Click here

Malware: Archive: April 2005 

4/29: Mydoo-BL Worm Uses Own Engine

W32.Mydoom.BL@mm is a mass-mailing worm that uses its own SMTP engine to send itself to the email addresses that it finds on an infected computer.

4/29: Francette-R Worm Uses Buffer Overflow

Worm_Francette.R usually arrives by exploiting the RPC DCOM Buffer Overflow vulnerability, which allows an attacker to gain full access and execute any code on a target machine.

4/29: Lingosky Trojan Opens Backdoor

Backdoor.Lingosky is a Trojan horse that opens a back door and allows the compromised computer to be used as a covert proxy.

4/29: Kelvir-AX Trojan Links to IM Contacts

W32.Kelvir.AX is a Trojan that sends a message to all MSN messenger contacts on the compromised computer.

4/29: MyDoom-BN Worm Opens Notepad

W32/MyDoom-BN is a member of the W32/MyDoom family of email worms.

4/29: Bropia-AJ Worm Messages IM Users

W32/Bropia.worm.aj is a threat similar to both the W32/Bropia and W32/Kelvir worm families.

4/29: Kelvir-D an IM Worm

W32/Kelvir-D is an instant messenging worm that spreads by sending a message through Windows Messenger to all of an infected user's contacts.

4/29: Banish-A Worm Exploits LSASS Flaw

Some security vendors have issued alerts for the Banish-A mass-mailing worm, which may take advantage of the LSASS vulnerability.

4/28: Gaobot-DEY Worm Hinders Security

W32.Gaobot.DEY is a network-aware worm with back door capabilities that spreads to network shares protected by weak passwords and can be controlled through IRC channels.

4/28: Mydoom-AQ Worm Uses SMTP

Worm_Mydoom.AQ uses its own Simple Mail Transfer Protocol (SMTP) to propagate.

4/28: Allim-B Worm Spreads Via AIM

W32.Allim.B is a worm that spreads through America Online Instant Messenger (AIM) and drops a variant of Backdoor.Sdbot.

4/28: Netsky-AI Worm Uses SMTP Engine

W32.Netsky.AI@mm is a mass-mailing worm that uses its own SMTP engine to send itself to email addresses it gathers from certain files on the compromised computer, and copies itself to mapped network drives.

4/28: Lingosky Trojan Opens Backdoor

Backdoor.Lingosky is a Trojan horse that opens a back door and allows the compromised computer to be used as a covert proxy.

4/28: Mytob-BT Worm/Trojan Uses Flaws

W32/Mytob-BT is a mass-mailing worm and backdoor Trojan that can be controlled through the Internet Relay Chat (IRC) network.

4/28: Banker-NL Trojan Logs Keystrokes

Banker.NL is a Trojan that logs keystrokes entered when the user accesses web addresses that contain certain text strings, mainly belonging to banking entities.

4/28: Kelvir-AW Worm Sends Message

W32.Kelvir.AW is a worm that downloads a file and sends a message to all MSN messenger contacts on the compromised computer.

4/28: Ahker-H Worm Spreads By Email

Worm_Ahker.H propogates via email.

4/28: Vundo-B Trojan Drops Adware

Trojan.Vundo.B is a Trojan horse that is designed to drop Adware onto a compromised system.

4/27: Kassbot-C Worm Has Backdoor Component

W32/Kassbot-C is a network worm with a backdoor component.

4/27: Nopir-A Worm Deletes Certain Files

Nopir.A is a worm that deletes all the files with a COM or MP3 extension from the affected computer.

4/27: Nopir-B Worm Spreads Via Peer-to-Peer

Worm_Nopir.B propagates via peer-to-peer networks.

4/27: Scold-C Worm Copies Itself Via Email

Like earlier WORM_SCOLD variants, Worm_Scold.C spreads by sending copies of itself to email addresses, which are gathered from Microsoft Outlook contacts.

4/27: Kelvir-AH Worm Spreads Via MSN Messenger

Similar to previous KELVIR variants, Worm_Kelvir.AH spreads copies of itself via MSN Messenger, a popular instant messaging application.

