Click here

Malware: Archive: March 2009 

3/31: Backdoor.Ghostnet Opens Backdoor

The Backdoor.Ghostnet Trojan opens a back door on the compromised computer allowing a remote attacker to perform a number of actions.

China Claims Not Spying Over Web

China Tuesday rejected a report suggesting it may be involved in using computer networks to spy on exiled Tibetans and foreign governments, accusing its authors of being possessed by "the ghost of the Cold War."

3/31: Mal/Swizzor-D is Family of Trojans

Mal/Swizzor-D is a family of Trojans which have functionality to download and execute files from the internet.

3/30: MalwareDefender2009 Is Misleading App that Exaggerates Threats

MalwareDefender2009 Is a misleading app that exaggerates threats.

3/30: W32.Xanib.A Infects Executable Files

W32.Xanib.A infects executable files.

3/30: Microsoft Provides Conficker Advice

Microsoft provides advice about how to protect your PC from the Conficker worm, due to resurface on April 1.

Conficker Worm Due on April 1

With the Conficker due to return on April 1, experts are warning users to make sure that their security software is updated.

3/27: Mal/VB-AE Drops More Malware

Mal/VB-AE installs in the registry and drops more malware.

3/27: Spy-Agent.bw Steals Data from Recruitment Websites

Spy-Agent.bw is a Trojan that steals data from recruitment websites when the user is infected.

3/26: Mal/FakeAV-AJ Sends Fake Warnings

Once running Mal/FakeAV-AJ bombards the user with fake security warnings in order to trick them into paying to register the product.

3/26: Mal/FakeAV-AK Installs Fake Anti-Virus Apps

Mal/FakeAV-AK dowloads and installs a fake Anti-Virus application that fraudulently reports a users system as infected and will not clean up these fraudulent reports until the users pays and registers the application.

3/25: JS_DLOADER.XBG is Javascript Malware

This JavaScript (JS) malware contains encrypted code that enables it to connect to a certain URL to possibly download malicious files.

3/24: Mal/VB-AB Drops Malware in Storage Devices

Mal/VB-AB Drops malware in removable storage devices.

3/24: Linux.Psybot Spreads via Routers

Linux.Psybot is a worm that spreads through routers and DSL modems.

3/23: Troj/Agent-IOV Adds DLL File

When run Troj/Agent-IOV copies itself to \digeste.dll and adds the DLL file to the following registry entry: HKLM\SYSTEM\CurrentControlSet\Control\SecurityProviders SecurityProviders ,digeste.dll

3/23: Mal/ObfJS-BE Spreads via Browser

Mal/ObfJS-BE is a malicious script that attempts to exploit vulnerabilities in order to infect the victim when the malicious web page is browsed.

3/17: FakeVir.LC Trojan Drops FIles in Media System Folder

W32/FakeVir.LC is a Windows system Trojan that upon execution drops files in the Program Files\MediaSystem folder.

3/17: Malicious Spam Coincides With NCAA's March Madness Basketball Tournament

Websense Security Labs is reporting the discovery of a massive malicious comment spam campaign brewing in the blogosphere, made to coincide with the NCAA's "March Madness" basketball tournament.

3/17: Waledac.CRV Worm Redirects User to Website

Worm_Waledac.CRV may be downloaded from remote site(s).

3/17: PHP_Akspy.A Malicious PHP Script May be Unknowingly Downloaded

PHP_Akspy.A is malicious PHP script that may be installed manually by a user.

3/17: BackDoor-CEP.gen Trojan Drops Files, Adds Registry Keys

Upon execution, BackDoor-CEP.gen Trojan installs itself into the %WINDIR% or %WINDIR%\System32 directory as server.exe, mstwain32.exe, or under another file name.

3/17: Waledac.NYS Arrives With Malicious Links

Worm_Waledac.NYS arrives on a system as a downloaded file from certain remote sites.

