Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - November 3, 2008

Nov 2, 2008 9:16AM PST

Discussion is locked

- Collapse -
Troj/Dwnldr-HJZ
Nov 3, 2008 1:11AM PST
- Collapse -
Troj/Drop-BH
Nov 3, 2008 1:12AM PST
- Collapse -
Troj/Dloadr-BXV
Nov 3, 2008 1:13AM PST
- Collapse -
Troj/Bdoor-APH
Nov 3, 2008 1:14AM PST

Category Viruses and Spyware

Type Trojan

Troj/Bdoor-APH is a Trojan for the Windows platform.

Troj/Bdoor-APH includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Bdoor-APH copies itself to:

<Startup>\userinit.exe
<User>\svchost.exe
<System>\drivers\services.exe

The following registry entries are created to run Troj/Bdoor-APH on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
[system]
<System>\drivers\services.exe

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
winlogon
<User>\svchost.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
[system]
<System>\drivers\services.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
winlogon
<User>\svchost.exe

More: http://www.sophos.com/security/analyses/viruses-and-spyware/trojbdooraph.html?_log_from=rss

- Collapse -
Troj/Agent-ICY
Nov 3, 2008 1:15AM PST
- Collapse -
Troj/Agent-ICX
Nov 3, 2008 1:16AM PST
- Collapse -
Mal/ObfJS-BI
Nov 3, 2008 1:17AM PST
- Collapse -
Troj/Arinj-Fam
Nov 3, 2008 3:28AM PST
- Collapse -
Troj/Bredol-Fam
Nov 3, 2008 3:29AM PST
- Collapse -
Troj/Dloadr-BXU
Nov 3, 2008 3:30AM PST
- Collapse -
Troj/Dloadr-BXW
Nov 3, 2008 3:36AM PST
- Collapse -
Troj/Dloadr-BXX
Nov 3, 2008 3:37AM PST
- Collapse -
Troj/FakeAle-JK
Nov 3, 2008 3:39AM PST

Category Viruses and Spyware

Type Trojan

When installed Troj/FakeAle-JK displays fake spyware infection messages.

Troj/FakeAle-JK reduces system security by setting the following registry entries:

HKCU\Software\Microsoft\Security Center\AntiVirusDisableNotify
0x00000001

HKCU\Software\Microsoft\Security Center\FirewallDisableNotify
0x00000001

HKCU\Software\Microsoft\Security Center\UpdatesDisableNotify
0x00000001

More: http://www.sophos.com/security/analyses/viruses-and-spyware/trojfakealejk.html?_log_from=rss

- Collapse -
Troj/Prosti-DK
Nov 3, 2008 3:40AM PST
- Collapse -
Troj/PWS-AVJ
Nov 3, 2008 3:41AM PST
- Collapse -
Troj/PWS-AVM
Nov 3, 2008 3:42AM PST
- Collapse -
Troj/Sinowa-Fam
Nov 3, 2008 3:43AM PST
- Collapse -
Phishers Target Domain Name Registrars
Nov 3, 2008 7:16AM PST

The Trend Micro Content Security Team has discovered a phishing attack that has some unusual targets ? customers of at least two popular domain name registrars and Web hosting companies. Both of them were among the world?s largest domain name registrars in the past year, which would probably explain the phishers? interest.

Here?s a screenshot of the one of the phishing pages:

More: http://blog.trendmicro.com/

- Collapse -
Troj/Zlob-AQG
Nov 3, 2008 8:06AM PST
- Collapse -
Troj/Zlob-AQF
Nov 3, 2008 8:07AM PST
- Collapse -
Troj/Zbot-AP
Nov 3, 2008 8:08AM PST
- Collapse -
Troj/OnlineG-BL
Nov 3, 2008 8:09AM PST
- Collapse -
Troj/FakeAV-FX
Nov 3, 2008 8:10AM PST
- Collapse -
Mal/Sality-B
Nov 3, 2008 8:11AM PST
- Collapse -
Mal/Sality-A
Nov 3, 2008 8:12AM PST
- Collapse -
Mal/ObfJS-BG
Nov 3, 2008 8:13AM PST
- Collapse -
EShoper
Nov 3, 2008 8:14AM PST

Category Adware or PUA

Type Unspecified PUA

EShoper is a potentially unwanted application.

When the application is installed the following folder and files are created:

<System>\eshop.xml
<System>\eshopcamp.xml
<System>\EShopee.exe
<System>\NewmsrdkForKey\

The following registry entry is created to run EShopee.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
EShopee
<System>\EShopee.exe

Registry entries are created under:

HKLM\SOFTWARE\EShopee\KeyWord\

http://www.sophos.com/security/analyses/adware-and-puas/eshoper.html?_log_from=rss

- Collapse -
IsolationAware
Nov 3, 2008 8:15AM PST
- Collapse -
GameVance
Nov 3, 2008 8:16AM PST
- Collapse -
Sus/ObfJS-BI
Nov 3, 2008 8:17AM PST