Click here

Malware: Archive: December 2004 

Vioxx Offers Topple Porn for Spam Crown

Is pornography actually taking a back seat online? Seems so... at least when it comes to spam. AOL reports that online medicine offers and phishing scams topped the 2004 spam list.

12/30: Troj/Agent-FO Downloads Files

Troj/Agent-FO is a Trojan for the Windows platform.

12/30: Leebad-B Worm Spreads Via Shares

W32/Leebad-B is a worm for the Windows platform that propagates through the available network shares with the filename system32.exe.

12/30: Bancban-AV Trojan Steals Banking Info

Troj/Bancban-AV is a Trojan for the Windows platform that steals confidential information such as online banking details and sends it to a preconfigured email address.

12/30: RAHack Virus Scans IP Addresses

W32/RAHack is a virus that attempts to exploit Radmin software.

Trojan Threatens XP

Flaw may leave Windows XP vulnerable to attack.

12/30: Chum-A Trojan Uses IRC For Access

Troj/Chum-A is a backdoor Trojan that uses the IRC network to allow an attacker to access the infected computer.

12/30: Generic PWS-B Trojans Steal Passwords

Generic PWS.b is a detection for multiple nondescript password-stealing trojans - typically one-off creations that have been received by McAfee.

New Cabir Variants are Spreading Fast

Code for virus that hits Symbian-based cell phones released.

12/29: Lifefournow Trojan Tests Network

Backdoor.Lifefournow is a backdoor Trojan horse program that allows a compromised computer to be used to reveal and test the configuration of a network.

12/29: Downloader-TO Exploits HTML Flaw

Downloader-TO is a downloader Trojan that is itself downloaded, via an HTA file (named Microsoft Office.hta and is detected with the current DAT files as VBS/Psyme) that is believed to be used in conjunction with a recent Microsoft Internet Explorer HTML Help Control Local Zone Security Restriction Bypass Vulnerability exploit.

12/29: Dedler-H Worm Uses ICQ Functions

W32/Dedler-H is a worm for the Windows platform that attempts to spread using ICQ functionality.

12/29: Perl/Spyski Worm Seeks PHP Servers

The Perl/Spyski.worm detection covers a worm that is based on the idea of the Perl/Santy.worm virus.

12/29: Protoride-B Worm Allows Access

W32.Protoride.B is a worm that spreads through network shares and opens a back door that allows unauthorized access to a compromised computer.

12/29: Symbos_Vlasco-A Infects Cell Phones

Symbos_Vlasco.A is Trojan malware that infects Series 60 mobile phones.

12/29: Spyki-A Worm Targets phpBB

Spyki.A is a worm that affects servers running a version of the application phpBB prior to 2.0.11. phpBB is an open source program used to easily create bulletin boards, forums and newsgroups.

12/29: Forbot-DH an IRC Backdoor and Worm

W32/Forbot-DH is an IRC backdoor and network worm for the Windows platform.

Viruses Crowd Internet in 2004

A banner year for virus writers meant a bad year for Internet users, but much of the damage was preventable.

12/28: HHelp an Exploit for IE Flaw

HHelp is an exploit for a vulnerability in Internet Explorer v6.0 working on Windows XP computers, even with Service Pack 2 installed.

12/28: Reper-A Virus Copies to Disks

W32.Reper.A is a virus that copies itself to the disks on a computer between C: and Z: and adds itself to the autorun.inf file, so that it is started automatically when the disk is inserted.

12/28: Trojan.Phel-A Exploits HTML Flaw

Trojan.Phel.A is a Trojan horse program, which is distributed as an HTML file, and attempts to exploit the Microsoft Internet Explorer HTML Help Control Local Zone Security Restriction Bypass Vulnerability (BID 11467).

12/28: Perl.Lexac Worm Spreads to Servers

Perl.Lexac is a worm that spreads to Web servers running php scripts that are vulnerable to a 'File Inclusion Flaw,' which results from programming errors.

12/28: W97M.Dinela a Macro Virus

W97M.Dinela is a macro virus that attempts to infect the Microsoft Word Normal.dot template file and active documents.

