Click here

Malware: Archive: September 2008 

9/30: OnLineGames.ACVR Trojan Infects Windows Systems

W32/OnLineGames.ACVR is a Trojan that will infect Windows systems.

9/30: FakeAlert-XPSecCenter!lnk Trojan Detects Dropped Files

FakeAlert-XPSecCenter!lnk is a Trojan that detects .LNK or Link files dropped by the FakeAlert-XPSecCenter Trojan.

9/30: Dloadr-BUF a Downloading Trojan

Troj/Dloadr-BUF is a downloading Trojan for the Windows platform.

9/30: Dropper.ED Trojan May be Unknowingly Downloaded

Troj_Dropper.ED Trojan may be dropped by other malware.

9/30: PE_Patched.DV Detects File With Malicious Code

PE_Patched.DV is the Trend Micro detection for copies of a certain legitimate Windows file that have been injected with a malicious code.

9/30: Small-EMI Trojan Drops More Executables

Troj/Small-EMI is a Trojan for the Windows platform.

9/30: DMserver.dll Detects New Disk Drives

W32/Dmserver.dll virus is the Windows Logical Disk Manager, which detects and monitors new disk drives.

9/29: DwnLdr-HIJ Trojan Disables System Software

Troj/DwnLdr-HIJ is a Trojan for the Windows platform.

9/29: Mondera.GEN Trojan Modifies Registry at System Startup

W32/Mondera.GEN is a Trojan that will infect Windows systems.

9/29: NtRootK-DZ a Windows Trojan

Troj/NtRootK-DZ is a Trojan for the Windows platform.

9/29: VBS/autorun.worm.k Spreads Via USB Drives

VBS/autorun.worm.k is a VBS autorun worm that spreads through USB drives.

9/29: VB-EBF Trojan Targets Windows Systems

Troj/VB-EBF is a Trojan for the Windows platform.

9/29: Agent-HTU Trojan Creates File Upon Installation

Troj/Agent-HTU is a Trojan for the Windows platform.

9/29: Agent-HTP a Downloader Trojan

Troj/Agent-HTP is a Trojan for the Windows platform.

9/29: IRCBot.DIR Trojan Drops .Exe File

W32/IRCBot.DIR is a Backdoor Trojan that infects Windows systems.

9/29: FakeAV-EE Trojan Copies Itself, Creates Files

Troj/FakeAV-EE is a Trojan for the Windows platform.

9/29: Earanc.A Worm Copies Itself

Earanc.A is a worm that spreads by copying itself, without infecting other files.

9/29: Mudrop.CY Trjojan Drops Files/Components

Troj_Mudrop.CY Trojan may be dropped by other malware.

9/26: Autorun-KL Worm Copies Itself, Creates Files

W32/Autorun-KL is a worm for the Windows platform.

9/26: Sality.ao Parasitic Virus Infects PE Executable Files

W32/Sality.ao is a parasitic virus that infects Win32 PE executable files.

9/26: Delf.GSZ Trojan Downloads, Executes Files

Troj_Delf.GSZ Trojan may be downloaded from certain remote sites.

9/26: Buzus.NIR Drops .Exe File in Windows Folder

W32/Buzus.NIR is a Trojan that will infect Windows systems.

9/26: Agent.AHZV Sends Bogus Hallmark Card Email

Worm_Agent.AHZV arrives as attachment to email messages spammed by another malware or a malicious user.

9/26: Agent.AWAF Backdoor Arrives as Attachment

Bkdr_Agent.AWAF backdoor arrives as an attachment to email messages spammed by another malware or a malicious user.

9/26: VB-EBE Trojan Copies Itself, Creates Files

Troj/VB-EBE is a Trojan for the Windows platform.

9/26: Bloodhound.Olexe!JI Detects Embedded Ichitaro Files

Bloodhound.Olexe!JI is a heuristic detection for reporting JustSystems Ichitaro files that contain an embedded executable file.

9/26: Bloodhound.Pdexe Detects Embeddd PDF Files

Bloodhound.Pdexe is a heuristic detection for reporting PDF files that contain an embedded executable file.

