Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - December 31, 2008

Dec 30, 2008 10:05AM PST

Discussion is locked

- Collapse -
Troj/DwnLdr-HME
Dec 30, 2008 10:06AM PST
- Collapse -
Troj/DownLnk-B
Dec 30, 2008 10:07AM PST
- Collapse -
Troj/Dloadr-CDX
Dec 30, 2008 10:09AM PST
- Collapse -
Troj/Dloadr-CDW
Dec 30, 2008 10:10AM PST
- Collapse -
Troj/Dloadr-CDV
Dec 30, 2008 10:11AM PST
- Collapse -
Troj/Dloadr-CDU
Dec 30, 2008 10:12AM PST
- Collapse -
Troj/BHO-IY
Dec 30, 2008 10:13AM PST
- Collapse -
Troj/Agent-IMQ
Dec 30, 2008 10:14AM PST
- Collapse -
Troj/Agent-IMO
Dec 30, 2008 10:15AM PST
- Collapse -
WORM_DOWNAD.AD
Dec 30, 2008 10:27AM PST

Malware type: Worm

This worm may be downloaded from remote sites by other malware. It may be dropped by other malware. It may arrive bundled with malware packages as a malware component.

It drops copies of itself. This technique prevents dropping of several copies of itself on already affected systems. It also locks its dropped copy to prevent users from reading, writing, and deleting it.

It registers itself as a system service to ensure its automatic execution at every system startup. It does this by creating registry keys/entries.

It drops a copy of itself in all available removable and network drives. It drops an AUTORUN.INF file to automatically execute dropped copies when the drives are accessed.

It creates mutex(es) to ensure that only one instance of itself is running in memory.

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM%5FDOWNAD%2EAD

- Collapse -
W32/Confick-C
Dec 30, 2008 2:34PM PST
- Collapse -
Troj/Renos-CF
Dec 30, 2008 2:36PM PST

Category Viruses and Spyware

Type Trojan

Troj/Renos-CF is a Trojan for the Windows platform.

When run Troj/Renos-CF creates the file <System>\msxml71.dll (detected as Troj/Renos-CF) and creates the following registry entries:

HKCR\CLSID\{500BCA15-57A7-4eaf-8143-8C619470B13D}\InprocServer32
ThreadingModel
Apartment

HKCR\{500BCA15-57A7-4eaf-8143-8C619470B13D}
Install
OK

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{500BCA15-57A7-4eaf-8143-8C619470B13D}
(default)
XML module


http://www.sophos.com/security/analyses/viruses-and-spyware/trojrenoscf.html?_log_from=rss

- Collapse -
Troj/FakeVir-IZ
Dec 30, 2008 2:37PM PST
- Collapse -
Troj/Agent-IMT
Dec 30, 2008 2:38PM PST
- Collapse -
Troj/Agent-IMS
Dec 30, 2008 2:39PM PST
- Collapse -
Troj/Agent-IMR
Dec 30, 2008 2:40PM PST
- Collapse -
Internet Speed Monitor
Dec 30, 2008 2:41PM PST
- Collapse -
Troj/Zlob-AMC
Dec 31, 2008 12:39AM PST
- Collapse -
Troj/PWS-AXJ
Dec 31, 2008 12:40AM PST
- Collapse -
Troj/Mdrop-BVQ
Dec 31, 2008 12:41AM PST
- Collapse -
Troj/FakeAV-HW
Dec 31, 2008 12:42AM PST
- Collapse -
Troj/FakeAV-HU
Dec 31, 2008 12:43AM PST
- Collapse -
Troj/Dloadr-CDY
Dec 31, 2008 12:44AM PST
- Collapse -
Troj/Agent-IMV
Dec 31, 2008 12:45AM PST
- Collapse -
Troj/Agent-IMU
Dec 31, 2008 12:46AM PST

Category Viruses and Spyware

Type Trojan

Troj/Agent-IMU is a Trojan for the Windows platform.

When run the Trojan will copy itself to the system folder as the file csrcs.exe and set the following registry to ensure that it is executed on system restart.

HKLM\Software\Microsoft\Windows\Current Version\Policies\Explorer\Run\Csrcs
<system>\csrcs.exe

Malicious behaviours of Troj/Agent-IMU will be detected and prevented by the following HIPS Runtime Behavior Analysis rules:

HIPS/FileMod-001
HIPS/ProcMod-002
HIPS/RegMod-002
HIPS/RegMod-012
HIPS/RegMod-009

http://www.sophos.com/security/analyses/viruses-and-spyware/trojagentimu.html?_log_from=rss

- Collapse -
Troj/Agent-IMM
Dec 31, 2008 12:47AM PST
- Collapse -
SuperiorAds
Dec 31, 2008 12:48AM PST

Aliases AdWare.Win32.TrafficSol
Win32/Adware.GooochiBiz

Category Adware or PUA

Type Adware

SuperiorAds is an adware-related application, including a plugin for Microsoft Internet Explorer.

SuperiorAds installs a Browser Helper Object with registry entries set under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

SuperiorAds may also have a run-key registry entry set to re-register the plugin on startup using the existing <System>\rundll32.exe application.

http://www.sophos.com/security/analyses/adware-and-puas/superiorads.html?_log_from=rss

- Collapse -
ExpressAntiVirus2009
Dec 31, 2008 1:07AM PST
- Collapse -
Spyware.NetScreenWatch
Dec 31, 2008 1:08AM PST
- Collapse -
Mal/EncPk-EM
Dec 31, 2008 1:12AM PST