12/27: Worm_Santy-F Targets phpBB Applications

Trend Micro is reporting Worm_Santy.F is rapidly spreading in the wild.

12/27: Troj/Bancos-AS a Password-Stealing Trojan

Troj/Bancos-AS is a password stealing Trojan for the Windows platform.

12/27: Trojan.Phel-A Distributed as HTML

Trojan.Phel.A is a Trojan horse program that is distributed as an HTML file, and attempts to exploit the Microsoft Internet Explorer HTML Help Control Local Zone Security Restriction Bypass Vulnerability (BID 11467).

12/27: Pe_Stream-A a Direct Infector Virus

Pe_Stream.A is a new generation of Windows virus.

12/27: Bkdr_Surila-G a Memory-Resident Worm

Bkdr_Surila.G is a memory-resident backdoor program downloaded into a system by Worm_Mydoom.S, a mass-mailing worm.

12/27: Loadimg-A Trojan an Icon File

Troj_Loadimg.A is Trend Micro's detection for a proof-of-concept icon file that, if loaded, could cause a buffer overflow on the USER32 Library.

12/27: HLP_Exploit are .HLP Files

HLP_Exploit.A is Trend Micro's detection for the proof of concept .HLP files that, if loaded, would cause a buffer overflow on WINHLP32.EXE.

12/27: Santy-B Worm Written in Perl Script

Perl.Santy.B is a worm written in Perl script that attempts to spread to Web servers running versions of the phpBB 2.x bulletin board software prior to 2.0.11.

12/27: Perl.Santy-C Worm Hits Web Servers

Perl.Santy.C is a worm written in Perl script that attempts to spread to Web servers running versions of the phpBB 2.x bulletin board software prior to 2.0.11.

12/27: Agent-ZC Trojan Sends Spam

Troj/Agent-ZC is a Trojan for the Windows platform that can be used for sending unsolicited commercial email (spam) as a result of instructions downloaded from a preconfigured website.

12/23: Keylog-Jingt a Malicious Trojan

Keylog-Jingt is a malicious keylogger Trojan that sends a package originating from China.

12/23: Agobot-OR a Network Worm

W32/Agobot-OR is a network worm with an IRC backdoor component.

12/23: Worm_Beaker-A Spreads Via Email

Worm_Beaker.A arrives and propagates via email.

12/23: Rembot-A Worm Waits for Commands

W32/Rembot-A connects to a predetermined IRC channel and runs in the background waiting for backdoor commands.

In 2005, Organized Crime Will Back Phishers

Phishers proved to be the biggest security threat this year. And analysts say the growth of online organized crime will make it even worse for 2005.

Happy Holidays to Our eSecurityPlanet Readers

A holiday message from eSecurityPlanet...

12/22: Rbot-SD Worm, Trojan Uses Passwords

W32/Rbot-SD is a network worm and IRC backdoor Trojan for the Windows platform.

12/22: Sapattra a Macro Virus

W97M.Sapattra is a macro virus that infects Microsoft Word documents and the Normal.dot template.

12/22: Santy-A Worm Attacks Bulletin Boards

Several security vendors continue to issue alerts for Perl/Santy-A, a worm that exploits a vulnerability in the phpBB bulletin board software.

12/22: Randex-CCF Worm Opens Backdoor

W32.Randex.CCF is a network-aware worm that opens a backdoor on an infected computer and may be remotely controlled via IRC channels.

Santy-A Worm Raises Fears Over New Trend

The Santy-A worm, which shows off the first automated Google hacking, has security analysts bracing for a whole new trend.

12/22: Mkar-E Virus Infects EXE Files

W32/Mkar-E is a virus that infects EXE files.

Securing Data on Your Old, Dead Servers

Server disposal can be a weak link in enterprise data security. Don't forget to scrub them... and then maybe take a hammer to them.

12/21: Santy Worm Infects Web Servers

A new worm Santy has started spreading that infects only web servers, not end user computers.

12/21: Banedi Macro Virus Infects Word

W97M.Banedi is a macro virus that infects the Microsoft Word Normal.dot template and is triggered when a Word document is opened or closed.

