Click here

Malware: Archive: April 2008 

4/30: TinyDL-S a Malicious Windows Program

Mal/TinyDL-S is a malicious program for the Windows platform.

4/30: Killwin.AM Trojan Modifies HOSTS File to Block Sites

W32/Killwin.AM is a Trojan that will infect Windows systems.

4/30: Worm_Autorun.BSG Drops Copies of Itself in Removable Drives

Worm_Autorun.BSG may be downloaded from remote sites by other malware.

4/30: Trojan.Garntet Downloads Malicious Code

Trojan.Garntet is a Trojan horse that downloads potentially malicious code and opens a back door on the compromised computer.

4/30: Buzuz-A Trojan Runs Continuously in the Background

Troj/Buzus-A is a Trojan for the Windows platform.

4/30: Gida-D a Shockwave Flash Trojan

Troj/Gida-D is a Shockwave Flash Trojan.

4/30: Imaut-C Worm Copies Itself, Creates Files

W32/Imaut-C is a worm for the Windows platform.

4/30: Zatyudi.A Worm Copies Itself to Network Shares, Drives

W32.Zatyudi.A is a worm that copies itself to network shares and removable drives.

4/30: Malas-C Worm Targets Windows Systems

W32/Malas-C is a worm for the Windows platform.

4/29: Mal/LinBDoor-A Trojan Targets Unix Operating Systems

Mal/LinBDoor-A Trojan targets the Unix operating system.

4/29: Mal/Dloadr-E an Executable File

Mal/Dloadr-E is an executable file with characteristics typical of downloader Trojans.

4/29: PWS-FerTP Trojan Steals FTP Account Details

PWS-FerTP is a Trojan that attempts to steal FTP account details on infected machines and posts them to a remote server.

4/29: Mal/Zlob-O a Malicious WIndows Program

Mal/Zlob-O is a malicious program for the Windows platform.

4/29: Banker.LVH Trojan Infects Windows Systems

W32/Banker.LVH is a Trojan that will infect Windows systems.

4/29: Lineag-DL Trojan Copies Itself, Creates Files

Troj/Lineag-DL is a Trojan for the Windows platform.

4/29: Trojan.Qipian Steals System Information

Trojan.Qipian is a Trojan horse that steals information from the compromised computer.

4/29: Trojan.Asnoms!inf Detects Files Modified For Malicious Purposes

Trojan.Asnoms!inf is a detection for files that have been modified to load other malicious files during system start up.

4/28: Bobandy-D a Mass-Mailing Worm

W32/Bobandy-D is a mass-mailing worm for the Windows platform.

4/28: Smalla-Gen Trojan Targets Windows Systems

Troj/Smalla-Gen is a Trojan for the Windows platform.

4/28: DwnLdc-Gen a Downloader Trojan

Troj/DwnLdc-Gen is a downloader Trojan for the Windows platform.

4/28: Inja-Gen Trojan Injects Code Into Processes

Troj/Inja-Gen is a Trojan for the Windows platform.

4/28: Torpig-BZ Trojan Creates Files Upon Installation

Troj/Torpig-BZ is a Trojan for the Windows platform.

4/28: Mandaph Worm Spreads Through Mapped, Fixed Drives

W32.Mandaph is a worm that spreads through mapped and fixed drives, and downloads additional malware.

4/28: Agent-GXG Trojan Copies Itself to Systemroot Folder

Troj/Agent-GXG is a Trojan for the Windows platform.

4/25: Troj/Bckdr-QNE Creates Registry Entry

When run Troj/Bckdr-QNE copies itself and creates an entry in the registry.

4/25: Mal/ObfJS-AJ is Hidden Script

Mal/ObfJS-AJ is a script obfuscated in a manner typical of malware.

4/24: Mal/Behav-222 is Windows Malware

Detecting members of Mal/Behav-222 is based on behavior based.

