Click here

Malware: Archive: November 2007 

Cyber Crime Grows More Dangerous And Sophisticated

McAfee study finds online threats are getting more complex and brazen in what they target, like the U.S. military.

11/30: PEPatcher.a Virus a DLL Loader

W32/PEPatcher.a Virus is the dll loader patched in the PE header of the executable file.

11/30: Hupigon-SV Worm Hits Windows

W32/Hupigon-SV is a worm for the Windows platform.

11/30: Torpig-BY a Windows Trojan

Troj/Torpig-BY is a Trojan for the Windows platform.

11/29: Gexin.a!htm Detects HTML FIles With Malicious iFrame

W32/Gexin.a!htm detects html files that have a malicious iframe inserted at the end of the file, caused by W32/Gexia.a worm.

11/29: Pagipef.I Worm Copies Itself to Local, Removable Drives

W32.Pagipef.I is a worm that spreads by copying itself to local and removable drives.

11/29: Autorun.worm.aw a File-Infecting, Prepending Virus

W32/Autorun.worm.aw is a file-infecting prepending virus, which infects and spreads via network shares and removable drives.

11/29: Goopo-A Malicious Script Redirects Visitor to Other Web Page

Troj/Goopo-A is a malicious script that redirects the visitor from the malicious website to another malicious web page which installs additional malicious files.

11/29: VBS/Nutpea-A a VBS Windows Worm

VBS/Nutpea-A is a VBS worm for the Windows platform.

11/29: Zlob-AGJ Trojan Hits Windows

Troj/Zlob-AGJ is a Trojan for the Windows platform.

11/29: Generic Downloader.ce Detects Files Pointing to Malicious Content

Generic Downloader.ce is a detection for html, php, eml, jsp and asp files that contain an iframe pointing to malicious content.

11/29: Chike Worm Infects Windows Systems Via Drives, Shares

At least two security vendors have issued alerts for W32/Chike, a worm that is capable of spreading through removable devices and network shares.

11/29: Lurka.a.sys a PE File Infector With Rootkit Functions

W32/Lurka.a.sys is a PE file infector in form of a kernel device driver with rootkit capabilities.

11/29: Drowor.B Worm Spreads by Infecting Executable Files

W32.Drowor.B is a worm that spreads by infecting executable files on mapped drives.

11/29: Drowor.B!inf Detects Executable Files Infected by Drowor.B Worm

W32.Drowor.B!inf is a detection for executable files infected by W32.Drowor.B worm.

11/28: Trojan.Voterai Ends Security-Related Processes

Trojan.Voterai is a Trojan horse that ends security-related processes on the compromised computer.

11/28: Zlob.ERT Trojan Displays Window Showing EULA

Troj_Zlob.ERT is a Trojan that may arrive as a file downloaded by other malware from a certain URL.

11/28: MSNFunny.D Worm Disables Windows Security Center

MSNFunny.D is a worm that disables the Windows security center, considerably reducing the protection level of the computer, which would leave it vulnerable against the attack of possible threats.

11/28: Trojan.Quimkids Exploits Apple QuickTime RTSP Flaw

Trojan.Quimkids is a proof-of-concept Trojan horse that exploits the Apple QuickTime RTSP Response Header Remote Stack Based Buffer Overflow Vulnerability.

Firefox Fixes Cross-Site Flaws

Mozilla developers plug XSS, XSRF and memory vulnerabilities in Firefox browser.

11/28: Likasimal Worm Changes Wallpaper on System

W32.Likasimal is a worm that spreads through network shares and changes the wallpaper on the compromised computer.

DKIM-a-Palooza

If you manage email systems and aren’t familiar with DKIM, you may still have time to learn about it. But you don’t have the luxury of ignoring it.

11/27: Arcer Virus Copies .Exe Files to Windows Systems Folder

W32/Arcer is a virus that will infect Windows systems.

11/27: Gexin Worm Spreads Via Removable Drives, Network Shares

W32/Gexin is a worm that will infect Windows systems and spreads through removable drives and network shares.

11/27: OnlineG-Z Worm Copies Itself to Removable Storage Devices

W32/OnlineG-Z is a worm for the Windows platform.

11/27: Rdropper.A Trojan Exploits Flaw in WinRAR Archiver

Troj_Rdropper.A is the Trend Micro detection for malicious WinRAR files (RAR) that take advantage of a vulnerability in WinRAR Archiver.