12/21: Lateda Trojan Takes Commands

Backdoor.Lateda is a backdoor Trojan horse program that allows an attacker to download and run files on the infected machine.

12/21: Bancban-AN Trojan Steals Bank Info

Troj/Bancban-AN is a data stealing Trojan that attempts to capture confidential information related to internet banking, such as usernames and logon passwords.

12/21: Rbot-SB a Network Worm & Trojan

W32/Rbot-SB is a network worm and IRC backdoor Trojan for the Windows platform.

12/21: Rbot-RY Worm Hits Weak Shares

W32/Rbot-RY is a Windows network worm that spreads to weakly protected network shares and computers vulnerable to the RPC-DCOM exploit (see Microsoft Security Bulletin MS04-012).

12/20: Oddbob-A a Network Worm

W32/Oddbob-A is a network worm for the Windows platform.

12/20: Pulkfer Virus Infects .Exe Files

W32.Pulkfer is virus that infects .exe files in the folder where it is executed from.

12/20: Netdepix Worm Scans IP Addresses

W32.Netdepix is a worm that attempts to exploit the Microsoft Windows LSASS Buffer Overrun Vulnerability (Microsoft Security Bulletin MS04-011).

12/20: Grurev Macro Virus Infects Word

W97M.Grurev is a simple Macro virus that infects Microsoft Word's Normal.dot template.

12/20: PEQ a Generic VB Worm

W32.PEQ@mm is a generic Visual Basic worm that spreads by sending a copy of itself to email addresses gathered from the Microsoft Outlook Address Book.

12/20: Mugly-C Worm Uses Own SMTP Engine

W32.Mugly.C@mm is a worm that uses its own SMTP engine to spread by sending itself as an email attachment to addresses gathered from the compromised computer.

12/20: Looked Worm Infects .Exe Files

W32.Looked is a worm that propagates through shared folders, downloads a file, and infects .exe files.

12/20: Rbot-RW a Worm and IRC Trojan

W32/Rbot-RW is a network worm and IRC backdoor Trojan for the Windows platform.

12/20: Netdepix Trojan Exploits Buffer Overrun

Trojan.Netdepix is a Trojan horse program that attempts to exploit the Microsoft Windows LSASS Buffer Overrun Vulnerability (Microsoft Security Bulletin MS04-011) on randomly selected computers.

12/20: Tabdim Trojan Lets Hacker In

Backdoor.Tabdim is a Trojan horse program that opens a backdoor and allows a remote attacker to control the infected computer.

12/20: Sdbot-SI Worm also a Backdoor

W32/Sdbot-SI is a network worm and backdoor for the Windows platform.

12/20: Wort-D Worm Exploits LSASS Flaw

W32/Wort-D is a network worm that attempts to spread to remote computers by exploiting the LSASS vulnerability (MS04-011).

How Spyware Took the Next-Gen Threat Crown

Now that spyware has managed to draw the ire of corporate IT departments, we take a look at why it's still an uphill battle for both businesses and home users alike. At least for now...

Redmond Moves Unnerve McAfee Investors

Shares of McAfee sank Monday after Microsoft made its second move against the security company in a week.

CAN-Spam Act a Success... at Helping Spammers

Columnist Ray Everett-Church says very few think the CAN-Spam Act has been successful in stopping spam. But it has been successful in helping spammers fill your inboxes.

12/17: Atak.J Worm Uses Own Engine

W32/Atak.j@MM is another variant of the Atak worm family.

12/17: Envid-B Worm Steals Outlook Contacts

W32.Envid.B@mm is a worm that sends email to all addresses found in the Microsoft Outlook Address Book.

12/17: Forbot-DA Worm Targets Flaws

W32/Forbot-DA is a worm that attempts to spread to remote network shares and computers vulnerable to common exploits.

12/17: Forbot-EQ an IRC Trojan and Worm

W32/Forbot-EQ is an IRC backdoor Trojan and network worm for the Windows platform.

12/17: Delf-JB Virus Terminates Processes

W32/Delf-JB is a virus for the Windows platform.

