Click here

Malware: Archive: December 2007 

12/31: ASP/Backdoor-gen Detects Script Files Controlling a Web Server

ASP/Backdoor-gen is a generic detection for script files (usually VB) that are used to control a web server running asp extensions.

CSI Survey 2007, Part 3: Tech and Tribulations

In this final part of the series, we examine the security technologies companies employ to protect their networks. That is, when they even bother...

12/31: PE_Trats.A-O File Infector May be Dropped, Downloaded

PE_Trats.A-O is a file infector that may be dropped by other malware.

12/31: VB-DYF Windows Worm

W32/VB-DYF is a worm for the Windows platform.

12/28: Agent-GKH a Downloader Trojan

Troj/Agent-GKH is a downloader Trojan for the Windows platform.

12/28: Puper Trojan Offers Fake Codec on Bhutto Assassination

A new variant of the Puper Trojan is attempting to spread on the premise that it offers a codec to see a video of the suicide attack that killed Pakistani Prime Minister Benazir Bhutto.

12/28: QHosts-96 Trojan Modifies Local HOSTS File

QHosts-96 is a Trojan that modifies the local HOSTS file.

12/28: VB.Hc Worm Copies Itself, Modifies Registry

W32/VB.Hc is a worm that infects Windows systems.

12/28: Kibik.b a Parasitic Virus That Installs a Backdoor Proxy

W32/Kibik.b is a parasitic virus that will install a backdoor proxy.

12/28: Exploit-PPT.i Trojan Exploits PowerPoint Flaws

Exploit-PPT.i is a Trojan detection that covers specially crafted files attempting to exploit vulnerabilities in Microsoft PowerPoint to drop malware files.

12/28: DNSChanger.h Trojan Changes DNS Server Address

DNSChanger.h is a Trojan that changes the DNS server address to point to its preferred DNS, upon installation.

12/28: JS_Agent.AEVE Malicious JavaScript Unknowingly Downloaded

JS_Agent.AEVE is malicious JavaScript may be downloaded unknowingly by a user when visiting compromised Web pages that have a certain IFrame tag.

12/28: DNSChanger.f.dr Trojan Changes Default DNS Entries

DNSChanger.f.dr is a Trojan whose main objective is to change the default DNS entries to its own preferred DNS server.

12/28: VBS/Psyme Trojan Offering Fake Bhutto Attack Video

A new variant of VBS/Psyme Trojan is part of a threat attempting to spread on the premise that it offers a codec to see a video of the suicide attack that killed Pakistani Prime Minister Benazir Bhutto.

12/28: MsnChirstmas.A Worm Sends Messages to MSN Messenger Contacts

MsnChirstmas.A is a worm that sends messages with the worm to all our contacts of MSN Messenger.

2008: Year of Innovation, Both Good And Evil

Who will break more ground in the coming year: multi-billion dollar hardware companies or Russian malware gangs?

12/28: Ranetif Worm Opens Back Door, Infects Files

W32.Ranetif is a worm that opens a back door and infects files.

12/27: Yahmail.A Trojan Steals Yahoo IM User Passwords

Yahmail.A is a Trojan steals user passwords of the Instant Messaging Program "Yahoo Messenger" from the infected computer.

12/27: Onlinegames.Lov.PSW a Windows Trojan

W32/Onlinegames.Lov.PSW is a Windows systems Trojan.

12/27: VirtInf-A a Windows Virus

W32/VirtInf-A is a virus for the Windows platform.

12/27: Dload-AF a Downloader Trojan

Troj/Dload-AF is a downloader Trojan for the Windows platform.

12/26: Dload-AE a Multi-Component Downloader Trojan

Troj/Dload-AE is a multi-component downloader Trojan for the Windows platform.

12/26: BackDoor-CKB.sys Trojan Installs Rootkit

BackDoor-CKB.sys Trojan is the rootkit component of BackDoor-CKB.

12/26: W32/Checkout!Oe4a3c52 Worm Spreads Via MSN Messenger

W32/Checkout!Oe4a3c52 is a variant of the W32/Checkout worm, which was found spreading through MSN Messenger during Christmas day.

12/26: Zhelati.AIS Worm Arrives as Spam Mail Attachment

Worm_Zhelati.AIS arrives as attachment to email messages spammed by another malware or a malicious user.

