Click here

Malware: Archive: May 2009 

5/28: Troj/Dldr-X is Low Prevalence Windows Trojan

Troj/Dldr-X is a low prevalence Windows trojan.

5/28: Mal/PDFJs-I is Windows Malware

Mal/PDFJs-I is Windows malware.

5/27: Mal/Gampass-D is Windows Malware

Mal/Gampass-D is malware that targets that Windows platform.

5/27: W32.Simouk Infects Executable Files

W32.Simouk is a virus that infects executable files on the compromised computer.

Nearly All Email is Now Spam

The percentage of email that's spam has risen to a choking 90 percent, according to MessageLabs.

5/26: Troj/VB-EDL is a Windows Trojan

Troj/VB-EDL is a Windows Trojan.

5/26: Troj/Daonol-C Copies itself to the Root Folder

Members of Troj/Daonol-C typically copy themselves to the Root folder.

5/22: Mal/Behav-329 is Windows Malware

Mal/Behav-329 is malware that affects the Windows platform.

5/22: Adio Registry Optimizer is Spyware

Adio Registry Optimizer is spyware, considered to be in the "Rogue Security Software" category.

Does Twitter Create Security Problems?

Though it's a good tool for online conversation, Twitter may be leading some users astray in terms of security.

5/21: W32.Korron.B Replaces Files with Itself

W32.Korron.B is a worm that replaces some file types with a copy of itself.

5/21: Downloader.Kidkiti Downloads to Compromised PC

Downloader.Kidkiti is a Trojan horse that downloads files on to the compromised computer.

5/20: VBS.Runauto.F Copies Itself to Removable Drives

VBS.Runauto.F is a worm that spreads by copying itself to removable drives.

5/20: Mal/Armada-A Send Info to Remote Attacker.

Mal/Armada-A is a Trojan which may gather system information and send it to a remote attacker.

Spammer's Latest: Soft Drink Ads

Never lacking for invention, spammers have begun leveraging fake ads for a health food drink.

The Best Way to Remove Viruses, Spyware and other Malware (Part 1)

Much of today’s malware uses very technically sophisticated defenses against detection, making it far tougher for users to remove.

5/19: Troj/Agent-JXG is a Downloader Trojan

Troj/Agent-JXG is a downloader Trojan for the Windows platform.

5/19: Infostealer.Daonol Redirects Network Traffic

Infostealer.Daonol is a Trojan horse that redirects network traffic and attempts to steal FTP account information from the compromised computer.

5/18: Pigeon AZOD is a Windows Backdoor

Pigeon AZOD is a Windows backdoor.

5/18: Troj/Agent-JWQ is a Windows Trojan

Troj/Agent-JWQ is a Windows Trojan.

IT Security: To Patch or Not to Patch?

Automated software updates may ultimately create security issues for organizations. Who knows what updates are being pushed to user desktops and how they are actually installed?

Facebook Hackers Threaten Beyond Facebook

If hackers get the personal data of Facebook users they can use it to wreak damage beyond Facebook.

5/15: Troj/Bifrose-XI Sets Registry Entries

Troj/Bifrose-XI is a Trojan for the Windows platform that sets registry entries.

5/14: Mal/Sality-C Copies Itself to Removable Devices

Mal/Sality-C also spreads by copying itself to removable devices. The malicious autorun.inf files with hidden, system and read-only attributes are detected as Mal/AutoInf-A.

Security Update for OS X, Safari

Apple releases fixes for a wide array of security concerns, including a vulnerability in Safari.

5/14: Troj/PHPMod-A Detects Compromised PHP Files

Troj/PHPMod-A detects compromised PHP files that have been modified to insert Troj/JSRedir-R into webpages on the server.

5/13: W32.Fiala.A Copies to Fixed and Removable Drives

W32.Fiala.A is a worm that spreads by copying itself to fixed and removable drives. It also drops more malware, lowers security settings and may attempt to download files on to the compromised computer.

5/13: W32.Lujer Infects Executable Files

W32.Lujer is a virus that infects executable files on the compromised computer.

