Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - October 24, 2008

Oct 23, 2008 3:06PM PDT

Discussion is locked

- Collapse -
Celebrities and Politicians Running Afoul of Hackers
Oct 24, 2008 5:18AM PDT

October 24, 2008

Newsflash: Sarah Palin may no longer be the most famous victim of electronic crime. French President Nicolas Sarkozy found himself a contender for that dubious title following news reports that hackers managed to steal some money from his personal bank account.

While it is not yet clear how Sarkozy?s account information was stolen, some analysts speculate that it was not a classic phishing attack. It?s more likely that Sarkozy?s credit card information was stolen at some point in time?perhaps during one of his many trips abroad?and sold as just one of the many thousands of similarly compromised accounts. This is known as carding.

More: http://blog.trendmicro.com/

- Collapse -
Mal/PDFEx-B
Oct 24, 2008 8:05AM PDT
- Collapse -
Troj/Agent-IAD
Oct 24, 2008 8:06AM PDT

Aliases Trojan-Downloader.Win32.Agent.aknt

Category Viruses and Spyware

Type Trojan

Troj/Agent-IAD is a Trojan for the Windows platform.

When first run Troj/Agent-IAD copies itself to <Windows>\9129837.exe and creates the following file:

<Windows>\new_drv.sys

The file new_drv.sys is detected as Troj/Rootkit-DK.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojagentiad.html

- Collapse -
Troj/Agent-IAF
Oct 24, 2008 8:07AM PDT
- Collapse -
Troj/Dloadr-BWX
Oct 24, 2008 8:08AM PDT
- Collapse -
Troj/FakeAle-IV
Oct 24, 2008 8:09AM PDT
- Collapse -
W32/Huhk-C
Oct 24, 2008 8:10AM PDT
- Collapse -
W32/Rbot-GXE
Oct 24, 2008 8:11AM PDT
- Collapse -
Troj/AutoIT-AC
Oct 24, 2008 8:12AM PDT
- Collapse -
Troj/JSDownL-P
Oct 24, 2008 8:13AM PDT
- Collapse -
Troj/Meredrop-B
Oct 24, 2008 8:14AM PDT
- Collapse -
Troj/Agent-IAS
Oct 24, 2008 8:17AM PDT
- Collapse -
W32/AutoRun-MT
Oct 24, 2008 9:07AM PDT
- Collapse -
Troj/Zlob-APT
Oct 24, 2008 9:08AM PDT
- Collapse -
Troj/RKRun-Gen
Oct 24, 2008 9:09AM PDT

Category Viruses and Spyware

Type Trojan

Troj/RKRun-Gen is a family of rootkit Trojans for the Windows platform.

Members of Troj/RKRun-Gen are often dropped as the file <System>\drivers\runtime2.sys and are usually registered as a system driver service named "runtime2" with registry entries set under:

HKLM\SYSTEM\CurrentControlSet\Services\runtime2

Members of Troj/RKRun-Gen are often installed along with a file called startdrv.exe, often found in the Temp subfolder of the Windows folder.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojrkrungen.html?_log_from=rss

- Collapse -
Troj/MetaJuan-A
Oct 24, 2008 9:13AM PDT
- Collapse -
Troj/Gimmiv-A
Oct 24, 2008 9:14AM PDT
- Collapse -
Troj/FakeAV-FJ
Oct 24, 2008 9:16AM PDT

Aliases Win32.Agent.ais
TrojanDownloader:Win32/Renos.EN

Category Viruses and Spyware

Type Trojan

Troj/FakeAV-FJ is a Trojan for the Windows platform.

When installed, Troj/FakeAV-FJ presents the user with several popups warning of fictitious system and security problems.

Troj/FakeAV-FJ attempts to download additional code via HTTP from a remote server.

Troj/FakeAV-FJ alters the following registry entries:

HKLM\SOFTWARE\Mozilla\MSFOX\
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\MSFox\


http://www.sophos.com/security/analyses/viruses-and-spyware/trojfakeavfj.html?_log_from=rss

- Collapse -
Troj/FakeAv-FI
Oct 24, 2008 9:18AM PDT
- Collapse -
Troj/DwnLdr-HJN
Oct 24, 2008 9:20AM PDT
- Collapse -
Troj/Dloadr-BWY
Oct 24, 2008 9:22AM PDT
- Collapse -
Troj/Agent-IAR
Oct 24, 2008 9:23AM PDT