3/17: Trojan.Qhosts.G Lowers Security Settings

Trojan.Qhosts.G is a Trojan horse that lowers security settings by modifying the hosts file on the compromised computer.

3/17: Critical Alert Issued for Bifrost GI Backdoor

Security vendor Computer Associates has issued a critical alert today for Bifrost GI, a backdoor program that gives a remote intruder access to a system.

3/16: Autorun-ABI Worm Copies Itself, Creates Registry Entry

W32/Autorun-ABI worm copies itself to \Movie Maker\svchost.exe

3/16: Scribble-A Virus Infects Files With .Exe, .Scr Extensions

W32/Scribble-A is a polymorphic virus for the Windows platform.

3/16: Exp/APSA09-01 PDF File Exploits Adobe Reader Bug

Exp/APSA09-01 is a PDF file that exploits a bug in Adobe Reader.

3/16: Trojan.Tarodrop.H Exploits Ichitaro Office Suite Flaw

Trojan.Tarodrop.H is a Trojan horse that drops more files on to the compromised computer by exploiting a vulnerability in the Justsystem Ichitaro Office Suite.

3/16: Ransom.AQWA Trojan Drops Non-Malicious Configuration File

Troj_Ransom.AQWA is a Trojan that may be dropped by WORM_RANSOM variants.

3/16: Exploit-TaroDrop.g Trojan Targets Ichitaro Word Processing App

Exploit-TaroDrop.g is a Trojan that is delivered via a specially crafted Ichitaro document.

3/16: Helpud-A Trojan Drops Malicious Windows Executable

Troj/Helpud-A is a Trojan dropper for the Windows platform.

3/16: BackDoor-DNW Trojan Gives Attacker Remote Access Capabilities

BackDoor-DNW Trojan provides remote access capabilities to an attacker by opening a backdoor on the compromised machine.

3/16: Ransom.BG Trojan Opens Log File Upon Execution

Troj_Ransom.BG is a Trojan that arrives as a component file of WORM_RANSOM variants.

After McColo, Spam Still Rising

The online world enjoyed a brief respite from the spam onslaught after McColo was shut down. Now the spammers have bounced back.

3/16: Murlo-BI Trojan Connects to Internet Servers and Creates Files

Troj/Murlo-BI is a Trojan that connects to servers on the internet and creates files.

3/16: Critical Alert Issued for PCClient LA Backdoor

Security vendor Computer Associates has issued a critical alert for PcClient LA, a backdoor designed to exploit a vulnerability in a system, and open it to future access by an attacker.

3/13: SillyDI GXW a Downloader Trojan

SillyDl GXW is a downloader Trojan.

3/13: SillyDI GXP Downloader Trojan May Execute, Install Software

SillyDl GXP is a downloader Trojan that downloads and may execute or install software without user permission.

3/13: Buzus-AF Trojan Creates Multiple Files

Troj/Buzus-AF is a Trojan for the Windows platform.

3/13: Bdoor-ATJ Disables System Software

Troj/Bdoor-ATJ copies itself to WindowsXP.exe.

3/13: Mal/FakeAV-AD a Malicious Behavior Associated With Rogue Security Software

Mal/FakeAV-AD is malicious behavior for the Windows platform.

3/13: Agent-JET Trojan Changes IE Settings

Troj/Agent-JET changes settings for Microsoft Internet Explorer.

3/13: Mal/Zlob-AG a Malicious Windows Program

Mal/Zlob-AG is a malicious program.

3/13: Trojan.Win32.Agent2.dtb Calls Premium Rate Numbers

Trojan.Win32.Agent2.dtb calls premium rate numbers without the knowledge or consent of the user.

3/13: Email-Worm.Win32.Merond.a Spreads as Attachment

Email-Worm.Win32.Merond.a spreads as an attachment to infected emails and also via file-sharing networks and removable media.

3/12: IRCBot.IW WOrm Exploits System Flaws to Spread

Win32/IRCBot.IW is a worm that exploits system vulnerabilities in order to propagate across a network.

