Click here

Malware: Archive: September 2007 

9/28: Mal/EncPk-BB a Program With Suspect Encryption Characteristics

Mal/EncPk-BB is a program that has encryption characteristics unique to malware.

9/28: Delf-EYE Trojan Registers Itself as BHO for IE

Troj/Delf-EYE is a Trojan for the Windows platform.

9/28: Mdrop-BPW Trojan Hits Windows

Troj/Mdrop-BPW is a Trojan for the Windows platform.

9/28: BackDoor-CKB!1407 Trojan Steals Information, Runs Malicious Content

BackDoor-CKB!1407 is a Trojan intended to steal sensitive information, silently download and execute malicious content from a remote server.

9/28: Psyme-FF a Downloader Trojan

Troj/Psyme-FF is a downloader Trojan for the Windows platform.

9/28: Infostealer.Orcu.B Trojan Steals Confidential Information

Infostealer.Orcu.B is a Trojan horse that attempts to steal confidential information.

9/28: Virut.h a Polymorphic, EPO File Infector

W32/Virut.h is a polymorphic, entry point obscuring (EPO) file infector with IRC bot functionality.

Those Nifty Widgets Can Pack A Rude Surprise

Malware finds a new target in desktop widgets that look simple and harmless but can carry a malicious payload.

9/28: Scrimge.O Worm Spreads Via Microsoft IM Clients

W32.Scrimge.O is a worm that spreads through Microsoft instant messaging clients and opens a back door on the compromised computer.

9/27: MSIL.Yakizake Worm Runs Within .NET or Mono Framework

MSIL.Yakizake is a mass-mailing worm that runs within the .NET or Mono framework and requires that Thunderbird is installed.

9/27: Mal/Obfus-A an Obfuscated Malicious Program

Mal/Obfus-A is an obfuscated malicious program.

9/27: Mofei-X a Windows Worm

W32/Mofei-X is a worm for the Windows platform.

9/27: AdClicker-FC IE BHO Retrieves, Redirects Domains

AdClicker-FC is a browser helper object (BHO) for Internet Explorer that retrieves a list of domains, which it then redirects during browsing.

9/27: CEP.worm Spreads Via Removable Media and Drops Trojan

The W32/CEP.worm is designed to spread via the removable media and drops BackDoor-CEP Trojan.

9/27: Virut.W Virus Infects .Exe, .Scr Files on System

W32.Virut.W is a virus that infects .exe and .scr files on the compromised computer.

9/26: Downloader-BEU Trojan Drops, Installs More Malicious Components

Downloader-BEU is a downloader Trojan, which when executed, could further download more malicious components from the web and install them on the victim’s machine.

9/26: Sohana-AK Worm Spreads Via Removable Media

W32/Sohana-AK is a worm for the Windows platform.

9/26: Generic Script.c Trojan Detects Malicious Content

Generic Script.c Trojan is a heuristic detection for web pages that are crafted to contain references to some malicious content.

9/26: Backdr-Q Trojan Targets Windows

Troj/Backdr-Q is a Trojan for the Windows platform.

9/26: JS_Decdec.AX JavaScript Detects Compromised UK Web Site

JS_Decdec.AX JavaScript is the Trend Micro detection for the compromised Web site of Syrian embassy on United Kingdom, which is hosted at http://www.syrianembassy.co.uk.

9/26: BackDoor-CVT Trojan Injects Thread Into Browsers

BackDoor-CVT is a backdoor Trojan that will inject a thread into existing browsers (Internet Explorer or Mozilla) or start Internet Explorer to access the internet to download new commands and malware.

9/26: BackDoor-CEB a Remote Access Trojan

BackDoor-CEB is a remote access Trojan is downloaded by W32/Mydoom.u@MM.

9/26: Small.KYZ Downloads File from Certain URL

Troj_Small.KYZ is a Trojan that arrives as a file downloaded by JS_DECDEC.AX.

9/25: Autorun-D Worm Spreads to Devices Mapped to Drive Letter

W32/Autorun-D is a worm for the Windows platform.