4/27: Icpass-A Worm Creates Zip Files

W32/Icpass-A is a worm for the Windows platform.

4/27: Mytob-BW Worm/Trojan Spreads Via IRC

W32/Mytob-BW is a mass-mailing worm and backdoor Trojan that can be controlled through the Internet Relay Chat (IRC) network.

4/27: Kelvir-AP Worm Emails Messenger Contacts

W32.Kelvir.AP is a worm that sends a message to all MSN messenger contacts on the compromised computer and attempts to download a file.

4/27: Allim-A Worm Spreads Spybot Variant

W32.Allim.A is a worm that spreads a variant of the W32.Spybot.Worm through America Online Instant Messenger (AIM).

4/27: Trojan.Hotword Opens Back Door

Trojan.Hotword is a Trojan Horse program that logs keystrokes and opens a back door.

4/27: Mytob-CY Worm Arrives as Email Attachment

Like other Mytob worm variants, Worm_Mytob.CY propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/26: Antiman Worm Sends Romanian Emails

Worm_Antiman arrives as an attachment in email messages written in Romanian.

4/26: Mytob-AK Worm/Trojan Exploits OS Flaws

W32/Mytob-AK is a mass-mailing worm and IRC backdoor Trojan.

4/26: Kelvir-AO Worm Spreads VIa MSN Messenger

W32.Kelvir.AO is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm.

4/26: Sdbot-ZC Worm Seeks Weak Passwords

W32/Sdbot-ZC is a network worm with backdoor functionality for the Windows platform.

4/26: Antiman-B Worm Spreads Via Email

Worm_Antiman.B propagates via email messages.

4/26: Sdbot-WM Worm Spreads to Remote Shares

W32/Sdbot-WM is a worm that attempts to spread to remote network shares.

4/26: Mytob-BO Worm Spreads Flaw

W32.Mytob.BO@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/26: Admincash-B Trojan Infects Explorer.exe File

Trojan.Admincash.B is a Trojan horse that infects the Explorer.exe file and downloads adware and dialers.

4/26: Trojan.Servpam Uses System As Email Relay

Trojan.Servpam is a Trojan horse that allows a compromised computer to be used as an email relay.

4/26: PWSteal.Bancos-T Trojan Steals Passwords

PWSteal.Bancos.T is a password stealing Trojan horse that logs keystrokes and steals information entered into certain banking Web sites.

4/26: Flush-C Trojan Modifies DNS Server Settings

Trojan.Flush.C is a Trojan horse that modifies the DNS server settings on a compromised computer and redirects the browser to potentially malicious Web sites.

4/26: Mytob-BN Worm Gathers Email Addresses

W32.Mytob.BN@mm is a mass-mailing worm that has back door capabilities and uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/26: Mytob-AJ Worm Targets IRC Users

W32/Mytob-AJ is a mass-mailing worm and backdoor Trojan that targets users of Internet Relay Chat programs.

4/26: Antiman-A Worm Uses Own SMTP Engine

W32.Antiman.A@mm is a mass-mailing worm that uses its own SMTP engine to send a copy of itself to all email addresses that it finds in the compromised computer.

4/25: Nephtebank Trojan Downloads File

Trojan.Nephtebank is a Trojan horse that downloads and executes a file by exploiting the Microsoft Internet Explorer ADODB.Stream Object File Installation Weakness (BID 1051).

4/25: Kedebe Worm Kills Security

W32.Kedebe@mm is a mass-mailing worm that ends processes and prevents access to several Web sites, most of which are security-related.

4/25: Kelvir-AD Worm Spreads Via IM

Similar to previous KELVIR variants, Worm_Kelvir.AD spreads copies of itself via MSN Messenger, a popular instant messaging application.

Time to Remind Users of Security Responsibilities

Getting people to remember their security responsibilities can be a challenge. But it's worth the effort.

4/25: Gabloliz-A Worm Spreads Via AIM

W32.Gabloliz.A is a worm with back door capabilities that spreads through AOL Instant Messenger and Kazaa file-sharing networks.

