Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - October 21, 2008

Oct 20, 2008 12:00PM PDT

W32/Fanbot-I

Aliases Worm.Win32.AutoRun.qxz

Category Viruses and Spyware

Type Worm

W32/Fanbot-I is a worm for the Windows platform.

W32/Fanbot-I includes functionality to access the internet and communicate with a remote server via HTTP.

When first run W32/Fanbot-I copies itself to <System>\llwzjy081019.exe and creates the following files:

<User>\jjjydf16.ini
<Temporary Internet Files>\Content.IE5\od6fwfox\bc1[1].htm
<System>\mvjaj32dla.dll

The file mvjaj32dla.dll is detected as Mal/Behav-236.


http://www.sophos.com/security/analyses/viruses-and-spyware/w32fanboti.html?_log_from=rss

Discussion is locked

- Collapse -
Troj/VBDrop-I
Oct 20, 2008 12:01PM PDT
- Collapse -
Troj/Invo-Zip
Oct 20, 2008 12:02PM PDT
- Collapse -
Troj/Dloadr-BWM
Oct 20, 2008 12:03PM PDT
- Collapse -
Troj/Dloadr-BWL
Oct 20, 2008 12:04PM PDT
- Collapse -
Troj/Dldr-Q
Oct 20, 2008 12:05PM PDT
- Collapse -
Troj/Agent-HZD
Oct 20, 2008 12:06PM PDT
- Collapse -
Troj/Agent-HZC
Oct 20, 2008 12:07PM PDT
- Collapse -
Troj/Agent-HZB
Oct 20, 2008 12:08PM PDT
- Collapse -
Troj/Dloadr-BWP
Oct 21, 2008 1:15AM PDT
- Collapse -
Troj/Bdoor-AOR
Oct 21, 2008 1:16AM PDT

Category Viruses and Spyware

Type Trojan

Troj/Bdoor-AOR is a backdoor Trojan that includes rootkit functionality and communicates with a remote server.

Troj/Bdoor-AOR installs the following file:

<System>\NetNtEx.dll

This is also detected as Troj/Bdoor-AOR.

Troj/Bdoor-AOR replaces the legitimate file <System>\drivers\beep.sys with a malicious rootkit file. The malicious beep.sys is also detected as Troj/Bdoor-AOR.

The malicious beep.sys is installed as a driver with the name 'Re1986SDT'.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojbdooraor.html?_log_from=rss

- Collapse -
Troj/Banker-ENX
Oct 21, 2008 1:17AM PDT
- Collapse -
Troj/Banker-ENW
Oct 21, 2008 1:18AM PDT
- Collapse -
Troj/Agent-HZQ
Oct 21, 2008 1:20AM PDT
- Collapse -
Troj/Agent-HZP
Oct 21, 2008 1:21AM PDT
- Collapse -
Troj/Agent-HZO
Oct 21, 2008 1:22AM PDT
- Collapse -
Troj/Agent-HZN
Oct 21, 2008 1:23AM PDT
- Collapse -
Troj/Agent-HZM
Oct 21, 2008 1:24AM PDT
- Collapse -
Troj/Agent-HZL
Oct 21, 2008 1:25AM PDT
- Collapse -
Web Media Player
Oct 21, 2008 1:26AM PDT
- Collapse -
Experts predict botnets will spread to mobile devices in 200
Oct 21, 2008 2:38AM PDT

Experts predict botnets will spread to mobile devices in 2009

21 October 2008

Security experts from the renowned Georgia Institute of Technology expect to see botnets spread to mobile devices in 2009. The "Emerging Cyber Threats Report for 2009" from the annual summit, attended by various research and business specialists and organised by Georgia Tech Information Security Center (GTISC), concludes that bot-driven DDoS attacks on mobile phone networks are likely to occur from next year.

More: http://www.heise-online.co.uk/security/Experts-predict-botnets-will-spread-to-mobile-devices-in-2009--/news/111763

- Collapse -
Packed.Generic.193
Oct 21, 2008 2:40AM PDT
- Collapse -
Troj/Flux-EH
Oct 21, 2008 4:27AM PDT
- Collapse -
Troj/FakeAv-FB
Oct 21, 2008 4:28AM PDT
- Collapse -
Troj/Dwnldr-HJL
Oct 21, 2008 4:29AM PDT
- Collapse -
Troj/DSpyA-Gen
Oct 21, 2008 4:30AM PDT
- Collapse -
Troj/Drop-BD
Oct 21, 2008 4:31AM PDT
- Collapse -
Troj/DldB-Gen
Oct 21, 2008 4:31AM PDT
- Collapse -
Troj/Agent-HZT
Oct 21, 2008 4:33AM PDT
- Collapse -
Troj/Agent-HZR
Oct 21, 2008 4:34AM PDT
- Collapse -
Troj/Agent-HZJ
Oct 21, 2008 4:34AM PDT