Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - November 4, 2008

Nov 3, 2008 10:10AM PST

Discussion is locked

- Collapse -
Troj/Agent-ICZ
Nov 3, 2008 10:11AM PST
- Collapse -
Troj/Spy-BI
Nov 3, 2008 1:48PM PST
- Collapse -
Troj/FakeAV-FY
Nov 3, 2008 1:49PM PST
- Collapse -
Troj/Dloadr-BXZ
Nov 3, 2008 1:50PM PST
- Collapse -
Troj/Agent-IDA
Nov 3, 2008 1:51PM PST
- Collapse -
Troj/Kerbot-A
Nov 3, 2008 11:42PM PST
- Collapse -
Troj/FakeAle-JL
Nov 3, 2008 11:43PM PST
- Collapse -
Troj/Dorf-BW
Nov 3, 2008 11:44PM PST
- Collapse -
Troj/Dloadr-BYB
Nov 3, 2008 11:45PM PST
- Collapse -
Troj/Dload-EF
Nov 3, 2008 11:46PM PST
- Collapse -
Troj/Dload-BYA
Nov 3, 2008 11:47PM PST
- Collapse -
Troj/BadCab-A
Nov 3, 2008 11:48PM PST
- Collapse -
Abusing Magic for fun and profit
Nov 4, 2008 12:36AM PST

4 November 2008

So called ?Magic? numbers evolved from the UNIX operating system and now play a regular role in (amongst others) identifying particular file types. The doctoring of these magic numbers may render files unrecognisable by the operating system or applications expecting to work with them - and malware authors have long ago attempted to leverage this.

Malware authors are again rediscovering the usefulness of magic mangling and exploiting the fact that anti-virus engines also recognise files using magic - allowing them to hide certain content by preventing the correct parsing of tainted objects.

A recent example of this is the Troj/BadCab-A Trojan which to the casual observer might appear to be a legitimate Microsoft CAB file SFX?er - yet the CAB object appears to be missing from its regular location in the resource section?

More: http://www.sophos.com/security/blog/2008/11/1919.html

- Collapse -
Troj/AntiAV-D
Nov 3, 2008 11:50PM PST
- Collapse -
Troj/Agent-IDD
Nov 3, 2008 11:51PM PST
- Collapse -
Troj/Agent-IDC
Nov 3, 2008 11:52PM PST
- Collapse -
Sus/ObfJS-BL
Nov 3, 2008 11:53PM PST
- Collapse -
Trojan.Farfli!SP
Nov 4, 2008 12:40AM PST
- Collapse -
W32/Small-EMR
Nov 4, 2008 12:43AM PST
- Collapse -
Troj/PWS-AVP
Nov 4, 2008 12:45AM PST
- Collapse -
Troj/OnlineG-BM
Nov 4, 2008 12:46AM PST
- Collapse -
Mal/Sality-A
Nov 4, 2008 12:48AM PST
- Collapse -
Mal/Sality-B
Nov 4, 2008 12:49AM PST
- Collapse -
Troj/Prosti-DK
Nov 4, 2008 12:50AM PST
- Collapse -
Hupig-D Trojan - McCain pulls ahead in pharmaceutical spam
Nov 4, 2008 12:56AM PST

Taking the political temperature through the medium of *****-enlargement promises

By John Leyden ? Get more from this author

Posted in Spam, 4th November 2008

Barack Obama is ahead not only in the polls but where it counts the most - in spam messages. However, his presidential rival John McCain can claim his own guaranteed enlarged small victory.

The Democrat candidate is the topic of 70 per cent more junk mail messages than his Republican counterpart overall. But McCain edges ahead by a ratio of five to four in one important category - pharmacy spam, according to stats from Secure Computing.

So based on the volume of *****-enlargement pill promises the senior senator from Arizona is well ahead of the Illinois whippersnapper.

More: http://www.theregister.co.uk/2008/11/04/us_election_spam_results/

- Collapse -
Troj/Gimmiv-Gen
Nov 4, 2008 2:59AM PST

Aliases TrojanSpy:Win32/Gimmiv.A
TrojanSpy:Win32/Gimmiv.A.dll

Category Viruses and Spyware

Type Trojan

Troj/Gimmiv-Gen is a family of Trojans for the Windows platform.

When members of Troj/Gimmiv-Gen are run, the following file is usually dropped:

<System>\wbem\sysmgr.dll

Members of Troj/Gimmiv-Gen typically set the following registry entries to link the dll with svchost.exe:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost
sysmgr
sysmgr

HKLM\SYSTEM\CurrentControlSet\Services\sysmgr\Parameters
ServiceDll
<System>\wbem\sysmgr.dll

HKLM\SYSTEM\CurrentControlSet\Services\sysmgr\Parameters
ServiceMain
ServiceMainFunc

More: http://www.sophos.com/security/analyses/viruses-and-spyware/trojgimmivgen.html?_log_from=rss

- Collapse -
Exp/MS08067-A
Nov 4, 2008 3:00AM PST
- Collapse -
Troj/Dloadr-BYD
Nov 4, 2008 5:27AM PST
- Collapse -
Troj/Zlob-AQJ
Nov 4, 2008 8:19AM PST
- Collapse -
Troj/Zlob-AQI
Nov 4, 2008 8:20AM PST