11/27: Heular Worm Copies Itself, Lowers Security Settings

W32.Heular is a worm that copies itself across logical and removable drives and lowers security settings.

11/26: Pushdo.AR Trojan Arrives as Email Attachment

Troj_Pushdo.AR is a Trojan that arrives either as an email attachment to messages spammed by other malware or a malicious user.

11/26: Dload-AA a Windows Trojan

Troj/Dload-AA is a Trojan for the Windows platform.

11/26: Backi.C Worm May End Security-Related Processes

W32.Baki.C is a worm that spreads through mapped drives.

11/26: PWS-JV Trojan Runs Silently

PWS-JV is a Trojan that runs silently, no gui messages appear on the screen.

11/26: VBS/Downloader-BEN Trojan Drops PE Executable File

VBS/Downloader-BEN is a very small Trojan whose solely aim is to download a 32 bit PE executable file and write it to the root of the c: drive as: "c:\Rtsecar.exe."

11/26: KillFil-BR Trojan Targets Windows

Troj/KillFil-BR is a Trojan for the Windows platform.

11/26: Trojan.Quimkit Exploits Apple QuickTime Flaw

Trojan.Quimkit is a proof-of-concept Trojan horse that exploits the Apple QuickTime RTSP Response Header Remote Stack Based Buffer Overflow Vulnerability

11/26: Agentbyp.al Trojan Arrives as Spammed Attachment

Troj_Agentbyp.al is a Trojan that arrives as attachment to email messages spammed by another malware or a malicious user.

11/26: Pushdo.BI Trojan Triggers Download Upon Visit to Certain URL

A download of Troj_Pushdo.BI Trojan is triggered when an unsuspecting user visits a certain URL.

11/26: Gexin.a Worm Spreads Via Removable Devices, Shares

W32/Gexin.a is a worm that is capable of spreading through removable devices and network shares.

11/21: MSNWorm.BB Worm Spreads Via MSN Messenger IM

MSNWorm.BB is a worm whose main objective is to spread and affect as many computers as possible.

11/21: RSTDoor-B a Backdoor Trojan for Unix

Troj/RSTDoor-B is a backdoor Trojan for Unix-based platforms running PHP and HTTPD.

11/21: KillAV-EC Trojan Disables Anti-Virus, Other Security Software

Troj/KillAV-EC is a Trojan for the Windows platform.

11/21: Shangxing.A Worm Opens Back Door on System

W32.Shangxing.A is a worm that opens a back door on the compromised computer.

11/21: Kaiten-W a Backdoor Trojan for Linux

Troj/Kaiten-W is a backdoor Trojan for the Linux platform.

11/21: OpenCD Trojan Opens CD Rom Drive

OpenCD is a Trojan that when executed, immediately opens up the CD Rom drive.

11/20: Dloader.QRQ Trojan Arrives as Email Attachment

Troj_Dloader.QRQ is a Trojan that arrives as an attachment to email messages spammed by another malware or a malicious user.

11/20: Keylog-LMtry Trojan Steals User Information

Keylog-LMtry is a Trojan that attempts to steal information from a user's system.

11/20: Voterai.worm.d Turns User Machine Into Zombie

W32/Voterai.worm.d is a destructive worm designed to perform a dubious political campaign for Kenya elections.

11/20: O97M.Dropper Trojan Detects Other Threats

O97M.Dropper Trojan detects Microsoft Office macros that drop other threats.

11/19: Unubot-A Worm Has IRC Backdoor Functionality

W32/Unubot-A is a worm with IRC backdoor functionality for the Windows platform.

11/19: PDrop-B a Windows Trojan

Troj/PDrop-B is a Trojan for the Windows platform.

11/19: StraDr-A Trojan Hits Windows

Troj/StraDr-A is a Trojan for the Windows platform.

11/19: Lecivio.worm Copies Itself to Root of Disk Volumes

W32/Lecivio.worm attempts to copy itself to the root of any accessible disk volumes.

11/19: Unubot-B Worm Has IRC Backdoor Functions

W32/Unubot-B is a worm with IRC backdoor functionality for the Windows platform.

11/19: Downloader-BFX Trojan Contacts Remote Sites

Downloader-BFX is a Trojan that upon manual execution, immediately connects to remote sites to download further files from.