12/26: Mydoom.BD Worm Drops Files, Injects Threads into Process

Worm_Mydoom.BD drops several files upon execution.

12/26: Trojan.Virantix.B Ends Antivirus Apps, Displays Fake Security Alert

Trojan.Virantix.B is a Trojan horse that ends antivirus applications and displays a fake security alert.

12/26: Mubla.Gen Detects Mubla Worm Variants

W32.Mubla.Gen is a generic detection for variants of the W32.Mubla family of worms.

12/26: Lurkasys.A Virus Infects Executable Files

W32.Lurkasys.A is a virus that infects executable files.

12/26: BBDoS-A a Unix Trojan

Troj/BBDoS-A is a Trojan for Unix platforms.

12/26: Casail Worm Spreads Via Removable, Local Drives

W32/Casail is a worm that will infect Windows systems and spreads through removable drives and local drives.

12/26: Vapka.A Worm Copies Itself to Removable Media, Steals Info

W32.Vapka.A is a worm that spreads by copying itself to removable media and steals confidential information.

12/24: Autorun.worm.i.gen Worm Spreads to Removable Drives

W32/Autorun.worm.i.gen is a worm that attempts to spread to removable drives by creating an autorun.inf file, which will run the worm automatically, if a system that uses the removable drive is set to Autorun.

12/24: JS_Orkut.A Malicious JavaScript Searches Orkut Accounts

JS_Orkut.A is malicious JavaScript that may be dropped by other malware.

12/24: Trojan.Bankpatch.B Blocks Access to Security Sites

Trojan.Bankpatch.B is a Trojan horse that blocks Internet access to certain security-related Web sites.

You've Got Spam: The New Field of Reputation Management

Certain email snafus can be fatal to the effectiveness of a company's entire email strategy and can tarnish the goodwill associated with their good name.

12/21: MutRK-A a Rootkit Trojan

Troj/MutRK-A is a rootkit Trojan for the Windows platform.

12/21: Qhost.GC Trojan is Unknowingly Downloaded

Troj_Qhost.GC is a Trojan that can be downloaded unknowingly by a user when visiting malicious Web sites.

12/21: Evata.A Worm Makes Several Windows Registry Modifications

Evata.A is a worm that carries out plenty of modifications in the Windows Registry, which prevents the user from working with the computer as usual.

12/21: Agent.CFT Trojan Executes Itself Automatically

W32/Agent.CTF is Windows systems Trojan.

12/20: Agent-GJR a Windows Trojan

Troj/Agent-GJR is a Trojan for the Windows platform.

Trojan Found in Google Text Ads

BitDefender says ads placed by Google in Web pages are being hijacked by Trojan software that replaces the intended text with ads from a different provider.

12/20: QHosts-95 Trojan Modifies Windows Hosts File

QHosts-95 Trojan modifies the Windows hosts file to redirect accesses to Google Adsense to a malicious remote site.

12/20: Casail.A Worm Steals Sensitive Information

W32.Casail.A is a worm that spreads through removable drives.

12/20: Trojan.Qhosts.F Modifies Hosts File

Trojan.Qhosts.F is a Trojan horse that modifies the hosts file on the compromised computer.

12/20: Expl_Realplay.H Exploit Runs When Site is Accessed

Expl_Realplay.H is an exploit that is hosted on a Web site and runs when a user accesses the said Web site.

12/20: VB.KK.Dropper Trojan Installs Game Upon Execution

W32/VB.KK.Dropper is a Windows Trojan.

Firefox 3 Beta 2 Arrives Early

Mozilla tries to make up for lost time with new release packing in security and functionality enhancements.

12/19: KutWormor Virus Infects User With Orkut

W32/KutWormor is a virus that will add the user on a community called "Infectados pelo Virus Orkut," which means "Infected by the Orkut Virus" and start to send scraps (messages on orkut model) to the friends of the infected user.

12/19: JS.Woorkut Worm Spreads Via Orkut Online Community

JS.Woorkut is a worm that spreads through the Orkut online community.

12/19: SillyDFC-BQ a Spyware Worm

W32/SillyFDC-BQ is a spyware worm for the Windows platform.

12/19: Agent-GJL a Windows Trojan

Troj/Agent-GJL is a Trojan for the Windows platform.

12/19: Drop-D a Windows Trojan

Troj/Drop-D is a Trojan for the Windows platform.