4/24: Trojan.Mdropper.AB Arrives by Email

Trojan.Mdropper.AB is a Trojan horse that arrives through email as an MS Office file and downloads additional malware on to computer.

4/24: Troj/Badsrc-B Loads Scripts

Troj/Badsrc-B is a web page that has been compromised to load a script from a malicious website.

4/23: Privacy Watcher is Misleading App

PrivacyWatcher is a misleading application that may give exaggerated reports of threats on the computer.

4/23: JS/Psyme-IL is Malicious JavaScript.

JS/Psyme-IL is malicious JavaScript.

4/22: Mal/EncPk-DJ Used by Malware Authors

Mal/EncPk-DJ is a app written with a protection system typically used by malware authors.

4/22: W32.Bancotrep@mm Drops Video File

W32.Bancotrep@mm puts a video file on the local hard drive.

4/22: W32/Autorun-DL Spreads to Removable Devices.

The W32/Autorun-DL worm includes code to download, install and run new software.

4/21: Mal/ObfJS-AH is Malicious Javascript

Mal/ObfJS-AH is a JavaScript that tries to download more malicious content from a remote server.

4/21: Mal/Behav-220 Installs in Registry

Mal/Behav-220 installs itself in the registry.

4/18: Rbot-GWW Worm Has Backdoor Functions

W32/Rbot-GWW is a network worm with backdoor Trojan functionality for the Windows platform.

4/18: FakeAV-L Trojan Creates Bogus Message

Troj/FakeAV-L creates Windows MsgBox to display a message.

4/18: JS/Exploit-WkImgSrv Detects Microsoft Works Flaw

JS/Exploit-WkImgSrv is a detection for an exploit for a vulnerability in Microsoft Works.

4/18: Mal/JSShell-G Detects PDF Files With Malicious Code

Mal/JSShell-G detects PDF files containing malicious code that exploits vulnerabilities in older versions of Adobe Acrobat.

4/18: DwnLdr-HCN Trojan Drops Files, Changes WinSock

Troj/DwnLdr-HCN is a Trojan for the Windows platform.

4/18: AutoRun-DJ Worm Copies Itself, Sets Registry Entry

W32/AutoRun-DJ is a worm for the Windows platform.

4/18: StartPage.BBA Trojan Drops .Exe File When Executed

W32/StartPage.BBA is a Trojan that will infect Windows systems.

4/18: Mdrop-BRP Trojan Creates Folder Upon Installation

Troj/Mdrop-BRP is a Trojan for the Windows platform.

4/18: PasSteal-A a Password-Stealing Trojan

Troj/PasSteal-A is a password-stealing Trojan for the Windows platform.

4/17: Obfuscated.XZ Trojan Drops Copy of Itself

W32/Obfuscated.XZ is a Trojan that infects Windows systems.

4/17: Busky-FB Trojan Creates Registry Entry

Troj/Busky-FB is a Window Trojan.

4/17: Xorer-D Worm Creates Registry Entries, Files

W32/Xorer-D is a worm for the Windows platform.

4/17: AdClick-ET Trojan Targets Windows Systems

Troj/AdClick-ET is a Trojan for the Windows platform.

4/17: Mal/Dial-V a Malicious Windows Program

Mal/Dial-V is a malicious program for the Windows platform.

4/17: AutoRun-DG Wom Spreads Via Removable Drives

W32/AutoRun-DG is a worm for the Windows platform.

4/17: DwnLdr-HCM a Downloader and Information-Stealing Trojan

Troj/DwnLdr-HCM is a downloader and information-stealing Trojan for the Windows platform.

4/17: Pushdo-Gen Family of Trojans Drop File Upon Installation

Troj/Pushdo-Gen is a family of Trojans for the Windows platform.

4/17: Dutan.A Worm Copies Itself to Network, Removable Drives

W32.Dutan.A is a worm that spreads by copying itself to all available network and removable drives.

4/17: Trojan.Erotpics Tries to Download Remote Files

Trojan.Erotpics is a Trojan horse program that attempts to download files from a remote location.