Symantec, Veritas Marriage Gets Mixed Reviews

Analysts discuss Symantec's $13.5 billion proposal for Veritas, and rival EMC throws cold water on the deal.

12/16: Forbot-BI an IRC Trojan and Worm

W32/Forbot-BI is an IRC backdoor Trojan and network worm for the Windows platform.

12/16: Rbot-RR Worm Hits Remote Shares

W32/Rbot-RR is a worm that attempts to spread to remote network shares.

12/16: Atak-F Worm Collects Addresses

W32.Atak.F@mm is a mass-mailing worm that sends itself to addresses collected from the infected computer.

12/16: VBS.Sorpe-B Worm Disables Utilities

VBS.Sorpe.B@mm is a mass-mailing worm that sends itself to the email addresses gathered from the files on an infected computer.

12/16: VBS.Feadfe Worm Mails Itself

VBS.Feadfe@mm is a mass-mailing worm that sends itself to email addresses it finds in the Microsoft Outlook Address Book.

12/16: Ginena a Macro Virus

W97M.Ginena is a macro virus that infects the Microsoft Word Normal.dot template and is triggered when a Word document is opened, closed, or saved.

Zafi-D Worm Infecting 1 Out of 10 Emails

The Zafi-D worm, which hit the Wild with great speed this past Monday, is infecting one out of every 10 emails traveling the Internet, according to anti-virus reports.

12/16: VBS.Sorpe-A a Mass-Mailing Worm

VBS.Sorpe.A@mm is a mass-mailing worm that sends itself to email addresses gathered from files on the infected computer.

Symantec to Buy Veritas for $13.5B

UPDATED: The marriage of Symantec and Veritas would form one of the largest security and back-up software powers in the market.

12/15: Atak-H Worm's 'Christmas Greetings'

Atak.H is a worm without destructive effects that spreads via e-mail in messages with variable characteristics that pass themselves off as Christmas greetings.

12/15: Protoride-Z Worm Copies Itself

W32/Protoride-Z is a Windows worm that spreads via network shares.

12/15: Forbot-CY Worm Spreads Via Shares

W32/Forbot-CY is a network worm that attempts to spread via network shares.

12/15: Agobot-DAA an IRC Backdoor, Worm

W32/Agobot-DAA is an IRC backdoor and network worm.

12/15: Erkez-D a Mass-Mailing Worm

W32.Erkez.D@mm is a mass-mailing worm that sends itself to email addresses gathered from the infected computer.

12/15: Atak-I an Email Worm

W32/Atak.i@MM is a worm that bears several characteristics.

12/14: Worm_Bagz-I Spreads Via Email

Worm_Bagz.I is a memory-resident worm that arrives and propagates through email.

12/14: Worm_Rbot-AEF Arrives as File

Worm_Rbot.AEF arrives as the file WIN23UPD.EXE on affected machines.

12/14: Trojan.Conycspa Downloads Programs

Trojan.Conycspa is a Trojan horse program that downloads and executes adware, dialers, and spamming Trojan horse programs from the Internet.

12/14: Backdoor.Ranky-N Acts as Covert Proxy

Backdoor.Ranky.N is a backdoor program that allows a compromised computer to be used as a covert proxy.

12/14: Atak-G a Windows Worm

W32/Atak-G is a Windows worm that spreads via email.

12/14: Qeds Worm Sends Itself as Attachment

W32.Qeds@mm is a mass-mailing worm that sends a copy of itself as an attachment to the email addresses that it gathers from the files on an infected computer.

12/14: Zafi-D Worm Disguised as E-Greeting

Several vendors have issued alerts for Zafi.D, a worm that ends the active processes whose name contains the text strings firewall or virus.

New Zafi-D Worm Spreads Christmas Fear

The latest variant in the Zafi worm family has hit the Wild, disguising itself as a Christmas greeting. Discovered on Dec. 13, the worm already has earned 'medium threat alert' status.

12/14: Sdbot-SG Worm Has Trojan Functions

W32/Sdbot-SG is a worm with backdoor Trojan functionality.