12/19: Onlinegames.Isb.PSW Trojan Copies Itself, Drops Files

W32/Onlinegames.Isb.PSW is a Trojan that will infect Windows systems.

Security Alarm Sounded on Gmail and IE

Security vendor Cenzic claims its found vulnerabilities that both Microsoft and Google aren't taking seriously.

12/18: Nahkos.A Worm Prevents User From Executing Certain Actions

Nahkos.A is a worm that prevents the user from carrying out certain actions.

12/18: Onlinegames.Isb.PSW Trojan Infects Windows Systems

W32/Onlinegames.Isb.PSW is a Trojan that will infect Windows systems.

12/18: Tarodrop.AB a Trojan Ichitaro Document File

Troj_Tarodrop.AB is a Trojan document file used by Ichitaro, a popular word processing application in Japan produced by JustSystem.

12/18: Dloadr-BGR Trojan Contacts Remote Server Via HTTP

Troj/Dloadr-BGR is a Trojan for the Windows platform.

12/18: Exploit-TaroDrop.d Trojan Exploits Ichitaro Flaw

Exploit-TaroDrop.d Trojan detects files attempting to exploit a 0-day vulnerability in JustSystem Ichitaro discovered in December 2007.

12/18: Etap a Cross-Platform Metamorphic Virus

W32/Etap is a highly complicated cross-platform metamorphic virus, which infects both Windows PE executables and Linux/UNIX ELF format executables.

12/17: YMWorm-A an IM Worm

W32/YMWorm-A is an instant messenger worm for the Windows platform.

12/17: BankDL-DC a Windows Trojan

Troj/BankDL-DC is a Trojan for the Windows platform.

12/17: Rbot-GVO a Worm and Backdoor Trojan

W32/Rbot-GVO is a worm and backdoor Trojan for the Windows platform.

12/17: Trojan.Silentbanker Records Strokes, Captures Images, Steals Info

Trojan.Silentbanker is a Trojan horse that records keystrokes, captures screen images and steals confidential financial information to send to the remote attacker.

12/17: Proxy-IB a Proxy Server Trojan

Troj/Proxy-IB is a proxy server Trojan for the Windows platform.

12/17: IRCBot-ZM a Windows Trojan

Troj/IRCBot-ZM is a Trojan for the Windows platform.

Report: One In Six Computers Has Spyware Infection

So says a company that sells a rootkit detection and removal product. But at least one analyst concurs that rootkit removal needs work.

12/14: Looked-EB a Virus and Network Worm

W32/Looked-EB is a virus and network worm for the Windows platform.

12/14: Asprox.A Trojan Opens TCP Port for Proxy

Troj_Asprox.A is a Trojan that opens TCP port 80 and acts as a proxy server to allow a remote malicious user to use the affected system in concealing the said author's identity when performing malicious activities.

12/13: Divvi.a Virus a Parasitic File Infector

W32/Divvi.a virus is a parasitic file infector, which appends its code to EXE files.

12/13: Trojan.Tarodrop.F Exploits Ichitaro App Flaw

Trojan.Tarodrop.F is a Trojan horse that attempts to exploit an unspecified vulnerability in the JustSystem Ichitaro application.

12/13: Atax-A a Windows Worm

W32/Atax-A is a worm for the Windows platform.

12/13: Voterai.worm.f Disables Many System Settings

W32/Voterai.worm.f is a destructive worm designed to perform a dubious political campaign for Kenya elections.

12/13: Tanto-G Trojan Targets Windows

Troj/Tanto-G is a Trojan for the Windows platform.

12/13: AdClicker-FI Detects Trojan's .Exe File

AdClicker-FI is a detection is for the .EXE file dropped by the AdClicker-FI.dr Trojan.

12/13: AdClicker-FI.dr Trojan a Self-Extracting RAR File

AdClicker-FI.dr is a Trojan that comes as a self-extracting (SFX) RAR file.

12/12: Autorun.worm.bd Spreads By Copying Itself Over Media, Drives

W32/Autorun.worm.bd is a worm that propagates by making copies of itself over removable media and network drives.

12/12: Mypis-Fam a Family of Infected Executable Files

W32/Mypis-Fam is a family of infected executable files that has been patched to download and execute malware from a remote location.

12/12: Blehs-A a Windows Worm

W32/Blehs-A is a worm for the Windows platform.