5/12: W32.Lujer Infects Executable Files

W32.Lujer is a virus that infects executable files on the compromised computer.

5/11: Mal/Inject-M Executes other Malware

Mal/Inject-M is a malicious program that drops and executes other malware.

5/11: Packed.Generic.225 is a Heuristic Detection

Packed.Generic.225 is a heuristic detection for files that may have been obfuscated or encrypted in order to conceal them from antivirus software.

5/8: Troj/JSRedir-R Loads from Web Pages

Troj/JSRedir-R is a malicious script likely to have been injected into compromised web pages in order to load remote malicious content when the page is viewed.

5/8: Bloodhound.Exploit.236 Uses Heuristic Detection

Bloodhound.Exploit.236 is a heuristic detection for files attempting to exploit the Adobe Reader 'spell.customDictionaryOpen()' JavaScript Function Remote Code Execution Vulnerability (BID 34740).

Malware Hackers Build Custom Search Engines

Hackers are now constructing their own search engines that offer real links that hide redirect scripts.

5/7: Mal/ObfJS-BV Loads Remote Content

Mal/ObfJS-BV is a malicious script that attempts to load content from a remote site when a compromised web page is browsed.

5/7: Troj/Agent-JTZ is Windows Trojan

Troj/Agent-JTZ is a Trojan for the Windows platform.

5/6: Suspicious.S.Vundo.2 Detects New Malware Threats

Suspicious.S.Vundo.2 is a detection technology designed to detect entirely new malware threats without traditional signatures. This technology is aimed at detecting malicious software that has been intentionally mutated or morphed by attackers.

5/6: PerfectDefender2009 Exaggerates Threats

PerfectDefender2009 is a misleading application that may give exaggerated reports of threats on the computer.

5/6: Troj/Lineag-CF Sets Registry Entry

Troj/Lineag-CF is a Trojan for the Windows platform that creates a number of files when run.

5/5: Troj/Mbroot-F is a Troj/Sinowal Rootkit

Troj/Mbroot-F is a malicious MBR loader installed by a member of the Troj/Sinowal family of rootkits.

5/5: Trojan.Downexec.D!inf Detects Infected Code

Trojan.Downexec.D!inf is a detection for files infected with code to download and execute other potentially malicious files.

5/5: Troj/Mbroot-E is a Malicious MBR Loader

Troj/Mbroot-E is a malicious MBR loader installed by a member of the Troj/Sinowal family of rootkits.

Health IT Challenged by Cyber Threats

Security experts sound the alarm: the Conficker virus compromised hundreds of medical devices.

5/4: Troj/Bckdr-QTY Uses Standard Usernames

Troj/Bckdr-QTY is a backdoor Trojan that gains access to the system by using standard username and passwords.

5/4: W32.Sens.A Steals Sensitive Data

W32.Sens.A is a virus that may infect files on the compromised computer. It may steal sensitive information and may also download files from a remote location.

5/4: Troj/DwnLdr-HQL Copies to the Registry

Troj/DwnLdr-HQL is a Trojan for the Windows platform. When run Troj/DwnLdr-HQL copies itself to \winudpmgr.exe and sets a registry entry.

Cyber Chief Needed in White House, Experts say

The new cybersecurity administrator should be based in the White House itself, experts tell a Congressional panel.

5/1: Troj/Mdrop-CBR Modified Registry

Troj/Mdrop-CBR is a Windows Trojan that modifies the registry.

5/1: Bloodhound.PDF.12 is a Heuristic Detection

Bloodhound.PDF.12 is a heuristic detection for files that may have been obfuscated or encrypted in order to conceal them from antivirus software.

5/1: Trojan.Bankpatch.E Connects to URL

Trojan.Bankpatch.E is a Trojan horse that infects certain system files with code to connect to a predefined URL. The code has the functionality to upload and download data to and from the URL.

Facebook Combats Phishing Scam

For the second time, Facebook had to protect against attempts to get users' personal information.