4/25: Mytob-AI Worm/Trojan Hits IRC Users

W32/Mytob-AI is a mass-mailing worm and backdoor Trojan that targets users of Internet Relay Chat programs.

4/25: Velkbot-A Worm Spreads Via IM

W32.Velkbot.A is a worm with back door capabilities that spreads through MSN Messenger, Yahoo Messenger and AOL Instant Messenger.

4/25: Spybot-OBZ Worm Has DDoS Ability

W32.Spybot.OBZ is a worm that has distributed denial of service and back door capabilities.

4/25: Zhopa Trojan OKs Malicious Actions

Trojan.Zhopa is a back door Trojan that allows the remote attacker to perform various malicious actions on the compromised computer.

4/25: Mytob-BL Worm Uses Windows Flaw

W32.Mytob.BL@mm is a mass-mailing worm that exploits the Microsoft Windows Local Security Authority Service Remote Buffer Overflow vulnerability (as described in Microsoft Security Bulletin MS04-011).

4/25: Mytob-CU Worm Drops Copy of Itself

Upon execution, Worm_Mytob.CU drops a copy of itself in the Windows system folder.

4/25: Abwiz Trojan Gives Hackers Access

Trojan.Abwiz is a back door Trojan that allows the remote attacker to perform various malicious actions on the compromised computer.

Trend Micro Update Causes Mayhem

Trend Micro customers spent at least part of the weekend battling the fallout from a faulty software update that the company distributed last Friday.

4/25: Wurmark-I a Mass-Mailing Worm

W32/Wurmark-I is a mass-mailing worm.

4/25: Kelvir-AN Worm Spreads Other Worm

W32.Kelvir.AN is a worm that spreads W32.Spybot.OBZ through MSN Messenger.

4/25: Rbot-ABB a Windows Network Worm

W32/Rbot-ABB is a Windows network worm that attempts to spread via network shares.

4/25: Kelvir-AL Worm Spreads Sdbot Variant

W32.Kelvir.AL is a worm that spreads a variant of Backdoor.Sdbot through MSN Messenger.

4/25: Goldun-E Trojan Steals Account Info.

Trojan.Goldun.E is a Trojan horse that attempts to log keystrokes and steal account information entered into forms on the www.e-gold.com domain.

New Worm Wipes Out MP3 Files

One virus writer has taken the law into his own hands when it comes to online music pirates.

4/22: Kelvir-R Trojan Hits IM Contacts

The Kelvir-R Trojan monitors the status of MSN Messenger contacts and sends a message to all online contacts.

4/22: LegMir-AD Steals Information

The new worm, LegMir-AD, is receiving a low-to-medium threat status for stealing information and dropping more malware into the infected machine.

4/22: CashGrab-A Hits Bank Customers

The CashGrab-A Trojan is aimed at people using online banking sites.

4/21: Mytob-AH Worm Changes Data

The Mytob-AH worm, yet another variant of the virulent family, is attacking Windows systems, modifying data and dropping in more malware.

4/21: Dloader-MN Trojan Downloads Code

The Trojan, Dloader-MN, downloads code from the Internet.

4/21: Mytob-AG Worm Gives Remote Access

The Mytob-AG worm is enabling remote users to access the infected computer.

Man Arrested for Using Trojan, Webcam to Spy on Teen

A 45-year-old Cyprus man has been arrested for allegedly using a Trojan horse to control a teenage girl's webcam, using it to spy on her in her own bedroom.

4/20: Mytob-CC Worm Modifies Registry

Upon execution, Worm_Mytob.CC drops a copy of itself in the Windows system folder.

4/20: Mytob-BC Worm Links to IRC Server

Mytob.BC is a worm with backdoor characteristics that connects to an IRC server in order to receive remote control commands, such as delete, download and run files.

4/20: Sdbot-XH Worm Spreads Via Shares

W32/Sdbot-XH is a network worm with backdoor Trojan functionality for the Windows platform that spreads through network shares protected by weak passwords, MS-SQL servers and through various operating system vulnerabilities.

4/20: Dloader-MK a Downloader Trojan

Troj/Dloader-MK is a downloader Trojan on the Windows platform.