9/25: Obfuscated Script.b Detects Inspecting Web Scripts

Obfuscated Script.b is a heuristic detection for web scripts that crafted to prevent inspection of its malicious content.

9/25: Psyme-FC a Downloader Trojan

Troj/Psyme-FC is a downloader Trojan for the Windows platform.

9/25: Exploit-BaoFeng.a Detects Web Scripts Targeting Buffer Overflow Flaw

Exploit-BaoFeng.a is a generic detection for web scripts that are targeting a buffer overflow vulnerability in BaoFeng, a popular media player in China.

9/25: Backdoor.Darkmoon.E Trojan Opens Back Door on Port

Backdoor.Darkmoon.E is a Trojan horse that opens a back door on TCP port 5555 on the compromised computer.

9/24: Hasah.Worm.A Copies Itself to Mapped, Removable Drives to Spread

W32/Hasah.worm.a spreads by copying itself to mapped & removable drives.

9/24: Downloader-BEQ Installs Malicious Code on Victim's System

Downloader-BEQ is a downloader Trojan, which when executed, could further download more malicious components from the web and install them on the victim’s machine.

9/24: Virut.gen Detects Family of EPO File Infectors

W32/Virut.gen is a generic detection for the W32/Virut family of polymorphic, entry point obscuring (EPO) file infectors with IRC bot functionality.

9/24: Worm_VB.EAZ Drops Copies of Itself and Components

Worm_VB.EAZ may be dropped by other malware.

9/24: Downloader-BEG Trojan Drops More Malicious Code

Downloader-BEG is a downloader Trojan, which when executed, could further download more malicious components from the web and install them on the victim’s machine.

9/24: PE_Lurker.A File Infector Drops File

PE_LURKER.A is Trend Micro's detection for files detected as PE_LURKER.A-O.

9/24: Backdoor.Unpdoor Trojan Opens Random Port to Remote Site

Backdoor.Unpdoor is a Trojan horse that opens a random port and connects to a remote Web site.

New PDF Security Exploit Emerges

Thus far it's in the hands of a white hat hacker who has reported it to Adobe. But it could spell bad news if the bad guys find it before Adobe fixes it.

9/21: Exploit-VcardGadget Detects Vista Flaw

Exploit-VcardGadget is a detection for Windows Vista Contacts Gadget Code execution Vulnerability.

9/21: Forinsty Worm Spreads Via Removable Drives

W32.Forinsty is a worm that spreads through removable drives and opens a back door on the compromised computer.

9/21: Niucoft Worm Copies Itself to Drives, Inserts Iframe Tag

W32.Niucoft is a worm that spreads by copying itself to all drives on the compromised computer and inserts an iframe tag into .htm files.

9/21: Autorun.worm.y!host Detects Infected Hosts FIles

W32/Autorun.worm.y!host is a detection for hosts files that have been infected by W32/Autorun.worm.y.

9/21: DNSChanger.KA Trojan Installed Via Direct Access Installed

The DNSChanger.KA Trojan is observed to be installed via the Direct Access installer.

9/21: Dropper-RK Trojan Hits Windows

Troj/Dropper-RK is a Trojan for the Windows platform.

9/21: LdPinch-QY a Password-Stealing Trojan

Troj/LdPinch-QY is a password-stealing Trojan for the Windows platform.

9/21: Imaut.BA Worm Spreads Via IM Programs

W32.Imaut.BA is a worm that spreads through Yahoo! Instant Messenger, AOL Instant Messenger, Windows Live Messenger and Windows Messenger.

9/21: Yalove.D Worm Spreads Via Yahoo! IM

W32.Yalove.D is a worm that spreads through Yahoo! Instant Messenger and by copying itself to all drives.

9/21: Agent.EGK Trojan Arrives as Spam Mail Attachment

Troj_Agent.EGK is a Trojan that arrives as attachment to email messages spammed by another malware or a malicious user.

9/21: Sohanat.DB Worm Prevents Access to Search Sites

Sohanat.DB is a worm that prevents users from accessing websites belonging to several searchers.

