Click here

Articles by eSecurityPlanet.com Staff 

5/29: Runfer.OA Worm Drops Files, Modifies Registry

W32/Runfer.OA is a worm that will infect Windows systems.

5/29: Agent.GMO Trojan Drops Files, Modifies Registry

W32/Agent.GMO is a Trojan that will infect Windows systems.

5/29: Mal/Bifrose-A a Family of Backdoor Trojans

Mal/Bifrose-A is a family of backdoor Trojans.

5/29: Linux/Rst-B Virus Attempts to Infect ELF Executables

Linux/Rst-B is a virus that will attempt to infect all ELF executables in the current working directory and the directory /bin.

5/29: SWF_Dloader.ZTS a Malicious Shockwave Flash Object

SWF_Dloader.ZTS is malicious Shockwave Flash (.SWF) object that arrives on a system as a downloaded file from remote sites by JS_AGENT.AINS.

5/29: Autorun.worm.cw Copies Itself to Root of Disk Drives

W32/Autorun.worm.cw attempts to copy itself to the root of any accessible disk drive.

5/29: HTML_Dldr.BF HTML May be Unknowingly Downloaded

HTML_Dldr.BF is HyperText Markup Language (HTML) that may be hosted on a Web site and run when a user accesses the said Web site.

5/28: SWF_Dloader.YVM .SWF Object Arrives as Attachment

SWF_Dloader.YVM is a malicious Shockwave Flash (.SWF) object that arrives on a system as attachment to email messages spammed by another malware or a malicious user.

5/28: SWF_Dloader.YVN Specially Crafted .SWF File Exploits Flaw

SWF_Dloader.YVN is a malicious Shockwave Flash (.SWF) object that may be downloaded by SWF_DLOADER.YVM.

5/28: SWF_Dloader.ZHU a Malicious Shockwave Flash Object

SWF_Dloader.ZHU is a malicious Shockwave Flash (.SWF) object that arrives on a system as a downloaded file from remote sites by JS_AGENT.AINS.

5/28: Downloader.Swif.C Trojan Exploits Flash Player Flaw

Downloader.Swif.C is a Trojan horse that exploits the Adobe Flash Player SWF File Unspecified Remote Code Execution Vulnerability (BID 29386) in order to download more malware on to the compromised computer.

5/28: SillyFDC-AP Worm Drops, Installs, Runs New Software

W32/SillyFDC-AP is a worm for the Windows platform.

5/28: Autorun-EL Worm Copies Itself to Available Drives

W32/Autorun-EL is a worm that when run, copies itself to (System)/sys.vbs and also copies itself to all available drives to the file (Root)/sys.vbs.

5/28: SWFdldr-A Trojan Tries to Download, Run Malicious Code

Troj/SWFdldr-A is a Trojan that attempts to download and run further code from the internet via a malicious Flash file.

5/28: Trafaret.A Worm Copies Itself, Drops Other Malware

W32/Trafaret.A is a worm that will infect Windows systems.

5/28: Emsenush.A Worm Spreads Via Windows IM Clients

W32.Emsenush.A is a worm that spreads through Windows instant messaging clients.

5/28: SWFexp-B Trojan Targets Flaw to Run More Malware

Troj/SWFexp-B is a Trojan that exploits a currently unknown vulnerability in Adobe Flash Player to download and run further malware from the internet.

5/28: Mal/Dorf-E Trojan a Malicious Program

Mal/Dorf-E Trojan is a malicious program.

5/28: Pushdo-K Trojan Sends Spam Mail

Troj/Pushdo-K Trojan has been seen being spammed out in emails.

5/28: SWFExp-A Trojan Exploits Adobe Flash Player Flaw

Troj/SWFExp-A is a Trojan that exploits a currently unknown vulnerability in Adobe Flash player to download and run further malware from the internet.

5/27: MancSyn-H Trojan Copies Itself, Creates Registry Entry

Troj/MancSyn-H is a Trojan for the Windows platform.

5/27: FakeAle-BO Trojan Claims to Detect Spyware on Systems

Troj/FakeAle-BO claims to detect numerous examples of spyware on the user's computer for which removal costs a one-time fee of $49.95.