4/20: Mytob-CD Worm Drops Copies

Upon execution, Worm_Mytob.CD drops a copy of itself in the Windows system folder.

4/20: Mytob-AW Worm Uses Own Engine

W32.Mytob.AW@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/20: Kelvir-AE Worm Spreads Via IM

W32.Kelvir.AE is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm.

4/20: Mytob-CB Worm Drops Files

Upon execution, Worm_Mytob.CB drops a copy of itself in the Windows system folder.

4/20: Trojan.Riler-B Installs Itself as LSP

Trojan.Riler.B is a back door Trojan horse program that installs itself as a layered service provider (LSP), and allows a remote attacker to have unauthorized access to the compromised system.

4/20: Bancos-FC Trojan Lies in Wait

Bancos.FC is a Trojan that waits until an Internet connection is established using the Dial-up and Network Access.

4/20: Kelvir-AC Worm Spreads Via IM

W32.Kelvir.AC is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm.

4/19: Bagle.BI Worm Employs Trojan

Similar to some WORM_BAGLE variant, Worm_Bagle.BI employs a Trojan to acquire copies of itself from a certain location and run it on an affected system.

4/19: Mytob-BU Worm Copies in Email

Worm_Mytob.BU propagates by sending a copy of itself via email.

4/19: Bagle.BH Worm Employs Trojan

Similar to some WORM_BAGLE variant, Worm_Bagle.BH employs a Trojan to acquire copies of itself from a certain location and run it on an affected system.

4/19: Sober.N Worm Hits as Attachment

Sober.N is a memory-resident mass mailing worm that arrives as an email attachment.

4/19: Sober-O Worm Arrives in Email

W32/Sober.o@mm is a mass-mailing worm that arrives in an email message and is designed to trick users into thinking that someone else is receiving their email.

4/19: Sdbot-XH Worm Uses Network Shares

W32/Sdbot-XH is a network worm with backdoor Trojan functionality for the Windows platform that spreads through network shares protected by weak passwords, MS-SQL servers and through various operating system vulnerabilities.

4/19: Agobot-RN Worm Has Backdoor

W32/Agobot-RN is a network worm with backdoor functionality for the Windows platform.

4/19: Sober-M Worm Sends Email in German

W32/Sober-M is a mass-mailing worm.

4/19: Delbot-B an IRC Trojan

Troj/Delbot-B is a IRC backdoor Trojan for the Windows platform.

4/19: Mytob-AW Worm Uses SMTP Engine

W32.Mytob.AW@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/19: Startpag.La Trojan Affects Registry

Troj_Startpag.La modifies the registry in order to change the default Homepage and Search page of the Internet Explorer Browser. It also registers itself as a Browser Helper Object (BHO).

4/19: Ryejet Trojan Lets Hackers In

Backdoor.Ryejet is a back door Trojan horse that allows unauthorized remote access to a compromised computer.

Outtasking Solution to Company's Email Woes

A large chemical company has turned to outtasking the security side of its email system to keep its messaging system running smoothly and to free up its IT staff.

4/18: Kelvir-X Worm Spreads Via IM

W32.Kelvir.X is a worm that spreads through MSN Messenger and drops a copy of W32.Spybot.Worm.

4/18: Spybot-NYT Worm Has DoS Ability

W32.Spybot.NYT is a worm that has distributed denial of service and back door capabilities.

4/18: Sinnaka-A Worm Uses Own Engine

W32.Sinnaka.A@mm is a worm that uses its own SMTP engine to send itself as an email attachment.

4/18: Backdoor.Berpi Lets Attacker In

Backdoor.Berpi is a back door Trojan that allows the remote attacker to perform various malicious actions on the compromised computer.

4/18: Picrate-B Worm IMs Itself to Contacts

W32.Picrate.B@mm is a worm that sends copies of itself to instant messenger contacts and drops a variant of W32.Spybot.Worm.

4/18: Trojan.Tooso-H Halts Security Apps

Trojan.Tooso.H is a Trojan horse that interferes with the operation of security software by terminating processes, stopping services, removing registry entries, and deleting files.