9/21: AdClick-EJ a Windows Trojan

Troj/AdClick-EJ is a Trojan for the Windows platform.

9/21: Snaban Worm Copies Itself to Removable, Network Drives

W32.Snaban is a worm that spreads by copying itself to removable drives and network drives on the compromised computer.

9/21: Delf.JPH Trojan May Be Unknowingly Downloaded

Troj_Delf.JPH is a Trojan that arrives as a file downloaded from remote sites by TROJ_AGENT.EGK and by other malware.

9/21: Kaxela.A Worm Downloads Potentially Malicious Files

W32.Kaxela.A is a worm that copies itself to local and removable drives.

9/21: WoW-KA a Windows Trojan

Troj/WoW-KA is a Trojan for the Windows platform.

9/20: Atisa Worm Creates Autorun File to Spread to Drives

W32/Atisa.worm attempts to spread to removable drives by creating an autorun.inf file, which will run the worm automatically, if systems that use the removable drive are set to Autorun.

9/20: JS_Agent.AAAA JavaScript Arrives as Email Attachment

JS_Agent.AAAA is JavaScript that arrives as attachment to email messages spammed by another malware or a malicious user.

9/20: Ataxbot Worm an IRC Bot That Spreads Via MSN

W32/Ataxbot.worm is an IRC bot that is able, among other things, to spread through the popular MSN messenger chat program.

9/20: Dloader.UAM Trojan Downloads Other Malware

Troj_Dloader.UAM is a Trojan that arrives as a file dropped by other malware.

9/20: StartPage-KA Trojan Changes IE Start Page

StartPage-KA is a Trojan that changes the StartPage of the Microsoft Internet Explorer.

9/20: Baloon.Worm Spreads Via Social Engineering

W32/Baloon.worm attempts to spread by social engineering.

9/20: Scrimge.H Worm Spreads Through Microsoft IM Clients

W32.Scrimge.H is a worm that spreads through Microsoft instant messaging clients.

9/20: Stration.RE Worm May be Unknowingly Downloaded from Internet

Worm_Stration.RE may be downloaded unknowingly from the Internet.

9/20: UNIX/Generic Backdoor.a Detects Shell-Based Trojans

UNIX/Generic Backdoor.a is a detection covering many shell-based backdoor Trojans - typically one-off creations that have been received by AVERT.

9/20: Qova-A Trojan Hits Windows

Troj/Qova-A is a Trojan for the Windows platform.

9/19: DwnLdr-GXU a Windows Trojan

Troj/DwnLdr-GXU is a Trojan for the Windows platform.

9/19: VB-DXN Worm Spreads Via Yahoo! Messenger IM

W32/VB-DXN is a worm for the Windows platform.

9/19: Domamo Mass Mailer Has Dialing Capabilities

W32/Domamo@MM is a mass mailer with dialing capabilities that especially targets Italian users.

9/19: Oanamg-A Trojan Hits Windows

Troj/Oanamg-A is a Trojan for the Windows platform.

9/19: VBS.Runauto.C Worm Copies Itself to Drives

VBS.Runauto.C is a worm that spreads by copying itself to all drives except floppy drives.

9/19: Domamo!link an Internet Shortcut Linking to Malicious Website

W32/Domamo!link is an internet shortcut that is created on a user's desktop by W32/Domamo@MM.

9/19: Delf-EYC a Backdoor Trojan

Troj/Delf-EYC is a backdoor Trojan for the Windows platform.

9/18: MsnSend.A Worm Uses MSN Messenger to Spread

MsnSend.A is a worm whose main objective is to spread and affect as many computers as possible.

9/18: Ahah-A Worm Hits Windows

W32/Ahah-A is a worm for the Windows platform.

9/18: SillyFDC-AX a Windows Worm

W32/SillyFDC-AX is a worm for the Windows platform.

9/18: StartPage-KB Trojan Changes IE Startpage

StartPage-KB is a Trojan that changes the Startpage of the Internet Explorer.

9/18: Fujacks.ak a Win32/PE Executable File Infector

W32/Fujacks.ak is a Win32/PE executable file infector with downloading and spreading capabilities.