5/27: Mal/ExpJS-H Malicious Web Page Exploits Client-Side Flaws

Mal/ExpJS-H is a malicious web page intended to exploit client-side vulnerabilities in order to download and execute other malicious content.

5/27: Sohanad.BH Worm Spreads Via Email

W32/Sohanad.BH is a worm that will infect Windows systems and spreads through email.

5/27: Trojan.Spryct Drops FIles on Compromised System

Trojan.Spryct is a Trojan horse that may download files on to the compromised computer.

5/27: Dwnldr-HDP Trojan Drops File From Preconfigured URL

Troj/Dwnldr-HDP is a Trojan downloader for the Windows platform.

5/27: Troj/Dwnldr-HDO a Downloader Trojan

Troj/Dwnldr-HDO is a Trojan downloader for the Windows platform.

5/27: Bckdr-QNN Trojan Gives Intruder Remote Access

Troj/Bckdr-QNN is a backdoor Trojan for the Windows platform, which allows a remote intruder to gain access and control over the computer.

5/27: Agent-GZH Trojan Copies Itself, Creates Registry

Troj/Agent-GZH is a Trojan for the Windows platform.

5/23: NtRootK-DM Rootkit Trojan Targets Windows Systems

Troj/NtRootK-DM is a rootkit for the Windows platform.

5/23: Zlob.NEB Trojan Displays Fake Pop-Up Message

W32/Zlob.NEB is a Windows systems Trojan that upon execution, drops scm.exe in the folder from which the original file is executed.

5/23: Nitfun-A Trojan Downloads, Executes More Files

Troj/Nitfun-A is a Trojan that attempts to download and execute further files.

5/23: Mdrop-BSM Trojan Creates File

Troj/Mdrop-BSM is a Trojan for the Windows platform.

5/23: VB-DZS Trojan Copies Itself, Creates File and Registry Entry

Troj/VB-DZS is a Trojan for the Windows platform.

5/23: NtRootK-DN a Windows Rootkit Trojan

Troj/NtRootK-DN is a rootkit Trojan for the Windows platform.

5/22: Privacy-A Trojan Reduces Internet Privacy Level

Troj/Privacy-A reduces the Internet Zone privacy level to low (accept all cookies).

5/22: FakeAle-BL Trojan Claims to Have Found Threats

Troj/FakeAle-BL claims to have found security threats.

5/22: NtRootK-DL a Windows Kernel Drives Trojan

Troj/NtRootK-DL is a kernel driver Trojan for the Windows platform which attempts to silently sniff network traffic.

5/22: NtRootK-DK a Windows Rootkit Trojan

Troj/NtRootK-DK is a rootkit Trojan for the Windows platform.

5/22: Mbroot-Gen a Family of Trojan Rootkit Files

Troj/Mbroot-Gen is a family of Trojan rootkit files, usually seen dropped by members of the Troj/Mbroot or Mal/Sinowa family of malware.

5/22: IRCBot-ABT Trojan Runs Continuously in Background

Troj/IRCBot-ABT Trojan runs continuously in the background, providing a backdoor server that allows a remote intruder to gain access and control over the computer via IRC channels.

5/22: Bckdr-QNP Trojan Registers Itself as New System Driver Service

When first run Troj/Bckdr-QNP Trojan copies itself to System\ntsasvc.exe.

5/21: Volume-A Worm Tries to Create Files When Run

W32/Volume-A worm attempts to create the files on any available drive when run.

5/21: VKon-A Worm Spreads Via Social Networking Site

W32/VKon-A worm spreads using the social networking site Vkontakte.ru.

5/21: Tiotua-Q Trojan Contains Embedded .Exe File for Spyware Functions

W32/Tiotua-Q is a Trojan for the Windows platform.

5/21: Agent.LPY a Windows Systems Trojan

W32/Agent.LPY is a Windows systems Trojan.

5/21: PSWSys-Gen Kernel Driver Records Keystrokes

Troj/PSWSys-Gen is a kernel driver that attempts to record keystrokes silently.

5/21: Bckdr-QNO Trojan Installs Files, Creates Registry Entries

Troj/Bckdr-QNO is a Trojan for the Windows platform.