12/13: Sdbot-SB Worm Has Backdoor

W32/Sdbot-SB is a member of the W32/Sdbot family of worms with a backdoor component.

12/13: Atak-F Worm Spreads Via Email

W32/Atak-F is a Windows worm that spreads via email.

12/13: Rbot-RN a Network Worm

W32/Rbot-RN is a network worm that attempts to spread via network shares.

Netsky-P Biggest Threat of 2004

Netsky-P, first discovered March 22, has deftly used social engineering tricks to continually rank it as one of the most dangerous worms in the wild.

12/13: VBS.Junkmail a Mass-Mailing Worm

VBS.Junkmail@mm is a generic VBS mass-mailing worm that copies itself to files on the C drive of the infected computer.

12/13: Brabot-A a Backdoor Trojan

Troj/Brabot-A is a backdoor Trojan that accepts commands via IRC.

12/13: Janx Worm Exploits Windows Flaw

W32.Janx is a worm that attempts to exploit the Microsoft Windows LSASS Buffer Overrun Vulnerability (Microsoft Security Bulletin MS04-011).

Author of Zafi-B Worm Trailed to Hungary

The search for the author of the fourth most wide-spread bug on the Internet has led authorities to Hungary.

12/10: JS.Speth Worm a Java Script File

JS.Speth.Worm is a Java Script file that copies itself throughout the C drive of the infected computer.

12/10: Bagle-BF a Mass-Mailing Worm

W32/Bagle.bf@MM is a virus that is simply a repackaging of W32/Bagle.aa@MM.

12/10: Bagle-BG Arrives in Zip File

W32/Bagle.bg@MM is a new email worm that arrives by email in a password protected zip file.

12/10: Agobot-NX an IRC Trojan & Worm

W32/Agobot-NX is an IRC backdoor Trojan and network worm that is capable of spreading to computers on the local network protected by weak passwords.

12/10: Bagle-AA an Email-Aware Worm

W32/Bagle-AA is an email aware worm, and a member of the W32/Bagle family of worms.

2004: A Year of Phishing and Netsky Attacks

This was a turbulent year of viruses, phishing attacks and bank-robbing Trojans. And it was a lot for IT and security managers to have to suffer through.

12/9: Gaobot-BUU a Network-Aware Worm

W32.Gaobot.BUU is a network-aware worm that has backdoor capabilities and can be controlled through IRC channels.

12/9: AdClicker-BP a Screensaver App

AdClicker-BP is an application type for 'potentially unwanted programs,' it is not a virus.

12/9: Anig-C Worm Copies Itself Over Network

32/Anig-C is a worm that can spread by copying itself over network shares.

12/9: Setclo-A Worm Carries Executable

W32/Setclo-A is a network worm for the Windows platform.

12/9: Maslan-A Worm Gives Attacker Access

Some security vendors have issued alerts for W32.Maslan.A@mm, a worm that uses mass-mailing, exploits, password-stealer, and rootkit techniques.

12/8: Maslan-C Worm Spreads By Email

W32/Maslan-C is worm that spreads by emailing itself to addresses found on the infected computer.

12/8: Rbot-RJ Worm Spreads to Shares

W32/Rbot-RJ is a worm that attempts to spread to remote network shares.

12/7: Agent-BF a Downloading Trojan

Troj/Agent-BF is a downloading Trojan for the Windows platform that attempts to download and run a program from a remote location.

12/7: Banker-BG Trojan Targets Brazilian Banks

Troj/Banker-BG is a password stealing Trojan aimed at customers of Brazilian banks.

Locking Up All of That 'Free Information'

The open source community goes with the saying, ''Information wants to be free''. But does free necessarily mean safe? And how do you safely lock it down?

12/7: Rbot-RF a Network Worm and Trojan

W32/Rbot-RF is a network worm and IRC backdoor Trojan for the Windows platform.

12/6: Atak-E Worm Harvests Email Addresses

Some vendors have issued alerts for W32/Atak.e@MM, a new variant of the W32/Atak worm.

12/6: Rbot-RC an IRC Trojan and Worm

W32/Rbot-RC is an IRC backdoor Trojan and network worm.