9/18: Looked-DU a Windows Virus

W32/Looked-DU is a virus for the Windows platform.

9/18: Cream File Infector Places Hooks in Victim File Code

W32/Cream is a file infector.

9/18: Focelto.A Worm Spreads Via Microsoft IM; Uses Rootkit Techniques

W32.Focelto.A is a worm that spreads through Microsoft instant messaging clients and uses Rootkit techniques.

9/18: WS-IshPol!cfg Malicious Program Generates Password-Stealing Trojans

WS-IshPol!cfg is a malicious program that allows the malicious user to generate easily password-stealing Trojans.

9/18: PWS-IshPol a Password-Stealing Trojan

PWS-IshPol is a password-stealing Trojan created using the PWS-IshPol!cfg generation tool.

9/17: Rbot-GTG Worm Has IRC Backdoor Functions

W32/Rbot-GTG is a worm with IRC backdoor functionality for the Windows platform.

9/17: SillyFDC-AW Worm Hits Windows

W32/SillyFDC-AW is a worm for the Windows platform.

9/17: Rbot-GTF a Windows Worm

W32/Rbot-GTF is a worm for the Windows platform.

9/17: Sdbot.Fel Worm Spreads Via MSN Messenger

Worm_Sdbot.Fel is downloaded from remote sites by other malware.

9/17: Googbot Worm Exploits Certain Flaws

W32.Googbot@mm is a mass-mailing worm that also spreads by exploiting certain vulnerabilities.

9/14: Beagle.GM Trojan Downloads, Executes Malicious Files

W32.Beagle.GM is a Trojan horse that downloads and executes malicious remote files.

9/14: Nobond-B a Downloader Trojan

Troj/Nobond-B is a downloader Trojan for the Windows platform.

9/14: YBHO-A a Password-Stealing Trojan

Troj/YBHO-A is a password-stealing Trojan for the Windows platform.

9/14: Deledsig.A Virus Infects Executables Files

W32.Deledsig.A is a virus that infects executable files and changes the size of design pictures (.mc9 .mc8 .prt .pfm and .igs) to 0 bytes.

9/14: Mimbot.B Worm Spreads Via MSN IM

W32.Mimbot.B is a worm that spreads through MSN instant messaging applications.

9/14: Banker-EIS Trojan Steals Confidential Bank Information

Troj/Banker-EIS is a Trojan for the Windows platform.

9/14: VBS.Runauto.B Worm Copies Itself to Drives

VBS.Runauto.B is a worm that spreads by copying itself to all drives except floppy drives.

9/13: Desdie-A Trojan Hits Windows

Troj/Desdie-A is a Trojan for the Windows platform.

9/13: Fake-Alert-R Trojan Shows Fake Warning Message

Similar to other malwares of this family, FakeAlert-R Trojan shows a fake warning message, alarming the users that their machine is infected or at risk.

Was IBM.com at Cross-Site Scripting Risk?

Feed on Big Blue's site allegedly was at risk until security researcher raised the alarm.

9/13: Verbegon Trojan Writes MP3 File to Media Player

Verbegon is a Trojan has an icon visually similar to that of the default media player shell registration for an mp3 file extension.

9/13: Troj/Agent-GCJ a Windows Trojan

Troj/Agent-GCJ is a Trojan for the Windows platform.

9/13: Blastclan.B Worm Copies Itself to Shares

W32.Blastclan.B is a worm that spreads by copying itself to network shares.

9/13: Infostealer.Banbot Trojan Downloads Files, Steals Info

Infostealer.Banbot is a Trojan horse that downloads files from remote locations and steals sensitive information from the compromised computer.

9/13: Trojan.Downexec!inf Detects Files Infected With Code

Trojan.Downexex!inf is a detection for files that have been infected with code that downloads and executes remote files.

9/13: Psyme-FB Trojan a Web Page That Exploits ADODB Flaw in IE

Troj/Psyme-FB is a web page that exploits the ADODB stream object vulnerability in Microsoft Internet Explorer to download a remote file to the local computer.

