Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - November 10, 2008

Nov 9, 2008 10:35AM PST

Discussion is locked

- Collapse -
Troj/FakeVir-HD
Nov 9, 2008 10:36AM PST
- Collapse -
Troj/FakeVir-HC
Nov 9, 2008 10:37AM PST
- Collapse -
Troj/FakeAle-JT
Nov 9, 2008 10:39AM PST
- Collapse -
Troj/BHO-HX
Nov 9, 2008 10:40AM PST
- Collapse -
Troj/BHO-HW
Nov 9, 2008 10:41AM PST
- Collapse -
Troj/Bckdr-QQH
Nov 9, 2008 10:42AM PST
- Collapse -
W32/AutoRun-NZ
Nov 9, 2008 2:26PM PST

Category Viruses and Spyware

Type Worm

W32/AutoRun-NZ is a worm for the Windows platform.

When run W32/AutoRun-NZ copies itself to
<System>\vmmon.exe
<System>\wsntfy.exe

and creates the following registry entries:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\\userinit.exe,<System>\vmmon.exe,

HKCU\Software\Microsoft\Windows NT\CurrentVersion
(default)
<random characters>

HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
Microsoft Enterprise Manager
<System>\vmmon.exe

More: http://www.sophos.com/security/analyses/viruses-and-spyware/w32autorunnz.html?_log_from=rss

- Collapse -
Troj/Agent-IES
Nov 9, 2008 2:27PM PST
- Collapse -
Troj/DwnLdr-HKG
Nov 10, 2008 12:01AM PST
- Collapse -
Troj/Banker-EOD
Nov 10, 2008 12:02AM PST
- Collapse -
Troj/Agent-IET
Nov 10, 2008 12:03AM PST
- Collapse -
W32/Autorun-OB
Nov 10, 2008 12:04AM PST
- Collapse -
Troj/IRCBot-ACY
Nov 10, 2008 12:05AM PST
- Collapse -
Troj/Invo-Zip
Nov 10, 2008 12:06AM PST
- Collapse -
Troj/Cinmus-H
Nov 10, 2008 12:07AM PST
- Collapse -
Troj/Bancos-BET
Nov 10, 2008 12:08AM PST
- Collapse -
Troj/Agent-IEU
Nov 10, 2008 12:09AM PST
- Collapse -
Troj/AdClick-FB
Nov 10, 2008 12:10AM PST
- Collapse -
Troj/Zlob-AQW
Nov 10, 2008 1:54AM PST
- Collapse -
Troj/Zlob-AQV
Nov 10, 2008 1:55AM PST

Category Viruses and Spyware

Type Trojan

Troj/Zlob-AQV is a Trojan for the Windows platform.

When Troj/Zlob-AQV is installed the following files are created:

<Current Folder>\iebt.dll
<Current Folder>\iebtmm.exe

The following registry entry is created to run Troj/Zlob-AQV on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
start
<pathname of the Trojan executable>

The file iebt.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{3B7AAEB1-9F3D-4491-9C06-C7165CA8D058}
HKCR\CLSID\{3B7AAEB1-9F3D-4491-9C06-C7165CA8D058}

More: http://www.sophos.com/security/analyses/viruses-and-spyware/trojzlobaqv.html?_log_from=rss

- Collapse -
Troj/Zlob-AQT
Nov 10, 2008 1:56AM PST

Category Viruses and Spyware

Type Trojan

Troj/Zlob-AQT is a Trojan for the Windows platform.

Troj/Zlob-AQT includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/Zlob-AQT is installed it creates the file <Current Folder>\wcm.exe.

The following registry entry is created to run Troj/Zlob-AQT on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
smile
<pathname of the Trojan executable>

Troj/Zlob-AQT changes settings for Microsoft Internet Explorer by modifying values under:

HKCU\Software\Microsoft\Internet Explorer\Main\

Registry entries are created under:

HKCU\Software\Applications

http://www.sophos.com/security/analyses/viruses-and-spyware/trojzlobaqt.html?_log_from=rss

- Collapse -
Troj/Keylog-KU
Nov 10, 2008 1:57AM PST

Category Viruses and Spyware

Type Trojan

Troj/Keylog-KU is a keylogging Trojan for the Windows platform.

Troj/Keylog-KU copies itself to <System>\scvhost.exe and creates the following registry entries to run itself on system restart:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices
SCVHOST
<System>\scvhost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
SCVHOST
<System>\scvhost.exe

Troj/Keylog-KU also attempts to disable operating system tools such as Regedit and the Taskmanager.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojkeylogku.html?_log_from=rss

- Collapse -
Troj/FakeAV-GD
Nov 10, 2008 1:59AM PST
- Collapse -
Troj/Dloadr-BZA
Nov 10, 2008 1:59AM PST
- Collapse -
Mal/Mourn-A
Nov 10, 2008 2:01AM PST
- Collapse -
Mal/FakeAV-M
Nov 10, 2008 2:06AM PST
- Collapse -
Troj/Agent-IEW
Nov 10, 2008 2:07AM PST
- Collapse -
Troj/Agent-IEV
Nov 10, 2008 2:08AM PST
- Collapse -
W32/AutoRun-NZ.
Nov 10, 2008 2:11AM PST

10 November 2008

'Tis The Season To Be Jolly
As is customary every year, SophosLabs analysts brace themselves for the onslaught of various malware/spam campaigns during the Christmas period.

This year, someone has gotten off to an early start by releasing a mass-mailing worm in the form of W32/AutoRun-NZ.

This mass-mailing worm is very similar to the old W32/MyDoom family of mass-mailing worms except that it also incorporates functionality to spread via removable media (like USB keys).

A typical e-mail sent out by the worm looks like this:

More: http://www.sophos.com/security/blog/2008/11/1965.html

- Collapse -
Troj/Agent-IEZ
Nov 10, 2008 4:12AM PST