Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - October 17, 2008

Oct 16, 2008 12:27PM PDT

Discussion is locked

- Collapse -
Troj/Agent-HXV
Oct 16, 2008 12:28PM PDT
- Collapse -
Troj/PWS-AUK
Oct 16, 2008 12:29PM PDT
- Collapse -
Troj/PWS-AUL
Oct 16, 2008 12:29PM PDT
- Collapse -
W32/AutoRun-MB
Oct 16, 2008 12:31PM PDT
- Collapse -
W32/HostInf-A
Oct 16, 2008 2:53PM PDT

Category Viruses and Spyware

Type Worm

W32/HostInf-A is a worm with IRC backdoor functionality for the Windows platform.

W32/HostInf-A modifies the infected computers hosts file.

W32/HostInf-A runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over
the computer via IRC channels.

When first run W32/HostInf-A copies itself to <System&gtMischief<temp name>.exe.

http://www.sophos.com/security/analyses/viruses-and-spyware/w32hostinfa.html?_log_from=rss

- Collapse -
Troj/RootKit-DY
Oct 16, 2008 2:54PM PDT
- Collapse -
Troj/Agent-HXX
Oct 16, 2008 2:56PM PDT
- Collapse -
Troj/Agent-HXW
Oct 16, 2008 2:57PM PDT
- Collapse -
PlayMp3
Oct 16, 2008 2:58PM PDT
- Collapse -
Troj/Agent-HXY
Oct 17, 2008 12:41AM PDT
- Collapse -
JS/Psyme-KH
Oct 17, 2008 12:42AM PDT
- Collapse -
Troj/Zlob-APJ
Oct 17, 2008 12:43AM PDT
- Collapse -
Troj/Keygen-CN
Oct 17, 2008 12:44AM PDT
- Collapse -
Troj/IFrame-BH
Oct 17, 2008 12:45AM PDT
- Collapse -
Troj/FakeVir-GM
Oct 17, 2008 12:46AM PDT
- Collapse -
Troj/DwnLdr-HJI
Oct 17, 2008 12:47AM PDT
- Collapse -
Troj/Agent-HXZ
Oct 17, 2008 12:48AM PDT
- Collapse -
JS/Dload-DZ
Oct 17, 2008 12:49AM PDT
- Collapse -
CouponBar
Oct 17, 2008 12:59AM PDT

Category Adware or PUA

Type Unspecified PUA

App/CoupBar-A is a potentially unwanted application.

When the application is installed the following files are created:

<Windows>\CBBasis.xml
<Windows>\CBVersion.txt
<Windows>\CouponBarIE.dll
<Windows>\cpbrkpie.ocx
<Windows>\UccSpecB.sys

The files CouponBarIE.dll and cpbrkpie.ocx are registered as COM objects, creating registry entries under:

http://www.sophos.com/security/analyses/adware-and-puas/couponbar.html?_log_from=rss

- Collapse -
AntivirusPlasma
Oct 17, 2008 1:48AM PDT
- Collapse -
Worm:W32/AutoRun.NOI
Oct 17, 2008 1:55AM PDT

Name : Worm:W32/AutoRun.NOI
Detection Names : Worm.Win32.AutoRun.noi

Aliases : W32/Autorun-jl (Sophos)
Generic.dx trojan (McAfee)
WORM_AUTORUN.RC (Trend Micro)
W32.SillyFDC (Symantec)
Worm:Win32/Emold.C (Microsoft)

Type: Worm
Category: Malware

Summary
AutoRun worm.

Additional Details
Worm.Win32.AutoRun.noi creates a copy of itself as the following:


C:\Program Files\Microsoft Common\wuauclt.exe

It creates the following registry key:


HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\explorer.exe
Debugger = "%ProgramFiles%\Microsoft Common\wuauclt.exe


Note: The key is created for automatic execution when explorer.exe is launched.

http://www.f-secure.com/v-descs/worm_w32_autorun_noi.shtml

- Collapse -
Troj/JSRedir-D
Oct 17, 2008 1:56AM PDT
- Collapse -
Troj/JSAdCli-D
Oct 17, 2008 1:57AM PDT
- Collapse -
Troj/FakeVir-GL
Oct 17, 2008 1:58AM PDT

Category Viruses and Spyware

Type Trojan

Troj/FakeVir-GL is a Trojan for the Windows platform.

Troj/FakeVir-GL creates the files:

<Windows>\brastk.exe - detected as Troj/FakeVir-GL
<Windows>\karna.dat - detected as Mal/EncPk-BB
<System>\beep.sys - detected as Mal/FakeAle-C

The following registry entries are set:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows
AppInit_DLLs
karna.da

HKCU\Software\Microsoft\Internet Explorer\Main
Enable Browser Extensions
yes

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
brastk
<Windows>\brastk.exe

http://www.sophos.com/security/analyses/viruses-and-spyware/trojfakevirgl.html?_log_from=rss

- Collapse -
Troj/FakeAV-EV
Oct 17, 2008 1:59AM PDT
- Collapse -
Troj/FakeAv-EU
Oct 17, 2008 2:00AM PDT
- Collapse -
Troj/Dloadr-BVY
Oct 17, 2008 2:01AM PDT

Category Viruses and Spyware

Type Trojan

Troj/Dloadr-BVY is a Trojan for the Windows platform.

Troj/Dloadr-BVY includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/Dloadr-BVY is installed it creates the file <Temp>\wewt0.bat.

Registry entries are created under:

HKCU\Software\Applications
HKCR\multimediaControls.chl\CLSID

http://www.sophos.com/security/analyses/viruses-and-spyware/trojdloadrbvy.html?_log_from=rss

- Collapse -
Troj/Dloadr-BVX
Oct 17, 2008 2:02AM PDT
- Collapse -
Troj/Banker-ENU
Oct 17, 2008 2:03AM PDT
- Collapse -
Troj/JSRedir-C + Mal/EncPk-CZ.
Oct 17, 2008 2:06AM PDT

Crafty little redirect

17 October 2008

As discussed previously, redirection - the ability to guide/control user traffic - plays a critical role in today?s malware [1]. In this post I will describe a crafty way of redirecting users from a web page. Not new by any means, but seen again recently in the distribution of fake alert malware.

Our favourite-fake-alert-attackers ? have uploaded a whole series of malicious web pages packed with enticing keywords intended to catch user traffic. Numerous domains have been used, including some that were hosted on AOL servers [2]. Many of the pages follow standard templates, so are visually very similar:

More: http://www.sophos.com/security/blog/2008/10/1865.html