3/12: Zbot.JVE Trojan Drops Files, Modifies Registry

W32/Zbot.JVE is a Trojan that will infect Windows systems.

3/12: Conficker.worm Exploits Windows Server Flaw to Spread

W32/Conficker.worm exploits the Windows Server Service (MS08-067) vulnerability in order to spread.

3/12: Fake Facebook "Dancing Girl" Video Leads to Malware

Websense Security Labs is reporting it has received alerts of spoofed Facebook email messages that contain malicious links.

3/12: Zapchas-EJ Backdoor Gives Intruder Remote System Access

Troj/Zapchas-EJ is a backdoor Trojan that allows a remote intruder to gain access and control over the computer.

3/12: Mal/VBDl-B Malware Exhibits VB Downloader Traits

Mal/VBDl-B exhibits characteristics unique to Visual Basic downloaders.

3/12: Mal/WaledPak-B Worm Family Contacts Remote Server

Mal/WaledPak-B is a family of worms for the Windows platform.

Netbooks: a Security Risk?

The proliferation of low-end netbook may pose a new threat to the cybersecurity of users.

3/11: Buzus.AMRB Trojan Drops Files, Modifies Registry

W32/Buzus.AMRB is a Trojan that will infect Windows systems.

3/11: Mal/ObfJS-BB Malicious Script Compromises Web Page

Mal/ObfJS-BB is a malicious script that attempts to load content from a remote site when a compromised web page is browsed.

3/11: Mal/ObfJS-BA Malicious Script Loads Remote Content

Mal/ObfJS-BA is a malicious script that attempts to load content from a remote site when a compromised web page is browsed.

3/11: Shellot.worm Injects Dropped Files Into Windows Processes

W32/Shellot.worm injects the dropped files in to the legitimate Windows processes to open a backdoor.

3/11: Generic Rootkit.w Trojan a Driver File Dropped by Malicious Apps

Generic Rootkit.w Trojan is the detection for a driver file dropped by malicious applications to conceal their network activity.

3/11: Mal/WaledPak-B Worm Family Contacts Remote Server Via Http

Mal/WaledPak-B is a family of worms for the Windows platform.

3/11: Mal/AutoInf-B Malicious File May Cause Execution of Malware

Mal/AutoInf-B is a malicious file that may cause malware to be executed when the media containing the file is accessed by a computer running Windows.

3/11: Mal/Zlob-AF a DLL in Zlob Trojan Family

Mal/Zlob-AF is a DLL belonging to the Troj/Zlob family of Trojans.

3/11: "Critical Alert" Issued for Veslorn RO Trojan Downloader

Security vendor Computer Associates has issued a critical alert for Veslorn RO, a backdoor Trojan downloader.

3/10: Agent-JEC Trojan Creates Files, Registry Entries

Troj/Agent-JEC creates multiple files.

3/10: SillyFDC.BBA Worm Spreads by Copying Itself to Removable Drives

W32/SillyFDC.BBA is a worm that will infect Windows systems and spreads by copying itself to removable drives.

3/10: Chadem-A Trojan Runs on System Startup

Troj/Chadem-A is a Trojan for the Windows platform.

3/10: DInject-A Trojan Copies Itself, Creates Registry Entries

Troj/DInject-A is a Trojan for the Windows platform.

3/10: Downad.KK Worm Drops Copy Set to Allow Restricted Access

Worm_Downad.KK may be downloaded or dropped from remote sites by other malware.

3/10: BackDoor-CEP.gen Trojan Drops Files Into Directory

BackDoor-CEP.gen is a Trojan that installs itself into the %WINDIR%\System32 directory as server.exe or another file name.

3/10: Sohanad.JH Worm Sends Copies of Itself Via IM Applications

Worm_Sohanad.JH may be dropped by WORM_AUTORUN.DIO.