4/18: Banker-CH a Password-Stealing Trojan

Troj/Banker-CH is a password stealing Trojan for the Windows platform.

4/18: Kelvir-Y Worm Uses MSN Messenger

W32.Kelvir.Y is a worm that spreads through MSN Messenger and drops W32.Spybot.NYT.

4/18: Kelvir-AA Worm Spreads Via IM

W32.Kelvir.AA is a worm that spreads through MSN Messenger and drops W32.Spybot.NLI.

4/18: Agobot-RM Worm Uses Bad Passwords

W32/Agobot-RM is a network worm with a backdoor Trojan component.

4/18: Dloader-LR a Downloader Trojan

Troj/Dloader-LR is a downloader Trojan.

4/18: Trojan.Mitglieder-P Uses Runs Relay

Trojan.Mitglieder.P is a Trojan horse that allows a compromised computer to be used as an email relay.

4/18: Dloader-LW a Downloader Trojan

Troj/Dloader-LW is a downloader Trojan for the Windows platform.

Is Spam Actually Less Annoying?

Spam volume is up, but the annoyance factor is down.

4/18: Bagle-BR Worm Drops a File

W32/Bagle.Br is a variant of the Bagle family of worms that copies itself to the %WinDir% system32 as WINSHOST.EXE.

4/18: Bufei Virus Infects .Exe Files

W32.Bufei is a virus that attempts to infect .exe files.

4/18: Mytob-BR Worm Mails Itself Out

Worm_Mytob.BR, like other WORM_MYTOB variants, propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/15: Kelvir-V Worm Drops Other Worm

W32.Kelvir.V is a worm that spreads through MSN Messenger and drops W32.Spybot.NNT.

4/15: Kelvir-S Worm Spreads Via IM

W32.Kelvir.S is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm.

4/15: Tooso-F Trojan Hits Security Apps

Trojan.Tooso.F is a Trojan horse that interferes with the operation of security software by terminating processes, stopping services, removing registry entries, and deleting files.

4/15: Mytob-BQ Worm Copies into Email

Worm_Mytob.BQ, like other WORM_MYTOB variants, propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/15: Kelvir-W Worm Spreads Via IM

W32.Kelvir.W is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm.

4/15: Sdbot-XC Worm Targets Passwords

W32/Sdbot-XC is a network worm with backdoor functionality for the Windows platform.

4/15: BagleDL-N Trojan Creates Files

Troj/BagleDl-N is a Trojan dropper.

4/15: Kelvir-J an IM Worm

W32/Kelvir-J is an instant messaging worm.

4/15: Spybot-NPS Worm Has DDoS Ability

W32.Spybot.NPS is a worm that has distributed denial of service and back door capabilities.

4/15: Tirbot-D Worm Uses LSASS Flaw

W32/Tirbot-D is a network worm with backdoor functionality for the Windows platform.

IM Worm Prompts Reuters Messaging Shutdown

An IM worm forced Reuters to temporarily shut down its private instant messaging network.

4/15: Trojan.Esteems Steals Private Info

Trojan.Esteems is a Trojan horse that steals confidential information from a compromised computer by logging keystrokes and sending them to a remote server.

4/14: Kelvir-O Worm Sends Note in IM

Worm_Kelvir.O sends a message to all contacts in MSN Messenger.

4/14: Sdbot-BLL Worm Connects to IRC

Worm_Sdbot.Bll arrives as dropped by WORM_KELVIR.N.

4/14: Agent-DI a Backdoor Trojan

Troj/Agent-DI is a backdoor Trojan for the Windows platform.

4/14: Darro Virus Infects .Exe, .Hlp Files

W32.Darro is a virus that infects .exe and .hlp files.

4/14: Kelvir-N Worm Sends Message

Worm_Kelvir.N sends a message to all contacts in MSN Messenger.

4/14: Mytob-BA Worm Variant Spreading

W32/Mytob-BA is a mass-mailing worm and Trojan with an IRC backdoor.