4/17: Trojan.Fribet Downloads Malicious Code

Trojan.Fribet is a Trojan horse that downloads potentially malicious code on to the compromised computer.

4/17: Autorun-DH Worm Spreads Via Removable Drives

W32/Autorun-DH is a worm for the Windows platform.

4/16: Dropper.IAW Trojan Arrives as Spam Mail Attachment

At least two security vendors have issued alerts for Troj_Dropper.IAW, a Trojan that arrives as attachment to email messages spammed by another malware or a malicious user.

4/16: Agent-GWJ Trojan Overrides Default Windows Settings

Troj/Agent-GWJ is a Trojan for the Windows platform.

4/16: BackDoor-CRX Trojan Gives Attacker Remote Access Capabilities

BackDoor-CRX Trojan provides remote access capabilities to an attacker by opening a backdoor on the compromised machine.

4/16: Dropr-G a Windows Trojan

Troj/Dropr-G is a Trojan for the Windows platform.

4/16: Bckdr-QNA Trojan Gives Remote Intruder Access, Control

Troj/Bckdr-QNA is a backdoor Trojan for the Windows platform, which allows a remote intruder to gain access and control over the computer.

4/16: VB-DZH Worm Spreads Via Yahoo! Messenger

W32/VB-DZH is a worm for the Windows platform.

4/16: Agent.AMAL Trojan Sends Spam Message Targeting Company CEOs

Troj_Agent.AMAL is a memory-resident Trojan that arrives on a system as a dropped file of other malware or as a file downloaded unknowingly by a user when visiting malicious Web site(s).

4/15: Dwnldr-HCK Trojan Contacts Remote Server Via Http

Troj/Dwnldr-HCK is a Trojan for the Windows platform.

4/15: BackDoor-CRX Trojan Pretends to be Acrobat Install Program

BackDoor-CRX Trojan provides remote access capabilities to an attacker by opening a backdoor on the compromised machine.

4/15: Pamere.DC Clicker Trojan Arrives as Downloaded File

W32/Pamere.DC is a clicker Trojan that will infect Windows systems.

4/15: Agent-GWE Trojan Creates Registry Entries

Troj/Agent-GWE is a Trojan for the Windows platform.

4/15: Agent-GWD Trojan Contacts Remote Server

Troj/Agent-GWD is a Trojan for the Windows platform.

4/14: Drop-ZLB Trojan Drops, Runs New Malware

Troj/Drop-ZLB is a Trojan for the Windows platform.

4/14: Bckdr-QMZ Trojan Installs Files

Troj/Bckdr-QMZ is a Trojan for the Windows platform.

4/14: Banhost-L Trojan Tries to Overwrite Hosts File

Troj/Banhost-L is a Trojan for the Windows Platform.

4/14: Dloader.ACS Trojan Modifies Registry to Load Itself

W32/Dloader.ACS is a downloader Trojan that will infect Windows systems.

4/14: Trojan.Busdest Modifies Files

Trojan.Busdest is a Trojan that modifies files causing instability on the compromised computer.

4/11: BHO-FG Trojan Hits Windows

Troj/BHO-FG is a Trojan for the Windows platform.

4/11: Bkdr_PoisonIV.QI Backdoor Opens Random Port

Bkdr_PoisonIV.QI is a backdoor that may be downloaded from remote sites by a malware detected by Trend Micro as EXPL_NEVAR.B.

4/11: Nevar.B Exploit Targets Microsoft GDI Flaw

Expl_Nevar.B is an exploit that may be dropped by other malware.

4/11: Trojan.Emifie Exploits Windows GDI Stack Overflow Flaw

Trojan.Emifie is a Trojan horse that attempts to exploit the Microsoft Windows GDI Stack Overflow Vulnerability in order to download another potentially malicious file.

4/11: Autorun-CY Worm Creates Registry Entries

W32/Autorun-CY is a worm for the Windows platform.

