Version: 2008
  • On MovieTome: See the villain of IRON MAN 2!
Advanced Search
advertisement
advertisement

Forum display:

Spyware, viruses, & security : VIRUS \ Spyware ALERTS - January 9, 2009

by Marianna Schmudlach Moderator - 1/8/09 7:03 PM
advertisement
Click Here
Post 1 of 57

VIRUS \ Spyware ALERTS - January 9, 2009

by Marianna Schmudlach Moderator - 1/8/09 7:03 PM

W32/Sdbot-DNR


Aliases W32.Spybot.Worm
Worm/Rbot.210944
HASH(0xb22f1d8)

Category Viruses and Spyware

Type Worm

How it spreads Network shares

Affected operating systems Windows
Characteristics Installs itself in the registry


http://www.sophos.com/security/analyses/viruses-and-spyware/w32sdbotdnr.html?_log_from=rss

Post 2 of 57

Troj/PcCli-C

by Marianna Schmudlach Moderator - 1/8/09 7:04 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/trojpcclic.html?_log_from=rss

Post 3 of 57

Troj/MultPs-Gen

by Marianna Schmudlach Moderator - 1/8/09 7:05 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/trojmultpsgen.html?_log_from=rss

Post 4 of 57

Troj/FakeVir-JE

by Marianna Schmudlach Moderator - 1/8/09 7:06 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/trojfakevirje.html?_log_from=rss

Post 5 of 57

Troj/Agent-IOM

by Marianna Schmudlach Moderator - 1/8/09 7:07 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Aliases Trojan.Win32.Agent.asjk
Adware:Win32/AdRotator
Trojan.Fakeavalert

Category Viruses and Spyware

Type Trojan

Troj/Agent-IOM is a Trojan for the Windows platform.

Troj/Agent-IOM drops the following files:

<System>\<random letters>.dll (also detected as Troj/Agent-IOM)
<System>\<random letters>.exe (clean uninstall file)

Troj/Agent-IOM creates the following registry entries to run the DLL file on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
<random letters>
<System>\regsvr32.exe /s "<System>\<random letters>.dll"

Troj/Agent-IOM also installs the DLL file as a Browser Helper Object by creating registry entries under the following locations:

HKCR\CLSID\{<Trojan clsid>}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{<Trojan clsid>}


http://www.sophos.com/security/analyses/viruses-and-spyware/trojagentiom.html?_log_from=rss

Post 6 of 57

Mal/Sality-B

by Marianna Schmudlach Moderator - 1/8/09 7:08 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Malicious Behavior

Mal/Sality-B is a file infected by the Sality family of viruses.


How it spreads Network shares
Infected files

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/malsalityb.html?_log_from=rss

Post 7 of 57

W32/IRCBot-ADJ

by Marianna Schmudlach Moderator - 1/8/09 9:50 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Worm

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/w32ircbotadj.html?_log_from=rss

Post 8 of 57

W32/AutoRun-TN

by Marianna Schmudlach Moderator - 1/8/09 9:51 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Worm

W32/AutoRun-TN is a worm for the Windows platform.

When run W32/AutoRun-TN copies itself to <System>\csrcs.exe and sets the following regitry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\Run
csrcs
<System>\csrcs.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
Hidden
2

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
ShowSuperHidden
0

HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
SuperHidden
0

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Shell
Explorer.exe csrcs.exe

http://www.sophos.com/security/analyses/viruses-and-spyware/w32autoruntn.html?_log_from=rss

Post 9 of 57

W32/AutoRun-TM

by Marianna Schmudlach Moderator - 1/8/09 9:52 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Worm

How it spreads Removable storage devices

Affected operating systems Windows
Characteristics Installs itself in the registry


http://www.sophos.com/security/analyses/viruses-and-spyware/w32autoruntm.html?_log_from=rss

Post 10 of 57

VBS/DownLdr-D

by Marianna Schmudlach Moderator - 1/8/09 9:53 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

VBS/DwnLdr-D is a downloader Trojan which will attempt to download a file from the internet and run it.

The downloaded file is saved in C:\kuruna.exe

http://www.sophos.com/security/analyses/viruses-and-spyware/vbsdownldrd.html?_log_from=rss

Post 11 of 57

Troj/MDrop-BXO

by Marianna Schmudlach Moderator - 1/8/09 9:54 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Troj/MDrop-BXO is a Trojan for the Windows platform.

When run Troj/MDrop-BXO creates the files:

ServerApp.exe - detected as Mal/Behav-024
Stub.exe - detected as Troj/Dropper-QI

http://www.sophos.com/security/analyses/viruses-and-spyware/trojmdropbxo.html?_log_from=rss

Post 12 of 57

Troj/Agent-ION

by Marianna Schmudlach Moderator - 1/8/09 9:55 PM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/trojagention.html?_log_from=rss

Post 13 of 57

W32/Waled-Gen

by Marianna Schmudlach Moderator - 1/9/09 8:27 AM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Worm

W32/Waled-Gen is a worm for the Windows platform.

W32/Waled-Gen includes functionality to access the internet and communicate with a remote server via HTTP and send itself out using built-in SMTP client.


http://www.sophos.com/security/analyses/viruses-and-spyware/w32waledgen.html?_log_from=rss

Post 14 of 57

W32/Autorun-TO

by Marianna Schmudlach Moderator - 1/9/09 8:28 AM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Worm

Affected operating systems Windows

http://www.sophos.com/security/analyses/viruses-and-spyware/w32autorunto.html?_log_from=rss

Post 15 of 57

Troj/Rootkit-EL

by Marianna Schmudlach Moderator - 1/9/09 8:29 AM In reply to: VIRUS \ Spyware ALERTS - January 9, 2009 by Marianna Schmudlach Moderator

Category Viruses and Spyware

Type Trojan

Troj/Rootkit-EL is a rootkit Trojan for the Windows platform.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojrootkitel.html?_log_from=rss

Forum legend:
Locked Locked thread
Moderator Moderator
CNET staff CNET staff
Samsung staff Samsung staff
Norton Authorized Support team Norton Authorized Support team
AVG staff AVG staff
Windows Outreach team Windows Outreach team
Dell staff Dell staff
Intel staff Intel staff
Powered by Jive Software