5/21: Mal/EncPk-DX Program Used by Malware Authors

Mal/EncPk-DX is a program packed with a protection system typically used by malware authors.

5/21: FakeAle-BK Trojan Creates File When Installed

Troj/FakeAle-BK is a Trojan for the Windows platform.

5/21: NtRootK-DJ a Rootkit Trojan

Troj/NtRootK-DJ is a rootkit Trojan for the Windows platform.

5/21: Pws-Gina Password-Stealing Trojan Targets User Credentials

Pws-Gina is a password-stealing Trojan designed to steal the credentials of logged in windows user.

5/21: BackDoor-DPE Trojan Copie and Registers Itself

BackDoor-DPE Trojan is known to have been used in an attack involving Whitehouse.org.

5/20: Zbot-S Trojan Creates File, Changes Registry Entry

Troj/Zbot-S is a Trojan for the Windows platform.

5/20: Bancos-BEB Trojan Copies Itself, Creates Temp File

Troj/Bancos-BEB is a Trojan for the Windows platform.

5/20: Mal/ObfJS-AP an Obfuscated Script

Mal/ObfJS-AP is a script obfuscated in a manner typical of malware.

5/20: Mal/Badsrc-B a Compromised, Malicious Web Page

Mal/Badsrc-B is a malicious web page that has been compromised to load a script from a malicious website.

5/20: AntiVirusPro.A.FraudTool Trojan Displays Fake Warning

W32/AntiVirusPro.A.FraudTool is a Trojan that will infect Windows systems.

5/20: DisaCKT.B Worm Makes Several Registry Modifications

DisaCKT.B is a worm that carries out several modifications in the Windows Registry, which prevents the user from carrying out the following actions.

5/20: Dorf-BK Trojan Creates Registry Upon Installation

When first run Troj/Dorf-BK Trojan copies itself to Windows\herjek.exe.

5/20: Adload-LN Trojan Copies Itself, Creates File

When first run Troj/Adload-LN Trojan copies itself to Windows\livemessenger.com and creates the file Windows\admintxt.txt, which can be safely deleted.

5/20: Baklajan Parasitic Virus Infects PE Executable Files

W32/Baklajan is a parasitic virus that infects Win32 PE executable files.

5/19: Small.Nn.Proxy Trojan Infects Windows Systems

W32/Small.Nn.Proxy is a Trojan that will infect Windows systems.

5/19: Agent-GZQ Trojan Copies Itself, Drops Files

Troj/Agent-GZQ when run copies itself to (Profile)\Local Settings\Temp\tru7.tmp.

5/19: Mal/Encpk-DU File Used by Malware Authors

Mal/EncPk-DU is a file packed with a protection system typically used by malware authors.

5/19: Tilebot-KV Trojan Contacts Remote Server Via Http

W32/Tilebot-KV Trojan runs continuously in the background, providing a backdoor server that allows a remote intruder to gain access and control over the computer.

5/19: IRCBot-ABR Trojan Gives Remote Intruder System Control

Troj/IRCBot-ABR is a backdoor Trojan that allows a remote intruder to gain access and control over the computer.

5/19: Banker-ELS Trojan Modifies Windows HOSTS File

Troj/Banker-ELS Trojan modifies the Windows HOSTS file in order to redirect the user from a genuine online banking site to a phishing site.

5/19: NtRootK-DI a Windows Rootkit Trojan

Troj/NtRootK-DI is a rootkit Trojan for the Windows platform.

5/19: Agent-GYS Trojan Drops Files in Temp Folder

When run Troj/Agent-GYS Trojan drops three files in the Temp folder.

5/19: Agent-GZL Trojan Downloads Files, Steals Info

Troj/Agent-GZL is a Trojan for the Windows platform.

5/16: Shark.BZP Trojan Drops Files, Modifies Registry

W32/Shark.BZP is a Trojan that upon execution drops zlib.dll and mswinsck.ocx in Windows System folder.

5/16: Zapchas-EA Trojan Drops Files

Troj/Zapchas-EA is a backdoor IRC Trojan.

