. More information can be found at this Symantec page.

W32.Fujacks.CE Copies to Shared Drives

W32.Fujacks.CE is a worm that spreads by infecting files, copying itself to removable and shared drives and by exploiting vulnerabilities. More information can be found at this Symantec page.

Trojan.Malscript.C Redirects to Malicious Web Sites

Trojan.Malscript.C is a generic detection for HTML files infected with a JavaScript that redirects the browser to a malicious Web site that may exploit the browser or download other malicious threats. More information can be found at this Symantec page.

W32.Imaut.F Affects IM Clients

W32.Imaut.F is a worm that spreads by copying itself to local drives and network shares. It also sends links using instant messaging clients and may download configuration and update files from a remote computer. More information can be found at this Symantec page.

Agent-MIS Windows Trojan

Agent-MIS is a Trojan for the Windows platform. It includes functionality to access the Internet and communicate with a remote server via HTTP. More information can be found at this Sophos page.

Agent-MJD Creates Batch Scripts

Agent-MJD is a Trojan for the Windows platform. It includes functionality to create batch scripts, access the Internet and communicate with a remote server via HTTP. More information can be found at this Sophos page.

JSRedir-AR Redirects to Malicious Web Sites

JSRedir-AR will redirect the web browser to other malicious Web sites. More information can be found at this Sophos page.

QakBot-H Creates Files in System Folder

QakBot-H is a Trojan for the Windows platform. It includes functionality to run automatically, copy itself to the <System> folder, and create files in the <System> folder. More information can be found at this Sophos page.

Agent-MIR Copies to System Folder

Agent-MIR is a Trojan for the Windows platform. It includes functionality to run automatically, copy itself to the <System> folder and create files in the <System> folder. More information can be found at this Sophos page.

Mdrop-CKH Installs in Registry

Mdrop-CKH is a Trojan for the Windows platform. When run it copies itself to <System>explorer.exe<Windows>svchost.exe, and <Windows>spoolsv.exe. More information can be found at this Sophos page.

QakBot-D Copies to System Folder

QakBot-D is a Trojan for the Windows platform. When run, it copies itself to <System>sdra64.exe. More information can be found at this Sophos page.

Qakbot-E Copies to System Folder

Qakbot-E is a Trojan for the Windows platform. It includes functionality to run automatically, copy itself to the <System> folder, and create files in the <System> folder. More information can be found at this Sophos page.

1
IT Offers

Partners