9/26: Werly.A Virus Infects System Files

W32.Werly.A is a virus that spreads by infecting files on the compromised computer.

9/25: Doc-Zip a Family of Zip Files Containing Malware

Troj/Doc-Zip is a family of zip files that contain malware.

9/25: AutoRun-AG Worm Targets Windows

VBS/AutoRun-KG is a worm for the Windows platform.

9/25: Joke/Anywork-A a Non-Malicious Program

Joke/Anywork-A is a non-malicious program that prompts the user to enter their name.

9/25: Agent.ABUE Trojan May be Downloaded, Dropped

W32/Agent.ABUE is a Windows systems Trojan that may be dropped by other malware or may be downloaded from remote website by other malware.

9/25: Agent-HSV Trojan Creates Service, Stealths Itself

Troj/Agent-HSV is a Trojan for the Windows platform.

9/25: PSW-FR a Windows Trojan

Troj/PSW-FR is a Trojan for the Windows platform.

9/25: ParaDrop-C a Family of Appending Viruses

W32/ParaDrop-C is a family of appending viruses for the Windows platform.

9/24: FakeAV.NO Trojan May be Dropped by Other Malware

Troj_FakeAV.NO Trojan may be downloaded from remote Web sites by other malware.

9/24: Mal/AutoInf-A Malicious File Executes Malware

Mal/AutoInf-A is a malicious file that may cause malware to be executed when the media containing the file is accessed by a computer running Windows.

9/24: Agent-HSO Trojan Copies Itself, Creates Registry Entries

Troj/Agent-HSO is a Trojan for the Windows platform.

9/24: Agent.AINZ Trojan Arrives as Link Inside Emails

Troj_Agent.AINZ Trojan arrives as a link inside email messages spammed by another malware or a malicious user.

9/24: Auraax Worm Spreads Via Drives, Shares

W32.Auraax is a worm that spreads through removable drives and network shares.

9/24: Sality-AM Virus Infects Executables in Root Folder

W32/Sality-AM is a virus for the Windows platform.

9/24: Dwnlh-Gen Trojan Hits Windows

Troj/Dwnlh-Gen is a Trojan for the Windows platform.

9/24: Dloadr.IB Trojan Arrives as Email Attachment

Troj_Dloadr.IB Trojan arrives as attachment to email messages spammed by another malware or a malicious user.

9/24: FakeAV.NN Trojan Drops Files/Components

Troj_FakeAV.NN Trojan may be downloaded from remote sites by other malware.

9/23: Agent-HSI Trojan Creates File, Registry Entries

Troj/Agent-HSI is a Trojan for the Windows platform.

9/23: P2PShared.M Worm Spreads Via File Sharing

P2PShared.M is a worm whose main objective is to spread and affect as many computers as possible.

9/23: Dropa-Gen Trojan Hits Windows

Troj/Dropa-Gen is a Trojan for the Windows platform.

9/23: Autorun-AU a Visual Basic Worm

VBS/Autorun-AU is a Visual Basic worm for the Windows platform.

9/23: Autorun-YA Worm Creates Registry Entry

W32/Autorun-YA is a worm for the Windows platform.

9/23: Exploit-CodeBase.ch a Malicious Compiled Html

Exploit-CodeBase.ch is a malicious compiled HTML, which when executed could drop or download other malware.

9/23: Agent-HSH Trojan Copies Itself, Creates Registry Entry

Troj/Agent-HSH is a Trojan for the Windows platform.

9/23: Mal/EncPk-EG Program May be Used by Malware Authors

Mal/EncPk-EG is a program packed with a protection system typically used by malware authors.

McAfee Nabs Secure Computing for Network Cred

The second-largest name in security software makes a play to better rival No. 1 Symantec.

9/22: VB.EME Trojan May be Dropped or Downloaded

W32/VB.EME is a Trojan that will infect Windows systems.

9/22: AutoRun-JR Worm Creates Files, Registry Entries

W32/AutoRun-JR is a worm for the Windows platform.