3/10: Suspicious.Farfli.2 a Detection Technology for Malware Threats

Suspicious.Farfli.2 is a detection technology designed to detect entirely new malware threats without traditional signatures.

3/10: FakeAV-MK Trojan Creates Files

Troj/FakeAV-MK is a Trojan for the Windows platform.

3/10: Conficker.worm Exploits Flaw to Spread

W32/Conficker.worm exploits the MS08-067 vulnerability in order to spread.

3/10: Dload-FQ Trojan Creates Files

Troj/Dload-FQ is a Trojan for the Windows platform.

3/10: MalwareDefender2009 Adware Program Warns of Fake Threats

MalwareDefender2009 is an adware program that deceives users warning them of non-existing threats in their computers so that they purchase a certain program that removes them from the computer.

3/10: FakeAV-MM Trojan Runs Install.Exe on Startup

Troj/FakeAV-MM is a Trojan for the Windows platform.

3/10: IRCBot-ADV Trojan Gives Remote Intruder System Access, Control

Troj/IRCBot-ADV is a Trojan for the Windows platform.

3/10: FakeAV-MN Trojan Creates Multiple Data Files

Troj/FakeAV-MN is a Windows system that includes functionality to access the internet and communicate with a remote server via HTTP.

3/9: Wincod Trojan Drops Files, Modifies Settings

Two security vendors have issued alerts for W32/Wincod, a Trojan that will infect Windows systems.

Excel Hole Remains Unpatched

A security vulnerability in Microsoft Excel that compromises a system if a user opens a poisoned file continues to threaten users.

3/9: Mal/ObfJS-BA Malicious Script Tries to Load Content

Mal/ObfJS-BA is a malicious script that attempts to load content from a remote site when a compromised web page is browsed.

3/9: Kob-A Trojan Creates Text Files With Configuration Details

Troj/Kob-A is a Trojan for the Windows platform.

3/9: AutoRun-AAT Worm Spreads Via Removable Shared Drives

W32/AutoRun-AAT is a worm for the Windows platform.

3/6: Illomo.B Trojan Dops Multiple Files, Modifies Registry

W32/Ilomo.B is a Trojan that will infect Windows systems.

3/6: Dloadr-CIA Trojan Communicates With Remote Server

Troj/Dloadr-CIA is a Trojan for the Windows platform.

3/6: Dropper.EAA Trojan Drops, Executes Files

Troj_Dropper.EAA Trojan may be dropped by other malware.

3/6: BackDoor-DTN Trojan Exploits Microsoft Flaw to Give Attacker Admin Privileges

BackDoor-DTN is a backdoor Trojan that has rootkit capabilities.

3/6: Agent-JDB Trojan Sets Registry Entry, Stores Recorded Information

Troj/Agent-JDB is a Trojan for the Windows platform.

3/6: Undertake-B a Polymorphic Virus

W32/Undertake-B is a polymorphic virus for the Windows platform.

3/6: FlyStud.C a Keylogger Trojan That Captures Passwords

FlyStud.C is a variant of the Key Logger Trojan that captures passwords as they are entered or transmitted.

3/6: Agent-JDD Trojan Creates Registry Entry to Run Itself on Startup

Troj/Agent-JDD is a Trojan for the Windows platform.

3/6: Downadup.C Trojan Dropped by Worm Family

W32.Downadup.C is a Trojan horse that is downloaded on to the compromised computer by the W32.Downadup family of worms.

3/5: SillyFDC.BAZ Worm Copies Itself to Removable Drives

W32.SillyFDC.BAZ is a worm that spreads by copying itself to removable drives.

3/5: Dloader.ACG Trojan Drops Copy of Itself, Malicious Text File in Folder

Troj_Dloader.ACG Trojan may be dropped or downloaded by other malware.

3/5: SillyFDC.BBA Worm Copies Itself to Spread

W32.SillyFDC.BBA is a worm that spreads by copying itself to removable drives.

