Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - November 10, 2008

Nov 9, 2008 10:35AM PST

Discussion is locked

- Collapse -
Troj/Agent-IEY
Nov 10, 2008 4:13AM PST
- Collapse -
Troj/Agent-IEX
Nov 10, 2008 4:14AM PST
- Collapse -
SWF_EXPLOIT.CR
Nov 10, 2008 6:51AM PST
- Collapse -
PWS-Mmorpg.gen!24C50506
Nov 10, 2008 6:52AM PST

Alert ID : FrSIRT/ALRT-2008-06923
Aliases : N/A
Size : N/A
Rated as : Low Risk
Release Date : 2008-11-10


Description

This is a Trojan detection. Unlike viruses, Trojans do not self-replicate. They are spread manually, often under the premise that they are beneficial or wanted.

References

http://vil.nai.com/vil/content/v_153330.htm

Credits

Reported by McAfee

- Collapse -
Infostealer.Keylog.KU
Nov 10, 2008 6:54AM PST
- Collapse -
Stupid Rogue Trick
Nov 10, 2008 7:41AM PST

Monday, November 10, 2008

We came across a rogue today called Antivirus Professional 2008 that uses GeoIP Lookup as part of its scare tactics.

This site uses Flash and script to create the effect of an online scan, that then attempts to push an installer at the visitor.

The NoScript extension for Mozilla Firefox is an excellent way to mitigate against this kind of garbage.

More: http://www.f-secure.com/weblog/

- Collapse -
Troj/Killav-DQ
Nov 10, 2008 7:48AM PST
- Collapse -
Troj/FakeVir-HF
Nov 10, 2008 7:49AM PST
- Collapse -
Troj/FakeVir-HE
Nov 10, 2008 7:51AM PST
- Collapse -
Troj/FakeAV-GE
Nov 10, 2008 7:52AM PST
- Collapse -
Troj/DNSCha-D
Nov 10, 2008 7:53AM PST
- Collapse -
Troj/Dloadr-BZC
Nov 10, 2008 7:54AM PST
- Collapse -
Troj/Dloadr-BZB
Nov 10, 2008 7:55AM PST

Aliases TR/Crypt.PEPM.Gen
TrojanDownloader:Win32/Small.gen!F

Category Viruses and Spyware

Type Trojan

Troj/Dloadr-BZB is a downloader Trojan for the Windows platform.

Troj/Dloadr-BZB is a modified version of an NVIDIA Driver.

Troj/Dloadr-BYZ renames the clean NVIDIA Driver <System>\nvsvc32.exe to <System>\nvsvc32.exe.tmp and copies itself to <System>\nvsvc32.exe, thus replacing the existing NVIDIA Driver with itself.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojdloadrbzb.html?_log_from=rss

- Collapse -
Troj/Dloadr-BYZ
Nov 10, 2008 7:56AM PST

Aliases Trojan-Downloader.Win32.Agent.akph
TrojanDownloader:Win32/Small.gen!F
Trojan:Win32/Meredrop
Backdoor:WinNT/Farfli.E!sys

Category Viruses and Spyware

Type Trojan

Troj/Dloadr-BYZ is a downloader Trojan for the Windows platform.

When first run Troj/Dloadr-BYZ moves itself to <System>\vssrvc.exe and creates the file <System>\usbdisk.sys.

Troj/Dloadr-BYZ is registered as a new file system driver service named "VistualPC", with a display name of "Vistual PC" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\VistualPC

The file usbdisk.sys is registered as a new system driver service named "usbdisk", with a display name of "usbdisk" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\usbdisk

Troj/Dloadr-BYZ renames the clean system file <System>\nvsvc32.exe to <System>\nvsvc32.exe.tmp and drops a new replacement file named nvsvc32.exe.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojdloadrbyz.html?_log_from=rss

- Collapse -
Troj/Bckdr-EDZ
Nov 10, 2008 7:57AM PST
- Collapse -
Troj/Agent-IFA
Nov 10, 2008 7:58AM PST
- Collapse -
Perfect Keylogger
Nov 10, 2008 8:00AM PST
- Collapse -
FindKeyXP
Nov 10, 2008 8:01AM PST