9/22: Pakes.JMD Trojan Drops Files, Modifies Registry

W32/Pakes.JMD is a Trojan that may be dropped by other malware or may be downloaded from remote website by other malware.

9/22: Renos.SYM Trojan Drops Copy of Itself

Troj_Renos.SYM Trojan may be downloaded from remote sites by the malware TROJ_DISKEN.K.

9/22: Bckdr-QPI Trojan Creates Files

Troj/Bckdr-QPI is a Windows Trojan.

9/22; DIAL/Dialer.Gen Detects Dialer Variants

DIAL/Dialer.Gen dialer is a generic detection routine designed to spot common family characteristics shared in several variants.

9/22: Backdr-AB Trojan Gives Remote Intruder Access

Troj/Backdr-AB is a backdoor Trojan that allows a remote intruder to gain access and control over the computer.

9/22: Agent-HSA Trojan Copies Itself, Creates Registry Entry

Troj/Agent-HSA is a Trojan for the Windows platform.

9/19: Pakes.JMD Trojan Drops Files, Modifies Registry

W32/Pakes.JMD is a Windows Trojan that may be dropped by other malware or may be downloaded from remote website by other malware.

9/19: Agent-HRM Trojan Copies Itself Changes Registry Entry

When first run Troj/Agent-HRM copies itself to (Windows)\config\csrss.exe and drops the clean system file (System)\mswinsck.ocx.

9/19: Renos.SYM Trojan Drops Components, Changes Wallpaper

Troj_Renos.SYM Trojan may be downloaded from remote sites by the malware TROJ_DISKEN.K.

9/19: Agent-HRL Trojan Contacts Remote Server Via Http

Troj/Agent-HRL is a Trojan for the Windows platform.

9/19: Exploit-IFrame.gen.b Trojan Detects Malicious IFrames Within Websites

Exploit-IFrame.gen.b Trojan is a detection for malicious IFrames embedded in various legitimate websites.

9/18: PWS-ATU Trojan Steals Internet Account Details

Troj/PWS-ATU Trojan steals internet account details and sends them to a preconfigured email address.

9/18: Banker-ENH an Information-Stealing Trojan

Troj/Banker-ENH is an information-stealing Trojan.

9/18: Backdoor.Tidserv Trojan Opens Back Door

Backdoor.Tidserv is a Trojan horse that opens a back door on the compromised computer.

9/18: IRCBot-ACS Trojan Copies Itself, Creates Registry Entry

Troj/IRCBot-ACS is a Trojan for the Windows platform.

9/18: FakeAle-HL Trojan Copies Itself

Troj/FakeAle-HL is a Trojan for the Windows platform.

9/18: Delf-FBD Trojan Contacts Remote Server Via Http

Troj/Delf-FBD is a Trojan for the Windows platform.

9/18: IRCBot.DUC Trojan Drops .Exe File

W32/IRCBot.DUC is a Windows Trojan that may be dropped by other malware or may be downloaded from remote website by other malware.

9/18: Iframe-AV Trojan Redirects Web Pages

Troj/Iframe-AV redirects web pages to those hosting exploits.

9/18: Scrods-Gen Drops, Executes Remote Files

Troj/Scrods-Gen is a family of Trojans for the Windows platform.

9/18: Dropper.BX Trojan Drops Component Files

Trojan_Dropper.BX may be downloaded from remote sites by other malware.

9/18: Savix Worm Spreads Via Fixed, Removable Media

W32.Savix is a worm that spreads through fixed drives and removable media.

9/17: AutoRun.MEF Trojan Drops Files, Modifies Registry

W32/AutoRun.MEF is a Windows systems Trojan that may be dropped by other malware or may be downloaded from remote website by other malware.

9/17: Bugnraw Trojan Family Display False Infection Warnings

Win32/Bugnraw is a family of trojans that display false infection warnings on the user's desktop in an attempt to trick the user.

9/17: Mal/EncPk-EG Program Used by Malware Authors

Mal/EncPk-EG is a program packed with a protection system typically used by malware authors.