4/14: Mytob-BM Mass-Mailing Worm Spreading

Like other WORM_MYTOB variants, Worm_Mytob.BM propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/14: Symbian/Hobbes-A Malware Hits Phones

Symbian/Hobbes.a is a malware targeting the Nokia Series 60 platform.

4/14: Bancos-CG Trojan Steals Passwords

Troj/Bancos-CG is a password stealing Trojan for the Windows platform that targets particular online banking sites.

4/14: Backdoor-CQY Trojan Drops EXE File

BackDoor-CQY is a BackDoor Trojan was originally dropped (and executed) by the MultiDropper-MY Trojan.

4/14: Codbot-K Worm Has Backdoor Ability

W32/Codbot-K is a network worm with backdoor functionality for the Windows platform.

4/14: Kelvir-U Worm Spreads Via MSN

W32.Kelvir.U is a worm that spreads through MSN Messenger and drops a copy of W32.Spybot.NLI.

4/14: Gaobot-EYP Worm Opens Door

Gaobot.EYP is a worm with backdoor characteristics that allows hackers to gain remote control over the affected computer and carry out actions such as command execution, download and execute files, log keystrokes, obtain different information on the computer, launch distributed denial of service (DDoS) attacks, etc.

4/14: Kelvir-T Worm Spreads Via IM

W32.Kelvir.T is a worm that spreads through MSN Messenger and drops a variant of W32.Randex.

4/14: MultiDropper-MY is a Trojan

When executed, MultiDropper-MY drops and executes the BackDoor-CQY trojan.

4/13: Mytob-BB a Mass-Mailing Worm

Like other WORM_MYTOB variants, Worm_Mytob.BB propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/13: Bancos-CD Password-Stealing Trojan

Troj/Bancos-CD is a password stealing Trojan for the Windows platform that targets customers of Brazilian banks.

4/13: Kelvir-R Worm Spreads Via IM

W32.Kelvir.R is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm.

4/13: Mytob-AU Worm Uses own Engine

W32.Mytob.AU@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

New Spam Scam Exploits Pope's Death

A new spam campaign is exploiting people's interest in and grief over the death of Pope John Paul II.

4/13: Spybot-NLX Worm Has DDoS Abilities

W32.Spybot.NLX is a worm that has distributed denial of service and back door capabilities.

4/13: Mytob-BH Worm Another Variant

Like other WORM_MYTOB variants, Worm_Mytob.BH propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/12: W97M.Spatch Macro Virus Infects Files

W97M.Spatch is a macro virus that infects Microsoft Word documents and lowers the security level settings for macros.

4/12: Mytob-AP Worm Uses LSASS Flaw

W32.Mytob.AP@mm is a mass-mailing worm with back door capabilities that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/12: Mytob-BA Worm Drops Copy of Itself

Worm_Mytob.BA upon execution, drops a copy of itself in the Windows system folder.

4/12: Mytob-AX Worm Spreads Via Email

Worm_Mytob.AX upon execution drops a copy of itself in the Windows system folder.

4/12: Mytob-AO a Mass-Mailing Worm

W32.Mytob.AO@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/12: Mytob-AV Worm Drops Copies of Itself

Worm_Mytob.AV drops copies of itself in several folders upon execution. It also drops other malicious files.

4/12: Mytob-AQ a Mass-Mailing Worm

W32.Mytob.AQ@mm is a mass-mailing worm with back door capabilities that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/12; Rbot-AAJ Worm Has Trojan Ability

W32/Rbot-AAJ is a worm with backdoor Trojan functionality.

4/12: Mytob-C Worm Hits LSASS Exploit

W32/Mytob-C is a mass-mailing worm with IRC backdoor functionality which can also infect computers vulnerable to the LSASS (MS04-011) exploit.

4/12: Mytob-E Trojan Targets IRC Users

W32/Mytob-E is a mass-mailing worm and backdoor Trojan that targets users of Internet Relay Chat programs.

4/12: Kelvir-Q Worm Spreads Via IM

W32.Kelvir.Q is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.Worm.