4/11: Autorun.cb Worm Copies Itself, Downloads More Malware

W32/Autorun.cb is a worm that spreads by copying itself to other drives, and also downloads additional malware.

4/11: Riba Worm Spreads Via Email

W32/Riba@m is a worm that is capable of spreading via email.

4/11: Exchanger.T Trojan Copies Itself, Creates Service

W32/Exchanger.T is a Trojan that will infect Windows systems.

4/11: VB-DZE Worm Sends Link in Yahoo IM Message

W32/VB-DZE is a worm for the Windows platform.

4/11: FakeVir-AW Trojan Creates Registry Entry to Run Code

When Troj/FakeVir-AW is installed it creates the file \rkvdr.dll - also detected as Troj/FakeVir-AW.

4/11: Dloadr-BKL Trojan Contacts Remote Server Via Http

Troj/Dloadr-BKL is a Trojan for the Windows platform.

4/11: Dloader.ACS Trojan Arrives as Email Attachment

Troj_Dloader.ACS Trojan arrives on a system as an attachment to email messages spammed by another malware or a malicious user.

4/11: Agent-GVU Trojan May Install File

Troj/Agent-GVU is a Trojan for the Windows platform.

4/11: Crasher Virus Infects All Files in System

W32/Crasher is a virus that infects all the files in the system.

4/11: Mal/ObfJS-V Malicious Behavior Downloads More Malware

Mal/ObfJS-V is malicious behavior that attempts to download more malware.

4/11: JS/ApndIfra-A Trojan Detects Obfuscated Iframe

JS/ApndIfra-A Trojan detects an obfuscated Iframe appended to an HTML document.

4/10: Spambot.AG Trojan Arrives as Downloaded File With Link

W32/Spambot.AG is a Trojan that will infect Windows systems.

4/10: Trojan.Drondog Modifies System File to Download Malware

Trojan.Drondog is a Trojan horse that modifies a system file and downloads more malware on to the compromised computer.

4/10: PWS-AQW an Information-Stealing Trojan

Troj/PWS-AQW is an information-stealing Trojan for the Windows platform.

4/10: Fribet a Remote Access Trojan

Fribet is a remote access Trojan and is observed to be downloaded via malicious web pages from remote sites.

4/10: Autorun.worm.bx Copies Itself to Root of Disk

W32/Autorun.worm.bx attempts to copy itself to the root of any accessible disk volumes.

4/10: Banker-ELF Trojan Contacts Remote Server Via Http

Troj/Banker-ELF is a Trojan for the Windows platform.

4/10: Mal/VBDldr-B a Malicious Windows Program

Mal/VBDldr-B is a malicious program for the Windows platform.

4/10: IRCBot-ABE Worm Has Backdoor Functionality

W32/IRCBot-ABE is a network worm with backdoor functionality for the Windows platform.

4/9: Mdrop-BRM Trojan Creates File When Run

Troj/Mdrop-BRM is a dropper Trojan which when run, creates the file with a randomly generated filename (detected as Troj/Delf-FAD).

4/9: Pigfeng File-Infecting Virus Targets .Exe Files

W32.Pigfeng is a file-infecting virus that infects .exe files that have shortcuts on the desktop.

4/9: Spy-Agent.cf Spyware Trojan Displays Fake Error Message

Spy-Agent.cf is a spyware Trojan that when opened, displays a Word file with the message: "Microsoft Word has encountered an error and needs to be close.

4/9: Spam-Mailbot.F Trojan Installs Itself as 'Print Spooler Service'

Spam-Mailbot.f is a Trojan that will install itself as a system service "Print Spooler Service.”

4/9: Artief.T Trojan Arrives as Spam Mail Attachment

Troj_Artief.T is a Trojan that arrives as attachment to email messages spammed by another malware or a malicious user.

4/9: MalWarrior Trojan Generates False Detection Alerts

MalWarrior Trojan is a Trojan that when run, starts a scan and generates false detection alert messages and warnings.