11/16: Backdoor-DLE Trojan Defrauds eBay Users

Backdoor-DLE is designed to defraud eBay users.

11/16: BraveSentry Rogue Security Program Detects, Scans Malware

BraveSentry is a rogue security program that is designed to scan and detect malware on a computer.

11/16: Bagle-TC Worm Spreads Via eMule P2P Network

W32/Bagle-TC is a worm for the Windows platform.

11/16: MedPlg-A a Windows Trojan

Troj/MedPlg-A is a Trojan for the Windows platform.

11/16: MedPlg-A Trojan Targets Windows

Troj/MedPlg-A is a Trojan for the Windows platform.

11/16: Zlob-AGB a Windows Trojan

Troj/Zlob-AGB is a Trojan for the Windows platform.

11/16: Tvido.A Virus Infects Executable Files

W32.Tvido.A is a virus that infects executable files on local and mapped drives.

11/15: Jardo-A a Windows Trojan

Troj/Jardo-A is a Trojan for the Windows platform.

11/15: PWS-Mmorpg Trojan Steals Game Passwords

PWS-Mmorpg is a Trojan written in Borland Delphi, that attempts to steal passwords information for popular online MMORPG games.

11/15: Kango-D Trojan Accesses Internet, Contacts Remote Server

Troj/Kango-D is a Trojan for the Windows platform.

11/15: Trojan.Falupan May Lower Security Settings

Trojan.Falupan is a Trojan horse that may lower security settings on the compromised computer.

11/15: Dropper.DCU Trojan Drops Fake Microsoft Windows Patch

Troj_Dropper.DCU is a Trojan that arrives as a file downloaded from certain remote sites.

11/15: Nuwar-D a Windows Worm

W32/Nuwar-D is a worm for the Windows platform.

Virus Infections Reflect Sloppy Manufacturing

Maxtor drive infection the latest example of what happens when manufacturing systems are connected to that virus haven known as the Internet.

11/15: Sobarbo Virus Drops Several Files When Executed

W32/Sobarbo is a virus that upon execution drops several files.

11/15: Backdoor.Bandock.A Trojan Opens Back Door

Backdoor.Bandock.A is a Trojan horse that opens a back door on the compromised computer.

11/14: Wixud-B Trojan Hits Windows

Troj/Wixud-B is a Trojan for the Windows platform.

11/14: Vora.worm!p2p Shows 'Doomsday' Message When Run

W32/Vora.worm!p2p is a worm that when run, shows a small GUI message box on the screen.

11/14: Rbot-GVC a Windows Worm

W32/Rbot-GVC is a worm for the Windows platform.

11/14: Sdbot-DIT Worm Has Backdoor Functions

W32/Sdbot-DIT is a worm with IRC backdoor functionality for the Windows platform.

11/14: VBDrop-D a Windows Trojan

Troj/VBDrop-D is a Trojan for the Windows platform.

11/14: Motsys Worm Copies Itself to Removable Drives to Spread

W32.Motsys is a worm that spreads by copying itself to removable drives.

11/14: Hakaglan.worm Spreads Via Yahoo! IM, Removable Drives, Shares

W32/Hakaglan.worm is a worm written in AutoIT that spreads via Yahoo Messenger, removable drives and network shares.

11/13: VBS.Invadesys.A Worm May Lower Security Settings

VBS.Invadesys.A is a worm that spreads through removable drives.

11/13: Sdbot-DIS Worm Has IRC Backdoor Functions

W32/Sdbot-DIS is a worm with IRC backdoor functionality for the Windows platform.

11/13: Sdbot.worm.gen.z Spreads Via Poorly-Secured Networks

The W32/Sdbot.worm.gen.z propagates via accessible or poorly-secured network shares.

11/13: Worm_Agent.AFFZ Drops Copies of Itself, Components

Worm_Agent.AFFZ arrives as a file downloaded from the Internet.

11/13: Dloader.SHB Trojan is Dropped or Unknowingly Downloaded

Troj_Dloader.SHB is a Trojan that arrives on a system as a file dropped by other malware.

11/13: IRCBot-ZA Worm Includes Backdoor Functionality

W32/IRCBot-ZA is a worm for the Windows platform that also includes backdoor functionality.

