Click here

Articles by eSecurityPlanet.com Staff 

8/31: PE_Bobax-AF Virus Appends .EXE File Code

PE_Bobax.AF is a memory-resident virus that infects all executable (EXE) files running on an affected system by appending its code to a target file.

8/31: PE_Bobax.AF-O Virus Infects .EXE Files

PE_Bobax.AF-O is Trend Micro's detection for the mother virus of PE_BOBAX.AF that infects all running .EXE files by appending its code.

8/31: Savage-A Worm, Creates, Executes File

Upon initial execution, Worm_Savage.A creates the file Me^sa~e#4% in the Windows temporary folder.

8/31: Trojan.Exphook Steals IE Passwords

Trojan.Exphook is a password stealing Trojan horse that hooks Internet Explorer and searches local files in an attempt to collect passwords and other sensitive information from the compromised computer.

8/31: Anisc-B a Macro Virus

W97M.Anisc.B is a macro virus that infects Microsoft Word documents.

8/31: Forbot-FL Worm, Trojan Exploits Flaws

W32/Forbot-FL is a worm and IRC backdoor Trojan for the Windows platform.

8/31: Bancban-EW an Internet Banking Trojan

Troj/Bancban-EW is an internet banking Trojan.

8/31: Fumilo-A Trojan Blocks Website Access

Troj/Fumilo-A is a Trojan for the Windows platform.

8/31: QQPass-U a Password-Stealing Trojan

Troj/QQPass-U is a password stealing Trojan for the Windows platform.

8/30: Trojan.Cdtray Opens CD-ROM Drive

Trojan.Cdtray is a Trojan horse program that causes the CD-ROM drive to open and close repeatedly.

8/30: Banker-FH Trojan Monitors Open Windows

Troj/Banker-FH is a Trojan for the Windows platform.

8/30: Zotob-E Worm Exploits Plug-and-Play Flaw

For the second time this month, a security vendor has issued an alert for Worm_Zotob.E, which spreads by exploiting the Windows Plug and Play vulnerability.

8/30: Mytob-JH Worm Lowers Security Settings

W32.Mytob.JH@mm is a mass-mailing worm the opens a back door and lowers security settings on the compromised computer.

8/30: Bobax-AH a Mass-Mailing Worm

W32.Bobax.AH@mm is a mass-mailing worm that attempts to use the compromised computer as a covert proxy.

8/30: Rbot-AMA Worm, Trojan, Exploits Flaws

W32/Rbot-AMA is a worm and IRC backdoor Trojan for the Windows platform.

8/30: Dloader-SR Trojan Runs Malicious Code

Troj/Dloader-SR is a Trojan for the Windows platform.

8/30: Dloader-TB Trojan Installs Driver

Troj/Dloader-TB is a Trojan for the Windows platform.

8/29: Feutel-U a Backdoor Trojan

Troj/Feutel-U is a backdoor Trojan for the Windows platform.

8/29: Mytob-JH Worm Lowers Security Settings

W32.Mytob.JH@mm is a mass-mailing worm the opens a back door and lowers security settings on the compromised computer.

8/29: Mytob-EG a Mass-Mailing Worm

W32/Mytob-EG is a mass-mailing worm and backdoor Trojan that can be controlled through the Internet Relay Chat (IRC) network.

8/29: Haxdoor-AI Trojan Has Stealth Functions

Troj/Haxdoor-AI is a backdoor Trojan incorporating stealth functionality, which allows a remote intruder to gain access and control over the computer.

8/29: Nethief-P a Backdoor Trojan

Troj/Nethief-P is a backdoor Trojan for the Windows platform that provides unauthorized remote access to the infected computer.

8/29: Chode-G Worm Spreads Via IM

W32/Chode-G is a worm with IRC backdoor Trojan functionality.

Mytob-GW Grabs Third Spot in Top Threats

The Mytob-GW variant is considered the third most widespread malware on the Internet, according to Central Command's listing of the Top Threats.

8/26: Deld-A Trojan Downloads Files

Troj/Deld-A is a Trojan for the Windows platform.