4/9: FakeAV-K Trojan Reports Fraudulent Infection

Troj/FakeAV-K is a Trojan for the Windows platform.

4/9: Lmir.BUL a Password-Stealing Windows Trojan

W32/Lmir.BUL is a password-stealing Trojan that will infect Windows systems.

4/9: AutoRun-CU Worm Downloads, Installs, Runs New Software

W32/AutoRun-CU is a worm for the Windows platform.

4/9: Isetspy-C Worm Silently Installs System Monitor Tool

W32/Isetspy-C is a worm that silently installs the System Monitor tool ActMon.

4/8: Exchanger.F Trojan Drops Executable File

W32/Exchanger.F is a Trojan that will infect Windows systems.

4/8: Agent.VLW Trojan May be Dropped or Downloaded

Troj_Agent.VLW Trojan may be dropped by other malware.

4/8: Spambot.AF Trojan Creates Registry Entries

Troj_Spambot.AF Trojan may be dropped by other malware.

4/8: Backdoor.Spakrab Trojan Sends Spam Mail

Backdoor.Spakrab is a Trojan horse that opens a back door and may send spam emails from the compromised computer.

4/8: Mal/BHO-H a Malicious Browser Help Object

Mal/BHO-H is a malicious Browser Helper Object.

4/8: Agent-GVM Trojan Copies Itself, Creates Entry

Troj/Agent-GVM is a Trojan for the Windows platform.

4/8: Agent-GVN Trojan Creates File, Registry Entries

Troj/Agent-GVN is a Trojan for the Windows platform.

4/7: Bckdr-ZLA Trojan Downloads Code, Performs DDoS Attacks

Troj/Bckdr-ZLA is a backdoor Trojan for the Windows platform.

4/7: Momib.A Worm May Delete Files, Copy Itself

W32.Momib.A is a worm that may delete files and copies itself to all removable and network drives.

4/7: Dwnldr-ZLG Trojan Copies Itself, Runs

Troj/Dwnldr-ZLG is a Trojan for the Windows platform.

4/7: Dropper.LCZ Trojan Downloaded From Remote Sites

Troj_Dropper.LCZ is a Trojan that may be downloaded from remote sites by other malware.

4/7: Bckdr-ZLB Trojan Gives Remote Intruder Access

Troj/Bckdr-ZLB is a backdoor Trojan for the Windows platform, which allows a remote intruder to gain access and control over the computer.

4/7: Dwnldr-ZLF Trojan Downloads Files

Troj/Dwnldr-ZLF is a Trojan for the Windows platform.

4/7: Mal/Zlob-N a Family of Windows Trojans

Mal/Zlob-N is a family of Trojans for the Windows platform.

4/7: BHO-FE Trojan Creates Registry Entries

Troj/BHO-FE is a Trojan for the Windows platform.

4/7: Dloader.UEF Trojan Dropped or Downloaded

Troj_Dloader.UEF is a Trojan that may be downloaded from remote sites by other malware.

4/7: Bdoor-AJW Trojan Contacts Remote Server Via Http

Troj/Bdoor-AJW is a Trojan for the Windows platform.

MessageLabs: Storm Botnet Spews 20 Percent of All Spam

In a new report, the security firm finds that the Storm botnet is still alive and kicking.

4/4: Peregar.C Trojan Drops Files, Opens Google Page

W32/Peregar.C is a Trojan that will infect Windows systems.

4/4: BackDoor-DNM Trojan Installs Itself as System Service

BackDoor-DNM is a backdoor Trojan that installs itself as a system service.

4/4: Hupigon-TA a Backdoor Trojan

Troj/Hupigon-TA is a backdoor Trojan for the Windows platform.

4/4: Exchanger.F Trojan Registers to Run as Service

W32/Exchanger.F is a Trojan that will infect Windows systems.

4/4: Linux/Piltot-A a Linux Virus

Linux/Piltot-A is a virus for the Linux platform.