9/12: Fujacks.BZ Virus Infects HTML, ASP FIles

W32.Fujacks.BZ is a virus that infects HTML and ASP files and adds IFRAME that links to malicious sites.

9/12: Hoba.A Trojan Drops .DLL File to Download Malicious Script

Troj_Hoba.A is a Trojan that is downloaded from a compromised Web site by another malware detected by Trend Micro as TROJ_DLOADER.MLP.

9/12: Neeris Worm Spreads Via MSN IM

W32.Neeris is a worm that spreads through MSN instant messaging applications.

9/12: Spy-Agent.cj Trojan Monitors, Steals User Keyboard Strokes

Spy-Agent.cj is a Trojan that monitors and steals user keyboard strokes as well as Window content and sends it back to its owner.

9/12: Dloader.MLP Trojan May be Downloaded or Dropped

Troj_Dloader.MLP is a Trojan that may be downloaded from remote sites by other malware.

9/12: Pushdo-B a Windows Trojan

Troj/Pushdo-B is a Trojan for the Windows platform.

9/12: HTML_Dloader.TAA a Malicious HTML File

HTML_Dloader.TAA is a malicious HTML file that may be downloaded from remote sites by other malware.

9/12: Agent.AAWD Worm Drops Copy of Itself, Overwrites HOSTS File

Worm_Agent.AAWD may arrive as a file downloaded from a link attachment to email messages.

9/12: CoreNet Trojan Contacts, Watches Certain Websites

CoreNet is a Trojan that will contact certain websites.

9/12: Killaut.A Worm Copies Itself to Drives, Disables Processes

W32.Killaut.A is a worm that copies itself to local and removable drives.

9/12: Rbot-GTC a Network Worm

W32/Rbot-GTC is a network worm for the Windows platform.

9/12: DNSChan-LZ Trojan Targets Windows

Troj/DNSChan-LZ is a Trojan for the Windows platform.

9/11: Pykse.Worm.B Spreads Via Skype Chat Messages

W32/Pykse.worm.b is a worm that spreads via Skype chat messages.

9/11: FrogExer Trojan Drops .Jpg, .Gif Files With Image of Frog

FrogExer is a Trojan that drops .jpg and .gif files that contain one or some appended encrypted executable files.

9/11: Dloadr-BDW Downloader Trojan Tries to Execute Remote File

Troj/Dloadr-BDW is a downloader Trojan for the Windows platform.

9/11: FakeAlert-Q Trojan Shows Fake Infected Warning Message

FakeAlert-Q is a Trojan that, similar to other malwares of this family, shows a fake warning message, alarming the user that their machine is infected or at risk.

9/11: VB-DXL Trojan May Inject Itself Into Other Processes

Troj/VB-DXL is a Trojan for the Windows platform.

9/11: Imaut.AY Worm Spreads Via Yahoo! IM

W32.Imaut.AY is a worm that spreads through Yahoo! Instant Messenger and by copying itself to network shares.

9/11: Lunchload.A Trojan Receives Orders From Remote Server

Lunchload.A is a Trojan that connects to a certain server in order to receive instructions, such as downloading and running files, which can be of any nature, including malware.

9/11: Bagle.VX Trojan Arrives as Spam Mail Attachment

Troj_Bagle.VX is a Trojan that arrives as attachment to email messages spammed by another malware or a malicious user.

9/10: Addsones Virus May Display Ads, Copy Itself to Drives

W32.Addsones is a virus that may display advertisements and copy itself to all removable drives.

9/10: Blastclan Worm Copies Itself to all Drives

W32.Blastclan is a worm that spreads by copying itself to all drives on the compromised computer.

9/10: Trojan.Cakefes Downloads, Executes Malicious File

Trojan.Cakefes is a Trojan horse that downloads and executes a potentially malicious file on the compromised computer.

9/10: SillyFDC-AV Worm Targets Windows

W32/SillyFDC-AV is a worm for the Windows platform.

9/10: RootKit-BM a Windows Rootkit

Troj/RootKit-BM is a rootkit for the Windows platform.

