Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - October 17, 2008

Oct 16, 2008 12:27PM PDT

Discussion is locked

- Collapse -
WORM_OTORUN.AM
Oct 17, 2008 2:08AM PDT

Alert ID : FrSIRT/ALRT-2008-06181
Aliases : N/A
Size : 37376 bytes
Rated as : Low Risk
Release Date : 2008-10-17


Description

This worm may be downloaded from remote sites by other malware. It may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.

References

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OTORUN.AM

Credits

Reported by Trend Micro

- Collapse -
TROJ_AGENT.BRQ
Oct 17, 2008 2:09AM PDT

Alert ID : FrSIRT/ALRT-2008-06182
Aliases : N/A
Size : Varies
Rated as : Low Risk
Release Date : 2008-10-17


Description

This Trojan may be dropped by other malware. It may arrive bundled with malware packages as a malware component. It creates registry entries to enable its automatic execution at every system startup. It also creates registry key(s)/entry(ies) as part of its installation routine. It requires a file to be installed on the system in order for it to execute its routines.

References

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_AGENT.BRQ

Credits

Reported by Trend Micro

- Collapse -
WORM_AUTORUN.ASL
Oct 17, 2008 2:10AM PDT

Alert ID : FrSIRT/ALRT-2008-06183
Aliases : Trojan-PSW.Win32.OnLineGames.zwl (Kaspersky) - Packed.Generic.61 (Symantec) - TR/Crypt.XPACK.Gen (Avira) - Mal/EncPk-DH (Sophos)
Size : 102499 bytes
Rated as : Low Risk
Release Date : 2008-10-17


Description

This worm may be downloaded from remote sites by other malware. It may be dropped by other malware. It may be downloaded unknowingly by a user when visiting malicious Web sites.

References

http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_AUTORUN.ASL

Credits

Reported by Trend Micro

- Collapse -
Virus Alerts [Panda Security's weekly report on viruses and
Oct 17, 2008 2:12AM PDT

Virus Alerts [Panda Security's weekly report on viruses and intruders - 10/17/0Cool

- Panda Security's weekly report on viruses and intruders -

Virus Alerts, by Panda Security (http://www.pandasecurity.com)

The Banbra.GBQ banker Trojan, the APop.A malicious Java Script and the Spammer.AJR Trojan are the focus of this week?s PandaLabs report.

Banbra.GBQ is designed to obtain bank information from the user. This malicious code is distributed through email. To fools users, the executable file passes itself off as a Word document, and when run it opens a document in Portuguese in which users are asked to appear in the regional electoral committee (see image: http://www.flickr.com/photos/panda_security/2947407316).

The idea is to distract users while the Trojan is infecting their computers.

APop.A is a Java Script file that opens a series of Internet Explorer windows when run. One of these opens a page which claims to offer downloads of eMule, the well-known P2P file-sharing application.

Both the Web page and the program are very similar to the originals, however, if users read the installation license carefully, they will see a text warning that the Navipromo adware will also be installed on their computer.

The Spammer.AJR Trojan is designed to send spam from infected computers. These emails have interesting sounding subjects and include a link to a fake YouTube page (see image: http://www.flickr.com/photos/panda_security/2946552395/). If users visit the page, a fake antivirus program will be installed on their system.

- Collapse -
Troj/Agent-HYC
Oct 17, 2008 4:46AM PDT
- Collapse -
Troj/FakeAV-EW
Oct 17, 2008 7:02AM PDT
- Collapse -
Troj/Emold-B
Oct 17, 2008 7:03AM PDT
- Collapse -
Troj/Dloadr-BVZ
Oct 17, 2008 7:04AM PDT
- Collapse -
Troj/BHO-HK
Oct 17, 2008 7:14AM PDT

Aliases trojan

Category Viruses and Spyware

Type Trojan

Troj/BHO-HK is a Trojan for the Windows platform.

When Troj/BHO-HK is installed the following files are created:

<System>\hl.dat
<System>\mp7arc.dat
<System>\mrcmgr.exe
<System>\mshpc.dll
<System>\scerpt.dll

The file mshpc.dll is registered as a COM object and Browser Helper Object (BHO) for Microsoft Internet Explorer, creating registry entries under:

HKCR\CLSID\{161B953B-95F9-4af3-B071-D5FF5EA132EF}
HKCR\Interface\{30989926-2D37-4561-B76F-65D0F89A3560}
HKCR\Interface\{ECEE577A-5B6F-4BDC-9210-DB603D6BEF78}
HKCR\TypeLib\{2D51E439-3AE8-4BF7-8FB2-45F768554DEC}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{161B953B-95F9-4af3-B071-D5FF5EA132EF}

http://www.sophos.com/security/analyses/viruses-and-spyware/trojbhohk.html?_log_from=rss

- Collapse -
Troj/BckDoor-A
Oct 17, 2008 7:15AM PDT
- Collapse -
Troj/Agent-HYE
Oct 17, 2008 7:16AM PDT
- Collapse -
Troj/Agent-HYD
Oct 17, 2008 7:17AM PDT
- Collapse -
Troj/Agent-HYB
Oct 17, 2008 7:19AM PDT
- Collapse -
Troj/Agent-HYA
Oct 17, 2008 7:20AM PDT
- Collapse -
Mal/Pushdo-C
Oct 17, 2008 7:20AM PDT
- Collapse -
WORM_VOTERAI.N.
Oct 17, 2008 7:31AM PDT

First detected in 2007, the WORM_VOTERAI family, which turned up during the presidential election season in Kenya that year, seems to be making a comeback in time for the US elections this year via WORM_VOTERAI.N. This worm, notable for dropping the following incomplete image file of Raila Odinga, has registered several infection counts in North America:

More:http://blog.trendmicro.com/

- Collapse -
W32/Acespade-a
Oct 17, 2008 9:03AM PDT
- Collapse -
Troj/Bancban-RA
Oct 17, 2008 9:10AM PDT

Aliases Trojan-GameThief.Win32.OnLineGames.jtz
TR/ATRAPS.Gen
PWS:Win32/Gamania.gen!B

Category Viruses and Spyware

Type Trojan

Troj/Bancban-RA is a Trojan for the Windows platform.

When Troj/Bancban-RA is installed the following files are created:

<Program Files>\winrar\14m.exe - detected as Troj/Lineag-CU
<Program Files>\winrar\14m.txt - garbage data file
<Program Files>\winrar\2.bat - clean text file
<Windows>\help\F3C74E3FA248.dll - detected as Troj/Lineag-CU
<Windows>\help\F3C74E3FA248.exe - detected as Troj/Lineag-CU

The file F3C74E3FA248.dll is registered as a COM object and shell extension, creating registry entries under:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
{1DBD6574-D6D0-4782-94C3-69619E719765}

HKCR\CLSID\{1DBD6574-D6D0-4782-94C3-69619E719765}

Registry entries are created under:

HKCU\Software\WinRAR SFX


http://www.sophos.com/security/analyses/viruses-and-spyware/trojbancbanra.html?_log_from=rss