Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - October 15, 2008

Oct 14, 2008 2:47PM PDT

Discussion is locked

- Collapse -
Troj/Bckdr-QPW
Oct 14, 2008 2:49PM PDT
- Collapse -
Troj/Agent-HXJ
Oct 14, 2008 2:49PM PDT
- Collapse -
Troj/PSW-FV
Oct 14, 2008 2:51PM PDT
- Collapse -
Troj/Merein-Gen
Oct 14, 2008 2:52PM PDT
- Collapse -
Troj/Mdrop-BWH
Oct 14, 2008 2:53PM PDT
- Collapse -
W32/AutoRun-LT
Oct 15, 2008 12:41AM PDT

Category Viruses and Spyware

Type Worm

W32/AutoRun-LT is a worm for the Windows platform.

When run W32/AutoRun-LT copies itself to <System>\vistaupgrade.exe and sets the following registry entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
VistaUpgrade
<System>\vistaupgrade.exe

W32/AutoRun-LT spreads via removable shared drives by copying itself to <Root&gtMischief<worm executable>.exe and creating the file <Root>\autorun.inf (detected as W32/Autorun-KQ).

http://www.sophos.com/security/analyses/viruses-and-spyware/w32autorunlt.html?_log_from=rss

- Collapse -
Troj/Agent-HXM
Oct 15, 2008 12:42AM PDT
- Collapse -
Troj/Agent-HXL
Oct 15, 2008 12:43AM PDT
- Collapse -
Troj/Agent-HXK
Oct 15, 2008 12:44AM PDT
- Collapse -
JS/Dload-DY
Oct 15, 2008 12:45AM PDT
- Collapse -
W32/AutoRun-LU
Oct 15, 2008 12:46AM PDT
- Collapse -
Troj/Psyme-KG
Oct 15, 2008 12:47AM PDT
- Collapse -
Troj/PDFex-U
Oct 15, 2008 12:48AM PDT
- Collapse -
Troj/Agent-HXO
Oct 15, 2008 12:49AM PDT
- Collapse -
Troj/Agent-HXN
Oct 15, 2008 12:50AM PDT
- Collapse -
Net-Worm:W32/Koobface.BM
Oct 15, 2008 12:52AM PDT

Name : Net-Worm:W32/Koobface.BM
Detection Names : Net-Worm.Win32.Koobface.bm

Type: Net-Worm
Category: Malware

Summary
A type of worm that replicates by sending complete, independent copies of itself over a network.

Details


Registry Modifications
Creates these keys:


HKEY_LOCAL_MACHINE\Microsoft\Windows\CurrentVersion\Run
sysftray32 = c:\windows\bolivar19.exe


http://www.f-secure.com/v-descs/net-worm_w32_koobface_bm.shtml

- Collapse -
W32.Chuzy
Oct 15, 2008 12:53AM PDT
- Collapse -
Trojan.Konov.A
Oct 15, 2008 12:54AM PDT
- Collapse -
Troj/Zlob-Gen
Oct 15, 2008 2:06AM PDT

Category Viruses and Spyware

Type Trojan

Troj/Zlob-Gen detects members of the Zlob family of Trojan downloaders.

The Troj/Zlob-Gen family of Trojans usually attempt to stealth themselves by injecting themselves into another system process or by registering themselves as a service process.

The typical Troj/Zlob-Gen Trojan may create folders in the <System> folder and store downloaded files in these folders and set the following registry entries to run on user startup:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\explorer\run
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

http://www.sophos.com/security/analyses/viruses-and-spyware/trojzlobgen.html?_log_from=rss

- Collapse -
Troj/Mejdho-Gen
Oct 15, 2008 2:10AM PDT
- Collapse -
Troj/Hupigo-Gen
Oct 15, 2008 2:11AM PDT
- Collapse -
Troj/Farfli-Gen
Oct 15, 2008 2:13AM PDT
- Collapse -
Troj/FakeAle-IL
Oct 15, 2008 2:14AM PDT
- Collapse -
Troj/DwnLdr-Gen
Oct 15, 2008 2:15AM PDT
- Collapse -
Troj/Delf-FBG
Oct 15, 2008 2:16AM PDT
- Collapse -
Troj/Agent-HXP
Oct 15, 2008 2:17AM PDT
- Collapse -
Mal/ObfJS-BD
Oct 15, 2008 2:18AM PDT
- Collapse -
Exp/MS04-028
Oct 15, 2008 2:19AM PDT
- Collapse -
Who fears German ?bank certificates?
Oct 15, 2008 2:36AM PDT

October 15, 2008

In the past weeks we have blogged about the scam related to faked bank certificates for Wachovia, Bradesco and Merrill Lynch.
All those attacks attempted to play with fear regarding online security, in good combination with the international bank crisis.
Yesterday we?ve noticed that this kind of spam arrived German mailboxes ? and of course in German language.

More: http://blog.trendmicro.com/

- Collapse -
Backdoor.Bifrose.M
Oct 15, 2008 6:06AM PDT