Version: 2008
Advanced Search
advertisement
advertisement

Forum display:

Spyware, viruses, & security : VIRUS \ Spyware ALERTS - November 14, 2008

by Marianna Schmudlach Moderator - 11/13/08 6:43 PM
advertisement
Post 1 of 53

VIRUS \ Spyware ALERTS - November 14, 2008

by Marianna Schmudlach Moderator - 11/13/08 6:43 PM

W32/Autorun-OS


Aliases Worm:Win32/Autorun.FC
Win32/Autorun.XFN
Win32/Yacspeel.gen!A
WORM_AUTORUN.BCX
Win32.AutoRun.byt

Category Viruses and Spyware

Type Worm


W32/Autorun-OS is a worm for the Windows platform.

W32/Autorun-OS contains functionality to spread via removable storage devices.


http://www.sophos.com/security/analyses/viruses-and-spyware/w32autorunos.html?_log_from=rss

Post 2 of 53

Troj/Renos-BM

by Marianna Schmudlach Moderator - 11/13/08 6:44 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/trojrenosbm.html?_log_from=rss

Post 3 of 53

Troj/FakeAV-GK

by Marianna Schmudlach Moderator - 11/13/08 6:45 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows
Characteristics Installs itself in the registry

http://www.sophos.com/security/analyses/viruses-and-spyware/trojfakeavgk.html?_log_from=rss

Post 4 of 53

Troj/Dropr-AK

by Marianna Schmudlach Moderator - 11/13/08 6:46 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Troj/Dropr-AK is a Trojan for the Windows platform.

When first run, the Trojan creates the following file:

<Program Files>\Microsoft Office\<System>\sysbar.exe

The file sysbar.exe is detected as Mal/Emogen-N.

Troj/Dropr-AK sets the following registry entries:

HKCR\.key
""
regfile

HKCR\CLSID\{F9BA1AA9-CAD4-4C14-BDE6-922DFF5F6F38}

http://www.sophos.com/security/analyses/viruses-and-spyware/trojdroprak.html?_log_from=rss

Post 5 of 53

Troj/Dloadr-BZM

by Marianna Schmudlach Moderator - 11/13/08 6:47 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Troj/Dloadr-BZM is a Trojan for the Windows platform.

Troj/Dloadr-BZM downloads, installs and runs rogue anti-virus malware detected as Troj/FakeAV-GK.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojdloadrbzm.html?_log_from=rss

Post 6 of 53

Troj/Agent-IFV

by Marianna Schmudlach Moderator - 11/13/08 6:48 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/trojagentifv.html?_log_from=rss

Post 7 of 53

Troj/Agent-IFU

by Marianna Schmudlach Moderator - 11/13/08 6:49 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/trojagentifu.html?_log_from=rss

Post 8 of 53

Troj/Agent-IFT

by Marianna Schmudlach Moderator - 11/13/08 6:50 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/trojagentift.html?_log_from=rss

Post 9 of 53

Troj/Agent-IFS

by Marianna Schmudlach Moderator - 11/13/08 6:50 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/trojagentifs.html?_log_from=rss

Post 10 of 53

Mal/FakeAV-F

by Marianna Schmudlach Moderator - 11/13/08 9:34 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Malicious Behavior

Mal/FakeAV-F is a malicious executable that pretends to be an anti-virus product and that exaggerates threats on the infected computer.

http://www.sophos.com/security/analyses/viruses-and-spyware/malfakeavf.html?_log_from=rss

Post 11 of 53

Troj/JSDown-C

by Marianna Schmudlach Moderator - 11/13/08 9:36 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Troj/JSDown-C is a malicious web page that attempts to exploit vulnerable ActiveX controls.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojjsdownc.html?_log_from=rss

Post 12 of 53

Troj/FakeAV-BG

by Marianna Schmudlach Moderator - 11/13/08 9:37 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/trojfakeavbg.html?_log_from=rss

Post 13 of 53

Troj/DwnLdr-HKM

by Marianna Schmudlach Moderator - 11/13/08 9:38 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Troj/DwnLdr-HKM is a downloader Trojan for the Windows platform.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojdwnldrhkm.html?_log_from=rss

Post 14 of 53

Troj/Bdoor-APW

by Marianna Schmudlach Moderator - 11/13/08 9:39 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Troj/Bdoor-APW is a Trojan for the Windows platform.

Troj/Bdoor-APW copies itself to <SYSTEM>\iexplore.exe and sets a registry entry to run on startup.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojbdoorapw.html?_log_from=rss

Post 15 of 53

W32.Sigougou

by Marianna Schmudlach Moderator - 11/13/08 9:45 PM In reply to: VIRUS \ Spyware ALERTS - November 14, 2008 by Marianna Schmudlach Moderator

Type: Worm

W32.Sigougou is a worm that spreads through mapped drives and network shares protected by weak passwords. It attempts to disable security-related processes and may download files on to the compromised computer.

http://www.symantec.com/business/security_response/writeup.jsp?docid=2008-111310-3725-99

Forum legend:
Locked Locked thread
Moderator Moderator
CNET staff CNET staff
Samsung staff Samsung staff
Norton Authorized Support team Norton Authorized Support team
AVG staff AVG staff
Windows Outreach team Windows Outreach team
Dell staff Dell staff
Intel staff Intel staff
Powered by Jive Software