Microsoft Beefs Up Office Security

Microsoft offers a tool to automate security settings in Office to protect against malicious files.

11/12: Zlob.DCY Trojan Poses as Codec Installer

Troj_Zlob.DCY is a Trojan that is usually downloaded from the Internet by HTML_DLOADER.WLZ and is installed by unsuspecting users.

11/12: Mabezat-A Virus Copies Itself to Shares, Removable Drives

At least two security vendors have issued alerts for W32/Mabezat-A, a virus for the Windows platform that also spreads by copying itself to network shares and removable devices.

11/12: Zlob-AFW a Windows Trojan

Troj/Zlob-AFW is a Trojan for the Windows platform.

11/12: Farfli.EY Trojan May be Dropped, Downloaded

Troj_Farfli.EY is a Trojan that may be dropped or downloaded from remote sites by other malware.

11/12: HTML_Dloader.WLZ Malicious HTML File Downloaded Unknowingly

HTML_Dloader.WLZ is a malicious HTML file that may be downloaded unknowingly by a user when visiting malicious Web sites.

11/12: Hupigon-SU a Windows Trojan

Troj/Hupigon-SU is a Trojan for the Windows platform.

11/12: PWS-JU Trojan Shows .Jpeg of Dog

PWS-JU is a Trojan that upon running, shows a small .jpeg picture of a dog in clothes appears on the screen, using caption/title "error".

11/12: VBS.Invadesys.A Worm Spreads Via Removable Drives

VBS.Invadesys.A is a worm that spreads through removable drives.

11/9: Imaut.BH Worm Spreads Via Yahoo! IM

W32.Imaut.BH is a worm that spreads through Yahoo! Instant Messenger and removable drives.

11/9: Ciadoor-DQ a Windows Trojan

Troj/Ciadoor-DQ is a Trojan for the Windows platform.

11/9: Baki.A Worm Disables Security-Related Processes

W32.Baki.A is a worm that spreads by copying itself to local and removable drives. It

11/9: MDrop-BPY Trojan Dropped by Other Malware

Troj/MDrop-BPY is a dropper Trojan for the Windows platform.

11/8: Nuwar.ARJ Worm Drops, Executes Files/Components

Worm_Nuwar.ARJ arrives as an email attachment spammed by other malware or a malicious user.

11/8: IRCBot-YZ Worm Hits Windows

W32/IRCBot-YZ is a worm for the Windows platform.

11/8: Anti-C Worm Hits Windows

W32/Anti-C is a worm for the Windows platform.

11/8: Brontok-DP Worm Copies Itself to Network, Removable Drives

W32/Brontok-DP is a worm for the Windows platform.

11/8: Sonebot-C a Windows Worm

W32/Sonebot-C is a worm for the Windows platform.

11/7: Worm_Zhelati.AXD Uses Own SMTP Engine to Send Mail

Worm_Zhelati.AXD may be downloaded from remote sites by other malware.

11/7: Downloader-BFT Trojan Drops, Installs Files

Downloader-BFT is a Trojan that upon execution runs silently, no gui messages appear on the screen.

11/7: Agent-GFG a Windows Trojan

Troj/Agent-GFG is a Trojan for the Windows platform.

11/7: Virut-S a Windows Virus

W32/Virut-S is a virus for the Windows platform.

11/7: SpyBot-OD Worm Targets Windows

W32/SpyBot-OD is a worm for the Windows platform.

11/7: PWS-Yahmali a Password-Stealing Trojan

PWS-Yahmali is a password-stealing Trojan that targets Yahoo Messenger and steals username and password entered by the user.

Norton Internet Security 2008: Faster, Stronger, Edgier Protection for Your PC

They're everywhere and they're out to get you. No, this isn't a "B" horror movie; it's the deluge of viruses, spyware and hackers assaulting your PC every day. Symantec's latest Norton Internet Security 2008 release is equipped to protect your personal data.

11/7: SdBot-DIP Worm Targets Windows

W32/SdBot-DIP is a worm for the Windows platform.

11/6: Nofupat Network Worm Causes Extensive Registry Damage

W32/Nofupat is a network worm that causes extensive damage to the registry, primarily in changing valid text throughout the system into graffiti text.

11/6: Generic Dropper.P Trojan Drops Other Malware

Generic Dropper.p is a Trojan dropper file containing other binaries within its body.