9/17: Spy-Agent.bg Trojan Captures Info From Victim Machine

Spy-Agent.bg Trojan is designed to capture information from the victim machine and send them to the remote site.

9/17: Dldr.Agent.RCE a Downloader Trojan

TR/Dldr.Agent.RCE is a downloader Trojan that drops a malicious file.

9/17: BackDoor-DNM Trojan Installs Itself as System Service

BackDoor-DNM is a backdoor Trojan that installs itself as a system service.

How To Get Your Email Past Clients' Spam Filter

Achieving “deliverability,” otherwise known as getting email delivered to a user’s inbox in a timely and fully-functional fashion, is both an art and a science.

Presidential Elections will Stuff Inboxes

Is the amount of junk e-mail you receive daily driving you crazy? Wait until the hackers begin leveraging interest in the elections.

9/16: Qhost.BA Trojan Modifies HOSTS File

Troj_Qhost.BA Trojan may arrive as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious Web sites.

9/16: Dload-DK Trojan Creates Files Upon Installation

Troj/Dload-DK is a Trojan for the Windows platform.

9/16: Mal/Pushdo-B Trojan Family Drops Files

Mal/Pushdo-B is a family of Trojans for the Windows platform.

9/16: Meredrop.GJ Trojan May be Downloaded or Dropped

Troj_Meredrop.GJ Trojan may be downloaded from remote Web sites by other malware. It may be dropped by other malware.

9/16: Pidief.BC Trojan Exploits Adobe Reader Flaw

Troj_Pidief.BC Trojan may be downloaded from remote Web sites by other malware.

9/16: Dwnldr-HHV Trojan Contacts Remote Server Via Http

Troj/Dwnldr-HHV is a Trojan for the Windows platform.

9/16: Dload-DJ Trojan Creates Files

Troj/Dload-DJ is a Trojan for the Windows platform.

9/16: Banker-ENG an Information-Stealing Trojan

Troj/Banker-ENG is an information-stealing Trojan.

9/16: Dwnldr-HHW Trojan Drops, Runs Files From Multiple Sites

Troj/Dwnldr-HHW is a Trojan for the Windows platform.

Hackers Hit BusinessWeek With Malware

The site was hit by a SQL injection attack and connects users to a sleeper site.

9/16: AutoRun.CTS Trojan Drops Files, Modifies Registry

W32/AutoRun.CTS is a Trojan that will infect Windows systems.

9/16: PWS-ATR Trojan Contacts Server, Copies Itself

Troj/PWS-ATR is a Trojan for the Windows platform.

9/15: FakeAV-DK Trojan Claims to be Anti-Virus Application

Troj/FakeAV-DK claims to be an anti-virus application.

9/15: Agent-HQV Trojan Registers File as COM Object

Troj/Agent-HQV is a Trojan for the Windows platform.

9/15: DwnLdr-HHU a Downloader Trojan

Troj/DwnLdr-HHU is a downloader Trojan for the Windows platform.

9/15: Lineag-FX a Password-Stealing Trojan

Troj/Lineag-FX is a password-stealing Trojan for the Windows platform.

9/15: Agent.ADFA Worm May be Unknowingly Downloaded

W32/Agent.ADFA is a worm that will infect Windows systems.

9/15: Istbar-DR Trojan Drops Files From Preconfigured URLs

Troj/Istbar-DR is a Trojan downloader for the Windows platform.

9/15: YTKit-A Trojan Used For Fake YouTube Sites

Troj/YTKit-A is a Trojan for the Windows platform.

Why Are IT Security Pros so Bad?

Have you heard about the security conference where the organizers inadvertently distributed a virus-infected USB stick to the attendees?

Browser Security: IE vs. Safari vs. Firefox

Each of the three browsers has strengths in malware protection, but it’s their weaknesses that are the most worrisome.

9/12: Mal/HLPExe-A Help File Drops More Malware

Mal/HLPExe-A is a Help file that will drop more malware.

9/12: Exiveter Virus Infects All .Exe Files

W32.Exiveter is a virus that infects all .exe files in the current folder that it is executed in.