8/26: Sacrep-A a Keylogger Trojan

Troj/Sacrep-A is a keylogger Trojan.

8/26: Mytob-JF a Mass-Mailing Worm

W32.Mytob.JF@mm is a mass-mailing worm that opens a back door and lowers security settings on the compromised computer.

8/26: Reatle-I a Mass-Mailing Worm

W32.Reatle.I@mm is a mass-mailing worm that downloads remote files and lowers security settings.

8/25: Downloader-EJD Trojan Installs Bugs

Downloader.EJD is a Trojan that downloads other Trojan to the affected computer from a certain website.

8/25: Reatle-F Worm Spreads Via Email

Worm_Reatle.F propagates via email.

8/25: Zotob-L Worm Exploits Various Flaws

W32.Zotob.L is a worm that opens a back door and exploits various vulnerabilities.

8/25: IRCBot.KN Backdoor Connects to Server

IRCBot.KN is a backdoor that connects to an IRC server in order to receive remote control commands. It can be instructed to search for computers to affect, launch DoS (Denial of Service) attacks, download files, etc.

8/25: Agent-AII Trojan Logs Keystrokes

Agent.AII is a Trojan that logs keystrokes entered by the user while accessing websites whose address contain certain following text strings.

8/25: Allocu-A Worm Uses Buffer Overflow

W32/Allocu-A is a worm for the Windows platform.

8/25: Troj/SDM-C Exploits Access Flaw

Troj/SDM-C is a Trojan for the Windows platform.

8/25: Lebreat-F a Mass-Mailing Worm

W32/Lebreat-F is a mass-mailing worm and backdoor for the Windows platform.

8/25: Backdoor.Mepcod Opens Door

Backdoor.Mepcod is a Trojan horse that opens a back door and downloads a file containing additional commands.

8/24: IRC.Litebot Trojan Opens Back Door

Backdoor.IRC.Litebot is a Trojan horse that opens a back door to a remote IRC server allowing a remote attacker access to the compromised computer and lowers security settings.

8/24: Troj/Whistler-F Deletes Files

Troj/Whistler-F is a destructive Trojan for the Windows platform.

8/24: Mytob-JX Worm in Attachment

Similar to other MYTOB variants, Worm_Mytob.JX propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

8/24: Ruland-A a Mass-Mailing Worm

W32.Ruland.A@mm is a mass-mailing worm that spreads using Microsoft Outlook and downloads a Trojan Horse.

8/24: Kelvir-HI Drops Another Worm

W32.Kelvir.HI is a worm that drops a copy of W32.Spybot.Worm, a family of worms that spreads using the Kazaa file-sharing network and mIRC.

8/24: Backdoor.Mepcod Downloads FIle

Backdoor.Mepcod is a Trojan horse that opens a back door and downloads a file containing additional commands.

8/24: Zotob-K Worm Opens Backdoor

W32.Zotob.K is a worm that opens a back door and exploits the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (as described in Microsoft Security Bulletin MS05-039) on TCP port 445.

8/24: KGBSpy a Hacking Tool

KGBSpy is a hacking tool.

8/24: PrsKey-A a Password-Stealing Worm

W32/PrsKey-A is a password stealing and keylogging worm aimed at the Priston Tale game and Yahoo! web email accounts.

8/24: Troj/Dloader-SK Installs Apps

Troj/Dloader-SK is a Trojan for the Windows platform.

8/24: Tilebot-M a Worm and a Trojan

W32/Tilebot-M is a worm and IRC backdoor Trojan for the Windows platform.

8/23: Nailpol-A Downloads Malicious Code

Troj/Nailpol-A is a Trojan for the Windows platform.

8/23: Zotob-J a Mass-Mailing Worm

W32.Zotob.J@mm is a mass-mailing worm that opens a back door and exploits the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-039), on TCP port 445.

8/23: Guapim Worm Spreads Via IM

W32.Guapim is a worm that spreads through Instant Messenger programs and file-sharing networks.