12/11: Mubla.C Worm Uses Email, MSN Messenger to Spread

W32.Mubla.C@mm is a mass-mailing worm that spreads through email and MSN Messenger.

12/11: PWS-LDPinch.cfg a Component of PWS-LDPinch Trojan

PWS-LDPinch.cfg is the server configurator component of the PWS-LDPinch Trojan.

12/11: Revkey-A a Hacked Copy of "Actual Spy" Keylogger

Troj/Revkey-A is a hacked copy of the commercial "Actual Spy" keylogger.

12/11: KillAV-ED Trojan Hits Windows

At least two security vendors hae issued alerts for Troj/KillAV-ED, a Trojan for the Windows platform.

12/11: Kangero.A Worm Lowers Security Settings

W32.Kangero.A is a worm that copies itself to mapped drives.

12/11: Cargar-A a Windows Trojan

Troj/Cargar-A is a Trojan for the Windows platform.

12/11: Psyme-GB Trojan Exploits Brower Flaw

Troj/Psyme-GB is a Trojan for the Windows platform.

12/10: Trojan.Palusad Bypasses Security Alerts

Trojan.Palusad is a Trojan horse that bypasses alerts triggered by Registry Monitor, a security software used in China.

12/10: Mabezat Worm Spreads Via Removable Drives, Shares

W32/Mabezat is a worm that is capable of spreading through removable devices and network shares.

12/10: SillyP2P-A a Windows Worm

W32/SillyP2P-A is a worm for the Windows platform.

12/10: StartP-W Trojan Hits Windows

Troj/StartP-W is a Trojan for the Windows platform.

12/10: PPntDrop-A a Windows Trojan

Troj/PPntDrop-A is Trojan for the Windows platform.

12/10: Vundo.ZE Trojan Arrives as Dropped or Downloaded File

W32/Vundo.ZE is a Trojan that infects Windows systems.

Cenzic Virtualizes Security

Worried that application vulnerability testing will bust your production environment? Don't be... "real."

U.S. Lab Falls Victim to Phishing Attack

Thieves stole 14 years of visitors' personal data in a sophisticated targeted attack.

12/7: Downloader-BDH a Downloader Trojan

Downloader-BDH is a downloader Trojan, which when executed, could further download more malicious components from the web and install them on the victim’s machine.

12/7: Downloader-BEZ Trojan Drops More Malicious Components

Downloader-BEZ is a downloader Trojan, which when executed, could further download more malicious components from the web and install them on the victim’s machine.

12/7: Trats Virus Infects Executable Files

W32.Trats is a virus that infects executable files on the compromised computer.

12/7: Agent-GIL A Windows Trojan

Troj/Agent-GIL is a Trojan for the Windows platform.

12/7: Autorun-X Worm Targets Windows

W32/Autorun-X is a worm for the Windows platform.

12/7: Baki.D Worm Copies Itself to Local, Removable Drives

W32.Baki.D is a worm that spreads by copying itself to local and removable drives.

12/7: Rarbeauty Worm Attaches Itself to Outlook Emails

W32.Rarbeauty@mm is a mass-mailing worm that spreads by attaching itself to emails sent to all Microsoft Outlook contacts.

12/7: Chod.S Worm Spreads Via Microsoft IM Clients

W32.Chod.S is a worm that spreads through Microsoft instant messaging clients.

12/7: HTML_Iframe.HT Detects Malicious HTML Scripts

HTML_Iframe.HT is the detection of Trend Micro for malicious HTML scripts that contain malicious IFRAME tags.

12/6: Spy-Agent.cf Trojan Attempts to Steal User Information

Spy-Agent.cf is a Trojan that attempts to steal information from a user's system.

12/6: Heiku Worm Modifies IE Start Page

W32/Heiku worm will modify Internet Explorer's start page and change the window title.

12/6: Sdbot-DJE Worm Also an IRC Backdoor

W32/Sdbot-DJE is a network worm and IRC backdoor for the Windows platform.

12/6: DDoS-Rincux Trojan Modifies Registry Keys, Creates Service

DDoS-Rincux is a Trojan that performs certain actions.

12/6: Sohana-AP a Windows Worm

W32/Sohana-AP is a worm for the Windows platform.

12/6: Trats Virus Infects Executable Files

W32.Trats is a virus that infects executable files in the Startup folder and listed in the registry under the Run subkey.