3/5: Dloader.ACI Trojan May be Dropped by Other Malware

Troj_Dloader.ACI is a Trojan that may be dropped by the following malware: TROJ_DROPPER.EAA

3/5: Hosts-F Trojan Installs New HOSTS File to Redirect User

Troj/Hosts-F installs a new HOSTS file in order to redirect the user from legitimate internet banking sites to malicious domains.

3/5: Dropper.EAT Trojan May be Unknowingly Downloaded

Troj_Dropper.EAT Trojan may be downloaded unknowingly by a user when visiting malicious Web site(s).

3/5: Spynov-Gen Trojan Family Install Themselves as Service

Troj/Spynov-Gen is a family of Trojans for the Windows platform.

3/5: Mal/Inject-D a Malicious Windows Program

Mal/Inject-D is a malicious program for the Windows platform.

3/5: SillyFDC.BAY Worm Copies Itself to Removable, Mapped Drives

W32.SillyFDC.BAY is a worm that spreads by copying itself to removable and mapped drives.

3/5: Mal/ObfJS-AT Malicious Script Attempts to Load Content

Mal/ObfJS-AT is a malicious script that attempts to load content from a remote site when a compromised web page is browsed.

Stimulus Scams Booming on Web

The FTC sounds the alarm that con men of every stripe are attempting to grab part of the Obama administration's stimulus package.

3/5: Popwin.CJM Trojan Drops Multiple Files

W32/Popwin.CJM is a Trojan that will infect Windows systems.

3/5: Pykse-E Worm Creates Registry Entries to Run on Startup

W32/Pykse-E is a worm for the Windows application.

Koobface on the Move, Experts Say

In addition to Facebook, this tough malicious bug may be infecting targets across the Web.

3/5: Autoit-CE Worm Attempts to Download More Malware

W32/Autoit-CE is a worm for the Windows platform.

3/5: Dialer.JF Trojan Uses Diales Numbers to Create Dial-Up Connection

Win32/Dialer.JF is a Trojan component that is usually dropped onto a system by other malware and used as a dialer.

3/5: Fruspam.J Mass-Mail Worm Uses Own SMTP Engine

Win32/Fruspam.J is a mass-mailing worm that has the capability to send spam email through its own SMTP engine.

3/4; Malas-D Worm Copies Itself, Creates Files

W32/Malas-D is a worm for the Windows platform.

3/4: SmallTR.OZ Trojan Accesses URLs to Display Pop-Up Ads

Troj_SmallTR.OZ is a Trojan may be dropped by the following malware: TROJ_FAKEALRT.RC

3/4: Autorun-AAG Worm Creates File, Sets Registry Entry

W32/Autorun-AAG is a worm for the Windows platform.

3/4: Agent-JCS Trojan Creates Registry Entry to Run on Startup

Troj/Agent-JCS is a Trojan for the Windows platform.

3/4: PWS-Gamania.gen.g a Game Password-Stealing Trojan

PWS-Gamania.gen.g. is a password-stealing Trojan that attempts to steal user information for certain online games.

3/4: Bankolimb.CH Trojan Obtains Confidential User Information

Bankolimb.CH is a Trojan designed to obtain confidential information from the user, such as passwords and usernames.

3/4: Koobface.worm Spreads Via Facebook, MySpace

W32/Koobface.worm spreads via Facebook and MySpace.

3/4: FakeAlert-SpyKiller Trojan Displays Fake Warning Message

FakeAlert-SpyKiller is a Trojan that shows a fake warning message, alarming the user that their machine is infected or at risk.

3/4: Mal/PDFJs-A Uses JavaScript to Install More Malware

Mal/PDFJs-A uses JavaScript to install other malicious software.

3/4: Pushu-Gen Trojan Family Create Files

Troj/Pushu-Gen is a family of Trojans for the Windows platform.

3/4: Koobface.AZ Worm Drops .Exe File

W32/Koobface.AZ is a Windows worm that upon execution drops freddy35.exe in Windows folder.