8/23: Hupigon-BS Takes Commands

Hupigon.BS is a backdoor that receives remote control commands such as logging the keystrokes typed by the user, obtaining files from the affected computer, downloading files to the affected system in order to run them later, capturing screenshots or checking which processes are running and attempts to download files from several domains.

8/23: Fuetel-T Drops Second Backdoor

Fuetel.T is a backdoor that drops another backdoor, detected as Hupigon.BS, to the affected computer.

8/23: Litebot-D Trojan Runs in Background

Troj/Litebot-D is a Trojan for the Windows platform.

8/23: Tixanbot Trojan Gives Remote Control

Backdoor.Tixanbot is a Trojan horse that gives a remote attacker control over the compromised computer.

8/23: Esbot-C Uses Plug-and-Play Flaw

W32.Esbot.C is a worm that spreads by exploiting the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-039), allowing a remote attacker access to the compromised computer.

8/23: PWSteal.Flecsip-B Grabs Passwords

WSteal.Flecsip.B is a password stealing Trojan horse that logs passwords and other confidential data entered by the user onto Internet Explorer Web pages.

8/23: Trojan Adclicker-DF Lowers Security

Trojan Adclicker-DF lowers internet security settings, adds itself to firewall exclusion policies and downloads multiple adwares.

8/23: PurScan-W Trojan Affects Browser

Troj/PurScan-W is a dropper Trojan for the Windows platform that also changes the browser security settings and attempts to open predefined URL.

8/23: Rbot-ALG Worm, Trojan Hits Windows

W32/Rbot-ALG is a worm and IRC backdoor Trojan for the Windows platform.

8/23: Keylog-AM Trojan Eyes Internet Usage

Troj/Keylog-AM is a Trojan DLL that provides keylogging functionality.

8/22: Spybot-UOL Worm has DDoS Ability

W32.Spybot.UOL is a worm that has distributed denial of service and back door capabilities.

8/22: Gaobot-DXO Worm Has Backdoor

W32.Gaobot.DXO is a network-aware worm with back door capabilities that can be controlled through IRC channels and spreads to network shares protected by weak passwords.

8/22: Dref-D Worm Spreads Via IRC

W32/Dref-D is a worm for the Windows platform that spreads via IRC channels and by emailing itself to email addresses harvested from the infected computer.

8/22: Zotob-I Uses Plug-and-Play Flaw

Worm_Zotob.I takes advantage of the Microsoft Windows Plug and Play vulnerability to propagate across networks.

8/22: Spybot-DU Worm and Trojan

W32/Spybot-DU is a worm and IRC backdoor Trojan for the Windows platform.

8/22: Bardus-A Trojan Steals Information

Troj/Bardus-A is a backdoor and keylogging Trojan for the Windows platform.

8/22: Tilebot-B Worm Spreads to Shares

For the second time this month, security vendor Sophos has issued an alert for W32/Tilebot-B, a worm that attempts to spread to remote network shares.

8/22: Troj/Spexta-A Sends Bogus CNN Email

Security vendor Sophos has issued an alert for Troj/Spexta-A, a Trojan for the Windows platform, for the second time this month.

8/19: Demotry-B Worm Scans Network

W32/Demotry-B is a network worm for the Windows platform.

8/19: Troj/Brospy-A a Windows Trojan

Troj/Brospy-A is a Trojan for the Windows platform.

8/19: Troj/ByteVeri-M a Java Applet

Troj/ByteVeri-M is a Java Applet that exploits a vulnerability in the Byte Code Verify component of the Microsoft VM to download and run an executable file.

8/19: Mytob-JU Worm Links to IRC Server

Worm_Mytob.JU propagates by sending a copy of itself as an attachment to email messages using its own Simple Mail Transfer Protocol (SMTP) engine.

8/19: Mytob-JT Worm Uses Own Engine

Worm_Mytob.JT propagates by sending a copy of itself as an attachment to email messages using its own SMTP (Simple Mail Transfer Protocol) engine.