4/12: Mytob-AS Worm Uses SMTP Engine

W32.Mytob.AS@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/12: Mytob-AN Worm Gathers Addresses

W32.Mytob.AN@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/12: Tirbot-D Worm Has Backdoor

W32/Tirbot-D is a network worm with backdoor functionality for the Windows platform.

4/12: Mytob-AP Worm Attaches to Emails

Like other WORM_MYTOB variants, Worm_Mytob.AP propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/12: Mytob-AY Worm Drops More Copies

Upon execution, Worm_Mytob.AY drops a copy of itself in the Windows system folder.

Five Critical Fixes in Latest Microsoft Update

UPDATED: The software giant introduces new fixes to shore up its product line.

4/12: Mytob-AR Yet Another Variant

W32.Mytob.AR@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer with back door capabilities.

4/12: Mytob-BF Worm Arrives as Attachment

Like other WORM_MYTOB variants, Worm_Mytob.BF propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

Mytob Author Playing 'Cat and Mouse Game'

Security pros say the author of the virulent Mytob family of worms is playing a cat and mouse game with them, and it's causing a flood of variants to pound the Internet.

4/12: Mytob-BG Worm Spreads Fast

Like other WORM_MYTOB variants Worm_Mytob.BG propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/12: Mytob-AT Worm Uses Shares

Worm_Mytob.AT propagates via network shares and email messages.

4/12: Mytob-BD a Mass-Mailing Worm

Like other WORM_MYTOB variants, Worm_Mytob.BD propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/11: Mytob-AI Harvests Addresses

Some security vendors have issued alerts for W32.Mytob.AI@mm, a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/11: Mytob-AF Sent as Attachment

Worm_Mytob-AF is a memory-resident worm that propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/11: Mytob-AH Worm is Spreading

Worm_Mytob-AH, like other WORM_MYTOB variants, propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/11: Mytob-AR a Mass-Mailing Worm

W32.Mytob.AK@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/11: Mytob-AG Sends Copy of Itself

Like other WORM_MYTOB variants, Worm_Mytob-AG propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/11: Istsvc-A a Trojan Downloader

Troj/Istsvc-A is a Trojan downloader for the Windows platform.

4/11: Mytob-AK a Mass-Mailing Worm

Like other WORM_MYTOB variants, Worm_Mytob-AK propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/11: Mytob-AN Stealing Addresses

Some security vendors have issued alerts for W32.Mytob.AN@mm, a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/11: Mytob-AM Sending Itself Out

Some security vendor have issued alerts for W32.Mytob.AM@mm, a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/11: Mytob-AJ Uses Own SMTP Engine

W32.Mytob.AJ@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/11: Mytob-AL Worm is Spreading

Some security vendors have issued alerts for W32.Mytob.AL@mm, a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

Americans Learning to Live With Spam Agita

E-mail users say they are more accepting of spam. Doesn't make it less painful though.

4/11: Mytob-Gen Worm Detects Variants

Mytob.gen is not a specific worm, but a generic detection for unknown variants of the Mytob family.

4/11: Kelvir-P Worm Spreads Via IM

W32.Kelvir.P is a worm that spreads through MSN Messenger and drops a variant of W32.Spybot.NLI.

4/11: Spybot-NLI Worm Opens Back Door

W32.Spybot.NLI is a worm that opens a back door on the compromised computer.

4/11: W97M.Spatch a Macro Virus

W97M.Spatch is a macro virus that infects Microsoft Word documents and lowers the security level settings for macros.

4/11: Agent-DH a Backdoor Trojan

Troj/Agent-DH is a backdoor Trojan.

4/8: Myfip-R Worm Spreads Via Shares

Worm_Myfip.R propagates via network shares.

4/8: Mytob-AB Worm Comes as Attachment

Worm_Mytob.AB, like other WORM_MYTOB variants, propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/8: Ablank-P Trojan Shows Popup Ads

Troj/Ablank-P is a Trojan for the Windows platform.

4/8: Prex-A Worm Arrives Via IM

Worm_Prex.A may arrive via the Instant Messenger applications MSN Messenger and Windows Messenger.