12/6: Folmess Worm Copies Itself to all Folders

W32.Folmess is a worm that spreads by copying itself to all folders on the compromised computer.

12/5: Babelloh Worm Copies Itself to Shared Folders, Drives

W32.Babelloh is a worm that copies itself to shared folders and removable drives.

12/5: Dropper-SR a Dropper Trojan

Troj/Dropper-SR is a dropper Trojan for the Windows platform.

12/5: Vora.A Worm Spreads Through Multiple Means

Vora.A is a worm whose main aim is to spread and affect as many computers as possible.

12/5: Debsis.A Worm Copies Itself

W32.Debsis.A is a worm that spreads by copying itself to network shares and removable drives.

12/5: Bckdr-QKK a Windows Trojan

Troj/Bckdr-QKK is a Trojan for the Windows platform.

12/5: DDos-Rincux Trojan Performs Certain System Actions

DDos-Rincux is a Trojan that upon execution performs certain actions.

12/5: Niuniu.B Worm May Lower Security Settings

W32.Niuniu.B is a worm that spreads through removable drives.

12/5: Dloader.XAP Trojan Maybe be Dropped or Downloaded

Troj_Dloader.XAP is a Trojan that may be dropped by other malware.

12/5: HTML_Iframe.EN Detects URLs With Hidden iFRAME Links

HTML_Iframe.EN is Trend Micro's detection for URLs that contain hidden iFrame links that lead to the download of TROJ_AGENT.BRB.

12/4: Delf.NWZ Trojan Arrives in Fake US Justice Department Email

Troj_Delf.NWZ is a Trojan that arrives as an attachment to mass-mailed emails with a fake message from the U.S. Department of Justice.

12/4: Dronzho Worm Spreads Via Removable Storage Devices

W32.Dronzho is a worm that spreads through removable storage devices.

12/4: Wiepaz-A a Windows Trojan

Troj/Wiepaz-A is a Trojan for the Windows platform.

12/4: LiveDeath.A Trojan Disables Mouse, Deletes Files on C: Drive

LiveDeath.A is a Trojan that disables the mouse and deletes all the files from the C: drive that are not being run at that moment.

12/4: Vundo.ZE Trojan May Be Unknowingly Dropped, Downloaded

Troj_Vundo.ZE is a Trojan that may be dropped by other malware.

12/4: Drowor Worm Copies Itself in Windows Folder

W32/Drowor is a worm that will infect Windows systems.

McAfee, Cox Team Up On Broadband Security

The security software provider will offer a smorgasbord of antivirus and identity-protection applications to all high-speed Internet customers in 2008.

Google Wants Your Help to Fight Malware

Google hackers, however, need not worry; at least that's what Johnny 'I hack stuff' Long thinks.

12/3: Agent-GHN Trojan Hits Windows

Troj/Agent-GHN is a Trojan for the Windows platform.

US-CERT Warns of Unpatched QuickTime Flaw

UPDATED: No patch yet from Apple as the government issues a Technical Cyber Security Alert.

12/3: Mabezat-B Virus Copies Itself to Shares, Removable Drives

W32/Mabezat-B is a virus for the Windows platform that also spreads by copying itself to network shares and removable devices.

12/3: Autorun-T a Spyware Worm

W32/Autorun-T is a spyware worm for the Windows platform.

12/3: DrProt-Gen Trojan Pretends to be Anti-Spyware App

Troj/DrProt-Gen is a Trojan for the Windows platform.

12/3: Puper.dr Trojan Downloads Puper Trojan

Puper.dr is a Trojan designed to download the Puper Trojan from a remote site.

Data Loss Prevention Software Goes Interactive

New data loss prevention software from Trend Micro knows when you've been naughty and tells you so.

12/3: Smit-A Worm Copies Itself to Shares, Devices and Folders

W32/Smit-A is a worm for the Windows platform.

12/3: Mal/Accesso-A a Windows Trojan Dialer

Mal/Accesso-A is a Trojan dialer for the Windows platform.

12/3: Generic VB.b Trojan Creates Copies

Generic VB.b Trojan has variants that will create copies of themselves with the same name of folders of the location it was executed.

12/3: Agent-GHM a Windows Trojan

Troj/Agent-GHM is a Trojan for the Windows platform.