8/19: Backdoor.Darkmoon Trojan Opens Back Door

Backdoor.Darkmoon is a Trojan horse that opens a back door on a compromised computer and has keylogging capabilities.

8/19: Processor a Hacking Tool

Processor is a hacking tool.

8/19: Cmdow-A a Hacking Tool

Cmdow.A is a hacking tool.

8/19: RKPort-Fam Rootkits Hide Information

Troj/RKPort-Fam is a family of kernel-mode driver rootkits.

8/19: Mytob-EE a Worm and a Trojan

W32/Mytob-EE is a mass-mailing worm and backdoor Trojan that can be controlled through the Internet Relay Chat (IRC) network.

8/19: Tilebot-Gen Worms Link to IRC Server

W32/Tilebot-Gen detects IRC backdoor worms of the Tilebot family.

8/19: Dogbot-C Worm Exploits OS Flaws

W32/Dogbot-C is a network worm with IRC backdoor Trojan functionality forogbot-c worm the Windows platform.

8/18: Kassbot-H a Worm and a Trojan

W32/Kassbot-H is a worm and backdoor Trojan for the Windows platform.

8/18: Tilebot-J Worm Spreads to Shares

W32/Tilebot-J is a worm that attempts to spread to remote network shares.

8/18: Zotob-H Uses Plug-and-Play Flaw

W32.Zotob.H is a worm that opens a back door and exploits the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (as described in Microsoft Security Bulletin MS05-039) on TCP port 445.

8/18: Tilebot-I Worm, Trojan Exploits Flaws

W32/Tilebot-I is a worm and IRC backdoor Trojan for the Windows platform.

8/18: Small-NY Trojan Talks With Server

Troj/Small-NY is a Trojan for the Windows platform.

8/17: Esbot-C Worm Hits Plug-and-Play Flaw

Worm_Esbot.C takes advantage of the Microsoft Windows Plug and Play vulnerability to propagate across networks.

8/17: Hwbot-B Worm Connects to Server

W32/Hwbot-B is a network worm for the Windows platform.

8/17: Troj/BagleDl-R Runs New Software

Troj/BagleDl-R is a downloader Trojan that will download, install and run new software without notification that it is doing so.

8/17: Rbot-CBS Worm Uses Windows Bug

Worm_Rbot.CBR takes advantage of the Microsoft Windows Plug and Play vulnerability to propagate across networks.

8/17: Bobax-AD Worm Copies Itself

Worm_Bobax.AD propagates by sending a copy of itself to email addresses harvested from the default address book of the system.

8/17: Zotob-F Worm Opens Backdoor

Several security vendors have issued alerts for W32.Zotob.F, a worm that opens a back door and exploits the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-039) on TCP port 445.

8/17: Zotob-E Worm Uses Port 445

W32.Zotob.E is a worm that opens a back door and exploits the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-039) on TCP port 445.

8/17: Zotob-G Worm Also Opens Backdoor

W32.Zotob.G is a worm that opens a back door and exploits the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-039) on TCP port 445.

8/17: Esbot-B Worm Exploits Plug-and-Play Flaw

W32.Esbot.B is a worm that spreads by exploiting the Microsoft Windows Plug and Play Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-039).

8/17: IRCbot-KC Worm Connects to Many Servers

IRCbot.KC is a worm that connects to several IRC servers in order to receive remote control commands, such as delete, download and run files.

8/17: IRCbot.KD Worm Connects to IP Address

IRCbot.KD is a worm that connects to a certain IP address, acting as a backdoor.

8/17: Bozori.Worm-B Contacts IRC Server

W32/Bozori.worm.b is designed to contact a remote IRC server (IP address is hard-coded in the worm's body - 72.20.41.139 ) to join a channel (#tbp ) and wait for further instructions.

8/17: Tpbot-A Worm Exploits System Flaws

W32/Tpbot-A is a network worm with backdoor Trojan functionality for the Windows platform.

8/17: Tilebot-Z Worm Spreads to Shares

W32/Tilebot-Z is a worm that attempts to spread to remote network shares.