4/8: Mytob-S Worm Continues to Flourish

Anti-virus vendors continue to issue alerts for mass-mailing Mytob worm variant and backdoor Trojan W32/Mytob-S. According to Sophos, W32/Mytob.S targets users of Internet Relay Chat programs.

4/8: Rbot-AAG Worm Spreads to Shares

W32/Rbot-AAG is a worm that attempts to spread to remote network shares.

4/8: Sdranck-C Worm OKs Remote Access

W32/Sdranck-C is a Windows worm that spreads via network shares, drops files and contains backdoor functions that allow unauthorized remote access to the infected computer via IRC channels.

4/8: Aprilcone-A Worm is Using JMail

W32.Aprilcone.A@mm is a mass-mailing worm that uses JMail to send emails to addresses that it gathers from the compromised computer.

4/8: Backdoor.Verify Trojan Lets Hackers In

Backdoor.Verify is a back door Trojan that allows unauthorized remote access to the compromised computer.

4/8: Imabut-A Trojan a Floppy Disk Image

Trojan_Imabut-A arrives as a self-extracting floppy disk image.

4/8: Cabir-J Worm Affects Symbian Phones

Cabir.J is a worm that only affects cellular phones that use the operating system Symbian 60 series.

Unblocked SP2, 'Critical' Patches on Deck From Microsoft

The company prepares fixes for MSN Messenger, Exchange and Office at the same time it removes blocks for Windows XP SP2.

4/8: Mytob-AD Worm Gathers Addresses

W32.Mytob.AD@mm is a mass-mailing worm that uses its own SMTP engine to send an email to addresses that it gathers from the compromised computer.

4/8: PWSteal.Cardwiz Trojan Steals Info

PWSteal.Cardwiz is a password-stealing Trojan horse that attempts to steal credit card information from the compromised computer.

Gates Wants to Can Spam -- Fast

Microsoft founder and chief software architect continues to push for eradication of spam.

4/8: Kelvir-O Worm Spreads Via Messenger

W32.Kelvir.O is a worm that spreads through MSN Messenger.

4/8: PWSteal.Ldpinch-F Steals Passwords

PWSteal.Ldpinch.F is a password-stealing Trojan horse that attempts to steal information from the compromised computer.

4/8: Anicmoo-D Trojan Exploits Windows Flaw

Trojan.Anicmoo.D is a Trojan that exploits the Windows User32.DLL ANI File Header Handling Stack-Based Buffer Overflow Vulnerability (described in Microsoft Security Bulletin MS05-002) and downloads other threats.

4/7: Rbot-DP IRC Backdoor Trojan

W32/Rbot-DP is an IRC backdoor Trojan with spreading capability.

4/7: Kelvir-K Worm Still Spreading

Another security vendor is issuing an alert for Worm_Kelvir.K.

4/7: Kelvir-H an IM Worm for Windows

W32/Kelvir-H is an instant messaging worm for the Windows platform.

4/7: PWS-Banker Trojan Steals Info

PWS-Banker.q is a Trojan intended to steal user's credit card details.

Cisco Fixes a Pair of IOS Vulnerabilities

Cisco has released patches that address denial of service and authentication vulnerabilities in IOS.

4/7: Rbot-AAF Worm Hits Network Shares

W32/Rbot-AAF is a network worm that attempts to spread via network shares.

4/7: Agobot-RJ Worm Has Backdoor

W32/Agobot-RJ is a network worm with backdoor functionality for the Windows platform.

4/7: Mytob-AA Worm Uses SMTP Engine

Worm_Mytob.AA, like other WORM_MYTOB variants, propagates by sending a copy of itself as an attachment to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.

4/7; Kelvir-L Worm Sends IM to Contacts

Similar to previous KELVIR variants, Worm_Kelvir.L spreads copies of itself via MSN Messenger, a popular instant messaging application.

Handheld Security Too Expensive For Enterprise?

Companies need to assess their antivirus, VPN, device security and management software, the Burton Group found.

How to Protect a Vanishing Perimeter?

Columnist Ken van Wyk says the idea of a perimeter is quickly fading away. And considering it a solid border is a dangerous way of thinking. Now, it's time, he says, to focus on the software.