9/12: Python.Velrag Virus Infects all Python Files

Python.Velrag is a virus that infects all python files in the current folder that it is executed in.

9/12: AutoRun-JE Worm Sets Registry Entries

W32/AutoRun-JE is a worm for the Windows platform.

9/12: Dload-DI Trojan Contacts Remote Server Via Http

Troj/Dload-DI is a Trojan for the Windows platform.

9/12: Agent.QFH Trojan May be Downloaded or Dropped

W32/Agent.QFH is a Trojan that will infect Windows systems.

9/11: Mal/Emogen-G a Malicious Program

Mal/Emogen-G is a malicious program for the Windows platform.

9/11: Mal/FakeAV-E a Malicious Executable

Mal/FakeAV-E is a malicious executable that pretends to be an anti-virus product and that exaggerates threats on the infected computer.

9/11: PWS-Banker.cs a Banking Password-Stealing Trojan

PWS-Banker.cs is a password-stealing Trojan that specifically looks to steal bank password related information.

9/11: Meredrop-A Trojan Creates Temp, System Files

Troj/Meredrop-A is a Trojan for the Windows platform.

Google to Purge Server Logs Twice as Fast

In a nod to mounting privacy concerns, Google slashes the time it stores users' IP addresses.

9/10: OnLineG-BC Trojan Copies Itself, Creates Files

Troj/OnLineG-BC is a Trojan for the Windows platform.

9/10: Mal/Dload-B a Malicious DLL

Mal/Dload-B is a malicious DLL that typically downloads more code from the internet.

9/10: Mal/Obfus-A an Obfuscated Malicious Program

Mal/Obfus-A is an obfuscated malicious program.

9/10: Joke/OffMsg-A Virus Displays Offensive Message

Joke/OffMsg-A virus displays a highly offensive message but is otherwise essentially innocuous.

9/10: Python.Sibi!inf Detects Python Script Files

Python.Sibi!inf is a detection for python script files infected by a polymorphic virus.

9/9: PHilto.A Trojan Drops Adware

PHilto.A is a Trojan that is designed to is to download the adware detected as NaviPromo to the affected computer.

9/9: Agent-HPR Trojan Copies Itself, Creates Registry Entries

Troj/Agent-HPR is a Trojan for the Windows platform.

9/9: Mal/PicEx-A Malware Contains Malicious .Exe

Mal/PicEx-A is a carefully constructed picture containing a malicious EXE.

9/9: Mal/GamePSW-C Trojan Family Steal Passwords

Members of Mal/GamePSW-C are Trojans that typically attempt to steal passwords for online games.

9/9: Agent.QFH Trojan May be Dropped, Downloaded

W32/Agent.QFH is a Trojan that will infect Windows systems.

9/9: Bdoor-ANR Trojan Changes Registry Enry

Troj/Bdoor-ANR is a Trojan for the Windows platform.

9/9: FakeAle-HA Trojan Creates Fake Antivirus Files

Troj/FakeAle-HA is a Trojan for the Windows platform.

9/9: Agent-HPU Trojan Disables Automatic Software Startup

Troj/Agent-HPU is a Trojan for the Windows platform.

9/9: AutoRun.CHV Worm Drops Files, Modifies Registry

W32/AutoRun.CHV is a worm that will infect Windows systems.

9/9: Dloader-BSO Trojan Copies Itself, Creates Registry Entry

Troj/Dloader-BSO is a Windows Trojan.

9/9: PWS-Banker a Password-Stealing Trojan

PWS-Banker is a password-stealing Trojan that captures keystrokes and sends notification and captured information to the author via http.

9/8: LdPinch-AL a Backdoor and Password-Stealing Trojan

Troj/LdPinch-AL is a backdoor and password-stealing Trojan.

9/8: Autorun-IW Trojan Copies Itself to Root, Windows Folders

Troj/Autorun-IW is a Trojan for the Windows platform.

9/8: AutoRun-IX Worm Spreads Via Removable Drives

W32/AutoRun-IX is a worm for the Windows platform that spreads via removable shared drives.