12/6: Rbot-RE Worm Targets Weak Passwords

W32/Rbot-RE is an IRC backdoor Trojan and network worm.

12/6: Trojan Wlogo Exploits IE Flaw

Trojan.Wlogo exploits the Microsoft Internet Explorer Malformed IFRAME Remote Buffer Overflow Vulnerability (described in the Microsoft Security Bulletin MS04-040) to download and execute a remote file.

12/6: Trojan Frutca Hides Files

Trojan.Frutca is a Trojan Horse program that hides files on the compromised computer and sends out information to remote server.

12/6: Atak-B a Mass-Mailing Worm

W32.Atak.B@mm is a mass-mailing worm that uses its own SMTP engine to send its messages to the email addresses it gathers from certain files on a compromised computer.

12/3: Netsky-Z@mm!enc Detects Netsky

W32.Netsky.Z@mm!enc is an .enc detection for MIME-encoded files that contain the W32.Netsky.Z@mm worm.

12/3: Atak-D an Email Worm

W32/Atak.d@mm is a worm that bears certain characteristics.

12/3: Rbot-QX a Worm and IRC Trojan

W32/Rbot-QX is a network worm and IRC backdoor Trojan for the Windows platform.

12/3: Rbot.Add Worm Uses Windows Flaw

Worm_Rbot.Add spreads via network shares.

12/2: Anzae a Mass-Mailing Worm

W32/Anzae.worm.gen is a generic detection for the W32/Anzae.worm family of viruses.

12/2: Agobot-OH Worm Has Backdoor Functions

W32/Agobot-OH is a worm with backdoor functionality that spreads to computers protected by weak passwords.

12/2: Agobot-OL Worm Targets Passwords

W32/Agobot-OL is a worm with backdoor functionality that spreads to computers protected by weak passwords.

12/2: Aidid Virus Overwrites A Drive Files

W32.Aidid is a virus that overwrites all files in the A drive with a copy of itself.

12/2: QLowZones-4 Trojans Attack IE

QLowZones-4 is a detection that covers multiple Trojans, all of which have the same standard characteristics.

12/2: JS.Kidrash a Java Script Program

JS.Kidrash is a Java Script program that adds random garbage data to .html and .js files.

Sober-I Hits Hard, Nears Nov. Title Spot

Sober-I is giving Netsky-P some competition when it comes to the title of Worst Virus on the Internet.

Fighting to Keep Smut-Spam in a Brown Wrapper

Microsoft brings seven new lawsuits against smut-peddling spammers under the CAN-SPAM law.

12/1: pcAudit a Spyware Program

pcAudit is a spyware program, which is developed by a private company in order to test the security level in a computer.

12/1: Wurmark-A a VB Mass-Mail Worm

W32/Wurmark-A is a Visual Basic mass-mailing worm.

12/1: Agobot-NX a Backdoor Trojan & Worm

W32/Agobot-NZ is a backdoor Trojan and worm that spreads to computers protected by weak passwords.

12/1: Salga-A Worm Uses Outlook Contacts

W32.Salga.A@mm is a mass-mailing worm that uses Microsoft Outlook to send itself to all the email addresses that it finds in the Outlook Address Book.

12/1: PWS-Banker.D Trojan Targets E-Gold

PWS-Banker.D is a detection for several password-stealing trojans - typically those targeted at E-Gold account holders.

Report: Spyware a Critical Security Threat

Spyware has become the fourth-greatest threat to a company's security, propelling the anti-spyware market from $12 million last year to $305 million by 2008.

HP Targets Viruses in Security Initiative

Following up on its enterprise offerings, HP puts new products out to fight viruses.

12/1: Iframebof-B a Malicious HTML File

HTML_Iframebof.B is a malicious HTML file that exploits a known IFRAME vulnerability affecting Microsoft Internet Explorer and enables the execution of arbitrary codes on affected machines.

12/1: PWSteal.Tarno-K Trojan Grabs Passwords

PWSteal.Tarno.K is a Trojan horse program that attempts to steal passwords and log information entered into Web forms.