9/10: Pykspa.D Worm Spreads Via Skype IM

W32.Pykspa.D is a worm that spreads through Skype Instant Messenger.

9/10: JS_Mulex.C Malicious JavaScript Downloads, Executes File

JS_Mulex.C is JavaScript is hosted on a certain URL.

9/10L Tibs.Arr Trojan Dropped by Other Malware

Troj_Tibs.Arr is a Trojan that may be dropped by other malware.

9/10: Sdbot.worm.gen.ax Uses Weak Network Shares to Spread

W32/Sdbot.worm.gen.ax!199CBEBA is a variant of W32/Sdbot.worm and bears strong resemblance to the many other members of this rapidly growing family.

9/10: PWS-AOU a Password-Stealing Trojan

Troj/PWS-AOU is a password-stealing Trojan for the Windows platform.

9/10: Skipi.A Worm May be Unknowingly Downloaded

Worm_Skipi.A may be downloaded unknowingly by a user when visiting malicious Web sites.

9/7: Trojan.Brutecell Retrieves Username and Password List

Trojan.Brutecell is a Trojan horse that retrieves a username and password list from the remote attacker and attempts to login to eBay using the list, sending the result to the attacker.

Flaw Still Shadows Firefox

Already fixed twice by Mozilla, security researchers claim the open source browser is still vulnerable.

9/7: IRCBot-XS Worm Spreads Via IM

W32/IRCBot-XS is a worm for the Windows platform.

9/7: Delf-EXV Trojan Targets Windows

Troj/Delf-EXV is a Trojan for the Windows platform.

9/7: Gnome.D Virus Spreads, Infects As Many Systems as Possible

Gnome.D is a virus with worm features, whose main aim is to spread and infect as many computers as possible.

9/7: Dropper.IPZ Trojan is Downloaded or Manually Installed

Troj_Dropper.IPZ is a Trojan that is hosted in a malicious Web site.

9/6: Trojan.Patchep Infects Executable Files

Trojan.Patchep is a Trojan horse that infects executable files and downloads potentially malicious files on to the compromised computer.

9/6; Lineag-BE a Windows Trojan

Troj/Lineag-BE is a Trojan for the Windows platform.

9/6: Haoba-A a Windows Trojan

Troj/Haoba-A is a Trojan for the Windows platform.

9/6: Virut.U Virus Infects .Exe, .Scr Files

W32.Virut.U is a virus that infects .exe and .scr files on the compromised computer.

Made in China: Virus-Laden Web Pages

Because China lags behind the West in security smarts, the bad guys find Chinese sites easier to compromise.

9/6: Worm_Nuwar.AQL Attacks Multiple Components

Worm_Nuwar.AQL is part of a complex attack initiated by the NUWAR family.

9/5: BeastPWS-H a Keylogging Trojan

Troj/BeastPWS-H is a keylogging Trojan for the Windows platform.

9/5: Trojan.Patchep!inf Detects Infected Executable Files

Trojan.Patchep!inf is a detection for infected executable files.

9/5: Ebbot a Bot With Password-Stealing Capabilities

W32/Ebbot is a bot with password-stealing capabilities designed to perform fraudulent activity aimed at eBay customers.

9/5: Dedlet Worm Copies Itself to Network Shared Drives

W32/Dedlet is a worm that spreads by copying itself to network shared drives.

9/5: Acdropper.K Trojan Arrives as Email Attachment

Troj_Acdropper.K is a Trojan that arrives as a file downloaded from remote sites or dropped by other malware.

9/4: Traxg-L a Windows Worm

W32/Traxg-L is a worm for the Windows platform.

9/4: SillyFDC-AU Worm Targets Windows

W32/SillyFDC-AU is a worm for the Windows platform.

9/4: Tibs.AJZ Trojan Arries Via Email

Troj_Tibs.AJZ is a Trojan that may be downloaded from remote sites by other malware.

9/4: Mysamurai Worm Copies Itself to Shared Drives

W32.Mysamurai is a worm that spreads by copying itself to shared drives.