5/16: Agent.AORZ Trojan May be Manually Installed

Troj_Agent.AORZ Trojan may be installed manually by a user.

5/16: Alureon.AI Trojan Dropped by Other Trojan

Troj_Alureon.AI Trojan is dropped by TROJ_ZLOB.CCW, another Trojan that drops files on the affected system.

5/16: Trojan.Cymdos Performs DoS Attacks

Trojan.Cymdos is a Trojan horse that performs denial of service attacks.

5/16: Moozye Worm Spreads Via Removable Files

W32/Moozye is a worm that attempts to spread to removable drives by creating an Autorun.inf file, which will run the worm automatically, if systems which use the removable drive are set to Autorun.

5/15: Dloadr-BLS Trojan Downloads Malware to Various Files

Troj/Dloadr-BLS Trojan downloads malware when run.

5/15: Agent-GZM Trojan Copies Itself to System Folder

Troj/Agent-GZM when run copies itself to the (System) folder as kd???.exe.

5/15: Mal/ObfJS-AO Script Appears to be Malware

Mal/ObfJS-AO is a script obfuscated in a manner typical of malware.

5/15: Mal/Dbot-A File Acts Like Backdoor Trojan

Mal/Dbot-A is a file with behavioral characteristics typical of backdoor Trojans.

5/15: Sohana-AY Worm Contacts Remote Server Via HTTP

W32/Sohana-AY is a worm for the Windows platform.

5/15: FakeAle-BI Trojan Sets Registry Entry

Troj/FakeAle-BI is a Trojan for the Windows platform.

5/15: Mal/ObfJS-Y Malware for Malicious Scripts

Mal/ObfJS-Y is malware for malicious scripts that use obfuscation to load other malicious content.

5/15: Sality.n Parasitic Virus Infects PE Executable Files

W32/Sality.n is a parastic virus that infects W32 PE executable files.

5/15: Danmec Trojan Searches Google for .ASP Pages

Danmec Trojan upon execution will search Google for .asp pages and attempts to compromise websites by launching a SQL injection attack.

5/15: Stubbot.worm Malware Drops File

W32/Stubbot.worm is a network aware worm that attempts to replicate across existing networks.

5/15: Tahun.worm Replicates Across Existing Networks

W32/Tahun.worm is a network-aware worm that is capable of replicating across existing networks through open network shares and removable storage media.

5/14: Trojan.Installscash Exploits Media Player Flaw

Trojan.Installscash is a Trojan horse that exploits the Microsoft Windows Media Player Plugin Buffer Overflow Vulnerability (BID 16644) in order to download files on to the compromised computer.

5/14: Agent-GZK Trojan Tries to Edit Websites

Troj/Agent-GZK attempts to edit websites to promote a target website.

5/14: Psyme-GZ Trojan Exploits Flaw to Download, Run Files

Troj/Psyme-GZ is a Trojan for the Windows platform.

5/14: Zlobar-B Trojan Claims to be Media Codec Installers

Troj/Zlobar-B detects installation archives containing Zlob Trojans.

5/14: MalDoc-H a Corrupt Excel Document

Troj/MalDoc-H is a corrupt Excel document containing malicious executable code.

5/14: Dorf-BI Trojan Copies Itself to Windows

When first run Troj/Dorf-BI Trojan copies itself to Windows\kavir.exe.

5/14: Mal/Hupig-E Detects Malware Behavior

Mal/Hupig-E detects behavior associated with known malware.

5/14: Generic FakeAlert.a Trojan Installs Antivirus Software

Generic FakeAlert.a is a Trojan that will silently install Antivirus2008 and run a virus scan on the system.

5/14: Mal/Iframe-D a Compromised Web Page

Mal/Iframe-D is a web page that has been compromised to load malicious content from a remote server.

5/14: Spy-Agent.bg Trojan Captures Information

Spy-Agent.bg Trojan is designed to capture information from the victim machine and send them to the remote site.

5/13: Dloadr-BBA Trojan Downloads Malware

Troj/Dloadr-BBA is a Trojan that when run downloads malware.

5/13: Banspy-F a .Net Application That Steals Info

Troj/Banspy-F is a .net application that steals personal information from Brazilian banking sites.