9/8: Mal/Badsrc-C a Malicious Web Page

Mal/Badsrc-C is a malicious web page that has been compromised to load a script from a malicious website.

9/8: Agent-HPH Trojan Contacts Remote Server

Troj/Agent-HPH is a Trojan for the Windows platform.

9/8: YTFakeCreator a Virus Constructor Malware

YTFakeCreator is a virus constructor type malware.

9/5: Dwnldr-HHM Trojan Copies Itself, Creates Registry Entry

Troj/Dwnldr-HHM is a Trojan for the Windows platform.

9/5: Fujacks-AM Virus Installs File, Creates Entry

W32/Fujacks-AM is a virus for the Windows platform that has functionality to spread to network shares and removable devices.

9/5: JS.Qsiframe Virus Infects HTML Files

JS.Qsiframe is a virus that infects HTML files on the compromised computer.

9/4: Mal/ObfJS-BC a Maliciously Obfuscated Script

Mal/ObfJS-BC is a maliciously obfuscated script that attempts to download and execute a further file.

9/4: Lowzones.UH Trojan Steals Confidential Information

Lowzones.UH is a Trojan that is designed to steal confidential information about the user from the affected computer, such as passwords or usernames.

9/4: Agent.AXAS Trojan Drops .Exe File, Modifies Registry

W32/Agent.AXAS is a Trojan that will infect Windows systems.

9/3: VBS/AutoRun-IT Script Worm Spreads Via Removable Drives

VBS/AutoRun-IT is a script worm that spreads via removable drives.

9/3: FakeAlert-AP Trojan Displays Misleading Fake Alerts

FakeAlert-AP is a Trojan that displays misleading fake alerts to entice the user into buying a product to "repair" malware problems.

9/3: Silnk Virus Infects .lnk Files

W32.Silnk is a virus that infects .lnk files on the compromised computer.

9/3: Mal/ObfJS-F a Malicious JavaScript Trojan

Mal/ObfJS-F is a malicious JavaScript Trojan within a web page.

9/3: GetCodec-A Worm Sets Registry Entries

W32/GetCodec-A is a worm for the Windows platform.

9/3: Autorun-IU a Windows Worm

W32/Autorun-IU is a worm for the Windows platform.

9/3: AutoKitty.A Worm Makes Modifications in Windows Registry

AutoKitty.A is a worm that carries out plenty of modifications in the Windows Registry, which prevent the user from working with the computer as usual.

9/2: Ruby.Sylrot Worm Sends Itself as Email Attachment

Ruby.Sylrot@mm is a mass-mailing worm that spreads by sending itself as an email attachment to addresses gathered from the compromised computer.

9/2: JS.Posmonk Worm Spreads by Injecting Links into Data

JS.Posmonk is a worm that spreads by injecting links into data when a Web form is submitted.

9/2: Sality.ac Parasitic Virus Infects Executable Files

Win32/Sality.ac is a parasitic virus that infects Win32 PE executable files.

9/2: FakeAV.IG Trojan Modifies Desktop Screensaver

Troj_FakeAV.IG Trojan may be dropped by other malware.

9/2: HkDla-Gen a Windows Trojan

Troj/HkDla-Gen is a Trojan for the Windows platform.

9/2: GoGho Trojan Copies Itself, Creates and Deletes Files

The GoGho Trojan copies itself, creates and deletes files.

Data Breach: The New Old Bogeyman

Best Western may have dodged a bullet, but the situation brought to light how customer data of all types are at risk.

9/2: Dload.CST Trojan Drops .Exe File in System Folder

W32/Dload.CST is a Windows Trojan that may be dropped by other malware or may be downloaded from remote website by other malware.

9/2: Banloa-FW Trojan Copies Itself to .Exe Directory

Troj/Banloa-FW is a Trojan for the Windows platform.

9/2: Exchanger.AR Trojan May be Dropped or Downloaded

W32/Exchanger.AR is a Trojan that will infect Windows systems.

9/2: MeterorBot.A Backdoor Sends System Information

MeteorBot.A is a backdoor that sends information about the affected computer to its author, such as computer name, IP address and operating system.