Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - November 7, 2008

Nov 6, 2008 2:10PM PST

Discussion is locked

- Collapse -
Troj/BHO-HS
Nov 6, 2008 2:11PM PST
- Collapse -
Troj/BHO-HR
Nov 6, 2008 2:12PM PST
- Collapse -
Troj/Agent-IDZ
Nov 6, 2008 2:13PM PST
- Collapse -
Mal/EncPk-FW
Nov 6, 2008 2:14PM PST
- Collapse -
Mal/Cimuz-G
Nov 6, 2008 2:15PM PST
- Collapse -
Mal/Bagle-B
Nov 6, 2008 2:16PM PST
- Collapse -
Mal/Autorun-C
Nov 6, 2008 2:17PM PST
- Collapse -
JS/Psyme-KM
Nov 6, 2008 2:18PM PST
- Collapse -
JS/Dload-EC
Nov 6, 2008 2:19PM PST
- Collapse -
Conduit Browser Help Object
Nov 6, 2008 2:20PM PST
- Collapse -
A-Patch
Nov 6, 2008 2:21PM PST
- Collapse -
W32/Autorun-NS
Nov 6, 2008 11:49PM PST
- Collapse -
Troj/Mdrop-BWQ
Nov 6, 2008 11:50PM PST
- Collapse -
Troj/Dwnldr-HKE
Nov 6, 2008 11:51PM PST
- Collapse -
Troj/Drop-BI
Nov 6, 2008 11:52PM PST
- Collapse -
Troj/Agent-IEA
Nov 6, 2008 11:53PM PST
- Collapse -
Troj/PWS-AVW
Nov 6, 2008 11:54PM PST
- Collapse -
Troj/FakeAle-JO
Nov 6, 2008 11:55PM PST
- Collapse -
Troj/Agent-IEC
Nov 6, 2008 11:56PM PST

Category Viruses and Spyware

Type Trojan

Troj/Agent-IEC is a multi-component Trojan for the Windows platform.

Troj/Agent-IEC copies itself to the following locations:

<System>\explorer.exe
<System>\iexplore.exe
<Windows>\svchost.exe

The Trojan also creates the file <System>\flash.exe which is a legitimate Shockwave Flash application.

Troj/Agent-IEC creates the following registry entries to run itself on system restart:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
explorer
<System>\explorer.exe

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
svchost
<Windows>\svchost.exe

http://www.sophos.com/security/analyses/viruses-and-spyware/trojagentiec.html?_log_from=rss

- Collapse -
Troj/Agent-IEB
Nov 6, 2008 11:57PM PST
- Collapse -
Virus Alerts [Panda Security's weekly report on viruses and
Nov 7, 2008 12:45AM PST

Virus Alerts [Panda Security's weekly report on viruses and intruders - 11/07/0Cool

- Panda Security's weekly report on viruses and intruders -

Virus Alerts, by Panda Security (http://www.pandasecurity.com)

The PCDefender2008 adware, the Downloader.UYC malicious script and the
MSNWorm.FH worm are the subject of this week's PandaLabs report.

PCDefender2008 is a "fake antivirus" adware that reaches computers with
the name pcdefender2008Install.exe. Once installed, it simulates a
computer scan to make users believe they are infected by dozens of
malware samples (image here: ). Its aim is for users to purchase the
fake antivirus promoted by this adware. Once the fake scan is over,
users are offered the option of neutralizing the supposed infections,
and if they accept, a screen is displayed (image here: ) in which users
are given two options: to buy the antivirus or remain infected.

On purchasing the product, users are redirected to the Web page of the
fake product, created by cyber-crooks. If they do not purchase it, the
adware will constantly display reminder messages to infected users,
which is extremely annoying.

"As incredible as it may seem, numerous users continue to fall victim to
these traps. It is therefore advisable to remember a few basic rules
such as not opening emails from unknown senders, and not running files
or clicking links in one of those emails, as that is how these fake
antiviruses enter computers," explains Luis Corrons, technical director
of PandaLabs.

Downloader.UYC is a malicious script designed to download the
Downloader.UYD Trojan, which in turn is used to infect computers with
other malware. To fool users and conceal its malicious actions, once run
on the computer, this script displays a Windows Internet Explorer
window.

The Trojan downloaded by Downloader.UYC is also designed to prevent the
firewall from blocking the downloading of malware.

MSNPhoto.A is a worm that spreads through MSN Messenger. To do so, it
sends a message with an infected file to all the affected users'
contacts so they accept it and become infected.

It also creates a key in the Windows Registry to ensure it is run every
time the session is started. Similarly, it disables several functions
including the system console and the computer recovery feature, and
modifies the host file, preventing access to several Web pages, most of
which are IT security-related, so users find it more difficult to remove
this worm from their computer.

In addition, PandaLabs has warned about the sending of malicious emails
that are using the name of the US president-elect, Barack Obama, as bait
to distribute malware. More information about this story here:
http://www.pandasecurity.com/spain/homeusers/media/press-releases/viewne
ws?noticia=9426

- Collapse -
W32.Gaut.A
Nov 7, 2008 1:20AM PST
- Collapse -
Avert Labs Low-Profiled Threat Notice: PHP/WPTrojan.b
Nov 7, 2008 1:37AM PST
- Collapse -
W32/Autorun-NU
Nov 7, 2008 1:41AM PST

Aliases Win32/Agent.OJO

Category Viruses and Spyware

Type Worm

W32/Autorun-NU is a worm for the Windows platform.

W32/Autorun-NU spreads to other network computers.

W32/Autorun-NU includes functionality to access the internet and communicate with a remote server via HTTP.

When first run W32/Autorun-NU copies itself to:

<Windows>\SSCVIIHOST.exe
<System>\SSCVIIHOST.exe
<System>\blastclnnn.exe

and creates the following files:

<System>\autorun.ini
<System>\dotnetfx.dll
<System>\setting.ini

The file autorun.ini is detected as Mal/AutoInf-A.

More: http://www.sophos.com/security/analyses/viruses-and-spyware/w32autorunnu.html?_log_from=rss

- Collapse -
Troj/SwfDldr-H
Nov 7, 2008 1:42AM PST
- Collapse -
Troj/Psyme-KN
Nov 7, 2008 1:43AM PST
- Collapse -
Troj/Mdrop-BWR
Nov 7, 2008 1:44AM PST
- Collapse -
Troj/FakeAV-GC
Nov 7, 2008 1:45AM PST
- Collapse -
Troj/Dloadr-BYW
Nov 7, 2008 1:45AM PST
- Collapse -
Troj/Agent-IED
Nov 7, 2008 1:46AM PST