11/6: Expl_Pidief.L Exploit Code Targets PDF Mailto Flaw

Expl_Pidief.L is the Trend Micro detection for an exploit code that takes advantage of the PDF Mailto vulnerability in Adobe Acrobat and Adobe Reader 8.1.

11/6: Delf-EYT Trojan Downloads, Installs and Runs New Software

Troj/Delf-EYT is a Trojan for the Windows platform.

11/6: Virut-R an Executable Virus

W32/Virut-R is an executable file virus for the Windows platform.

11/6: SdBot-DIN Worm Hits Windows

W32/SdBot-DIN is a worm for the Windows platform.

11/6: Astry.A Trojan Prevents User From Modifying Folder Settings

Astry.A is a Trojan that prevents the user from modifying the folder settings through the option Folder Options of the Windows Explorer.

11/5: Linkfars Worm Copies Itself to Drives, File-Sharing Folders

W32.Linkfars is a worm that spreads by copying itself to removable drives, file-sharing application folders, and shared folders by replacing existing .exe files.

11/5: Proyo Virus Prepends Its Viral Code to PE Executables

W32.Proyo is a virus that prepends its viral code to all PE executables whose extension is .exe or .scr on all fixed drives and removable drives.

11/5: Trojan.Pidief.B Downloads Files, Exploits Remote Flaw

Trojan.Pidief.B is a Trojan horse program that downloads files from a remote location and exploits a remote vulnerability.

11/2: Conhook-AI a Windows Trojan

Troj/Conhook-AI is a Trojan for the Windows platform.

11/2: PWS-Banker.dldr Detects Password-Stealing Trojans

PWS-Banker.dldr is a generic detection for Trojans that try to download password stealers that capture bank account information (username/password) and sends this information to the author.

11/2: VBS.Runauto.E Worm Copies Itself to Drives

VBS.Runauto.E is a worm that spreads by copying itself to all drives except floppy drives.

11/2: Virut.J a File-Infecting Virus

W32/Virut.j is a file infecting virus with IRC based backdoor functionality.

11/2: Unix_DNSChan.A a Malicious Bash Script

Unix_DNSChan.A is a malicious Bash script that arrives as a dropped file of OSX_DNSCHAN.A.

11/2: MSNPhoto.I Worm Stops Windows Security Center, VNC Service

MSNPhoto.I is a worm that its main objective is to stop the Windows Security Center service and VNC service if installed.

Security By the Numbers

A study of 450 small business IT managers shows that many small businesses aren't as protected as they might think.

11/2: Mal/Bifrose-F a Malicious Windows Program

Mal/Bifrose-F is a malicious program for the Windows platform.

11/1: OSX/Puper Trojan Pretends to be Codec Installer

OSX/Puper is a Trojan that purports to be a codec installer, to help the user view videos.

11/1: Zlob-AFI a Windows Trojan

Troj/Zlob-AFI is a Trojan for the Windows platform.

11/1: Mypis-B Virus Targets Windows

W32/Mypis-B is a virus for the Windows platform.

11/1: Exploit:W32/AdobeReader.K a Malicious PDF File

Exploit:W32/AdobeReader.K is a detection for a malicious PDF file that is being heavily spammed through e-mail and it appears as an attachment.

11/1: BatKill-B a Windows Trojan

Troj/BatKill-B is a Trojan for the Windows platform.

11/1: OSX_DNSChan.A Trojan Arrives as .DMG File

OSX_DNSChan.A is a Trojan that can be downloaded from http://{BLOCKED}odec.com/download/ultracodec{number}.dmg.

11/1: GenericPWS.y Detects Password-Stealing Trojans

GenericPWS.y is a detection for many non-descript password-stealing Trojans.

11/1: Trojan.Peacomm.D Gathers System Info, Email Addresses

Trojan.Peacomm.D is a Trojan horse that gathers system information and email addresses from the compromised computer.

11/1: OSX.RSPlug.A Mac Trojan Changes DNS Settings

OSX.RSPlug.A is a Trojan horse that runs on Macintosh OS X and changes the DNS settings on the compromised computer.

11/1: Noia.a.2465 a Downloader Virus

W32/Noia.a.2465 downloader virus is a detection for files that have been infected by W32/Noia.a.