4/3: MSJet.Y Trojan Exploits Microsoft Jet Database Engine

Troj_MSJet.Y is the Trend Micro detection for a specially crafted .MDB file that attempts to exploit a vulnerability in Microsoft Jet Database Engine (Jet) that could allow remote code execution.

4/3: Agent.AZZZ Trojan May be Dropped, Downloaded

Troj_Agent.AZZZ is a memory-resident Trojan that arrives on a system as a dropped file of other malware.

4/3: Agent-GVC Trojan Contacts Remote Server

Troj/Agent-GVC is a Trojan for the Windows platform.

4/3: Vetor.A Virus Hooks Itself Into System, Infects Files

W32/Vetor.A is a virus that will infect Windows systems.

4/3: OnlineG-AR a Password-Stealing Trojan

Troj/OnlineG-AR is a password-stealing Trojan for the Windows platform.

4/3: Bckdr-QMU Trojan Creates Files Upon Installation

Troj/Bckdr-QMU is a Trojan for the Windows platform.

4/3: JS_Dloader.TVP Malicious JavaScript Arrives as Downloaded File

JS_Dloader.TVP is malicious JavaScript that arrives as file downloaded by JS_IFRAME.US from the URL http://www.{BLOCKED}ena.com/1.htm.

4/3: Drach-A a Windows Downloader Trojan

Troj/Drach-A is a downloader Trojan for the Windows platform.

4/2: FakeAV-G is Fake Anti-Spyware Software

Troj/FakeAv-G is fake anti-spyware software for the Windows platform.

4/2: Nuwar Mass-Mailing Worm Uses Own SMTP Engine

W32/Nuwar@MM is a mass mailing worm that uses its own SMTP engine to send itself to the email addresses that it harvests on the infected computer.

4/2: IRCBot-ABA Trojan Gives Remote Intruder System Access

Troj/IRCBot-ABA is a Trojan for the Windows platform.

4/2: Agent-GUU Trojan Contacts Remote Server Via Http

Troj/Agent-GUU is a Trojan for the Windows platform.

4/2: Dloadr-BKB Trojan Accesses Internet

Troj/Dloadr-BKB is a Trojan for the Windows platform.

4/2: Nuwar.JQ Worm Arrives as Spam Mail Attachment

Worm_Nuwar.JQ arrives as attachment to email messages spammed by another malware or by a malicious user.

Mobile Spam Threat Worth Keeping a Watchful Eye

Right now carriers are doing the anti-spam lifting but things could change.

4/2: Dloadr-BKC Trojan Copies Itself, Creates Registry Entries

Troj/Dloadr-BKC is a Trojan for the Windows platform.

4/2: Agent-GVB Trojan Creates Files, Registry Entry

Troj/Agent-GVB is a Trojan for the Windows platform.

4/2: Agent-GUY Trojan Creates Files Once Installed

Troj/Agent-GUY is a Trojan for the Windows platform.

4/1; DNSChan-MI Trojan Adds Entries to Hosts File

Troj/DNSChan-MI is a Trojan for the Windows platform.

4/1: Proxy-Fireby Trojan Used by Malware Authors to Control System

Proxy-Fireby is a Trojan that could be used by malware authors to remotely control the machine.

4/1: Bancos-BDX Trojan Creates Files, Registry Entry

Troj/Bancos-BDX is a Trojan for the Windows platform.

4/1: Peacomm.WT Worm Sends April Fools Email

W32/Peacomm.WT is a worm that will infect Windows systems and spreads through email.

4/1: LegMir-ARS Trojan Copies Itself, Creates Files

Troj/LegMir-ARS is a Trojan for the Windows platform.

4/1; Agent-GUR Trojan Contact Remote Server Via Http

Troj/Agent-GUR is a Trojan for the Windows platform that includes functionality to access the internet and communicate with a remote server via HTTP.

4/1: FakeAle-AX Trojan Copies Itself, Creates File

Troj/FakeAle-AX is a Trojan for the Windows platform.