3/4: Banloa-FR Trojan Creates File, Changes Registry, Sets New One

Troj/Banloa-FR is a Trojan for the Windows platform.

3/4: Iframe-AQ Malicious Script is Injected Into Web Page

Troj/Iframe-AQ is a malicious script injected into a web page that attempts to silently load malicious content from a remote site when the page is browsed.

3/4: Downloader D Program Drops, Executes Malicious Software

Downloader D is a program that downloads and may execute or install software without user permission.

3/4: SillyDI GIP a Downloader Trojan

SillyDl GIP is a downloader Trojan.

3/3: SillyFDC.BAU Worm Copies Itself to Spread

W32.SillyFDC.BAU is a worm that spreads by copying itself to removable drives.

3/3: FakeAlert-SystemSecurity Trojan Displays Misleading, Fake Alerts

FakeAlert-SystemSecurity is a detection for a Trojan that displays misleading fake alerts to entice the user into buying a product.

3/3: SillyFDC.BAW Worm Copies Itself to Removable Drives

W32.SillyFDC.BAW is a worm that spreads by copying itself to removable drives.

3/3: Mal/ObfJS-AT Malicious Script Tries to Load Remote Content

Mal/ObfJS-AT is a malicious script that attempts to load content from a remote site when a compromised web page is browsed.

3/3: Mal/WaledPak-A Worm Communicates With Remote Server

Mal/WaledPak-A is a worm for the Windows platform.

3/3: Infostealer.Dunfyter Trojan Steals Online Game Info

Infostealer.Dunfyter is a generic detection for Trojan horses that attempt to steal information related to the online game Dungeon & Fighter (DNF).

3/3: Trojan.Neprodoor!inf Detects Infected .Sys Files

Trojan.Neprodoor!inf is a detection for infected ndis.sys driver files.

3/3: Mal/ZbotTemp-A Trojan Used to Drop, Install New Malware

Mal/ZbotTemp-A is a component of the Mal/Zbot family of Trojans.

3/3: Banker-EPN Trojan Creates Registry Entries to Run on Startup

Troj/Banker-EPN copies itself to the Windows folder with the name wmiprevse.exe.

Digg Hackers' New Target: YouTube

Malware creators spread their malicious content via the comments section.

3/3: VirusDoctor.A Trojan Drops Files, Modifies Registry

W32/VirusDoctor.A is a Trojan that will infect Windows systems.

3/3: Whizz.A Trojan Prevents Proper Computer Usage

Whizz.A is a Trojan that prevents the user from working properly with the computer, as it carries out several annoying actions.

3/3: Losto-Gen Trojan Family Provide Attacker With Remote System Access

Troj/Losto-Gen is a family of remote access Trojans for the Windows platform.

3/2: Worm_Koobface.AZ Searches For Cookies on Social Networking Sites

Worm_Koobface.AZ may be dropped by other malware.

3/2: Generic RootKit.x a Detection For Several Trojan Variants

Generic RootKit.x is a detection for several specific Trojan variants.

3/2: Suspicious.Vundo a Detection Technology For Type of Malware

Suspicious.Vundo is a detection technology designed to detect entirely new malware threats without traditional signatures for the Vundo family of Trojans.

Spam over IM, 'Spim' Makes Comeback

Industry observers say they're noticing spim levels increasing, a move that echoes an earlier trend.

3/2: AntiVirusPro.FS Trojan Drops Files in Adware Folder

W32/AntiVirusPro.FS is a Trojan that drops files in C:\Program Files\AdwarePro folder.

3/2: AutoTDSS.XP Worm Drops Files, Modifies Registry

W32/AutoTDSS.XP is a worm that will infect Windows systems.

3/2: Trojan.Neprodoor!inf Detects Infected .Sys Drive Files

Trojan.Neprodoor!inf is a detection for infected ndis.sys driver files.