Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - October 27, 2008

Oct 26, 2008 2:52PM PDT

Discussion is locked

- Collapse -
Troj/PDFex-AD
Oct 26, 2008 2:53PM PDT
- Collapse -
Troj/OnLineG-BJ
Oct 26, 2008 2:54PM PDT

Category Viruses and Spyware

Type Trojan


Troj/OnLineG-BJ is a Trojan for the Windows platform.

When first run Troj/OnLineG-BJ copies itself to <Windows>\help\EB6C4499B05F.exe and creates the following files:

<Root>\1.hiv
<Root>\2.hiv
<Current Folder>\2.bat
<Windows>\1.bat
<Windows>\help\EB6C4499B05F.dll

The file EB6C4499B05F.dll is detected as Mal/LineDLL-B. The other files are not malicious and may be deleted.

The file EB6C4499B05F.dll is registered as a COM object and shell extension, creating registry entries under:

HKCR\CLSID\{1DBD6574-D6D0-4782-94C3-69619E719765}
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
{1DBD6574-D6D0-4782-94C3-69619E719765}


http://www.sophos.com/security/analyses/viruses-and-spyware/trojonlinegbj.html?_log_from=rss

- Collapse -
Troj/FakeVir-GS
Oct 26, 2008 2:55PM PDT
- Collapse -
Troj/DwnLdr-HJR
Oct 26, 2008 2:56PM PDT

Category Viruses and Spyware

Type Trojan

Troj/DwnLdr-HJR is a Trojan for the Windows platform.

Troj/DwnLdr-HJR includes functionality to access the internet and communicate with a remote server via HTTP.

When first run, Troj/DwnLdr-HJR creates the following file:

<System>\CbEvtSvc.exe

which is also detected as Troj/DwnLdr-HJR.

The file CbEvtSvc.exe is registered as a new system driver service named "CbEvtSvc", with a display name of "CbEvtSvc" and a startup type of automatic, so that it is started automatically during system startup. Registry entries are created under:

HKLM\SYSTEM\CurrentControlSet\Services\CbEvtSvc\

The following registry entry is changed:

HKCU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders\


http://www.sophos.com/security/analyses/viruses-and-spyware/trojdwnldrhjr.html?_log_from=rss

- Collapse -
Troj/Bckdr-QQB
Oct 26, 2008 2:57PM PDT
- Collapse -
Troj/Bancos-BEQ
Oct 26, 2008 2:58PM PDT

Category Viruses and Spyware

Type Trojan

Troj/Bancos-BEQ is a Trojan for the Windows platform.

Troj/Bancos-BEQ includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/Bancos-BEQ is installed the following files are created:

<User>\Application Data\MicrosoftGenuine.exe
<User>\Application Data\winmanager.sys
<System>\drivers\winmanager.sys
<System>\skandisk.dll

The file MicrosoftGenuine.exe and winmanager.sys are detected as Troj/Bancos-BEQ. The file skandisk.dll is not malicious and may be deleted.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojbancosbeq.html?_log_from=rss

- Collapse -
Troj/Agent-IBC
Oct 26, 2008 2:59PM PDT
- Collapse -
Troj/Agent-IBA
Oct 26, 2008 3:00PM PDT
- Collapse -
Troj/Agent-IAL
Oct 26, 2008 3:01PM PDT
- Collapse -
W32/Virut-Gen
Oct 27, 2008 1:19AM PDT
- Collapse -
Troj/Agent-HNY
Oct 27, 2008 1:21AM PDT
- Collapse -
W32/Voterai-B
Oct 27, 2008 1:22AM PDT
- Collapse -
Troj/Gimmiv-B
Oct 27, 2008 1:23AM PDT
- Collapse -
Troj/Banker-ENZ
Oct 27, 2008 1:24AM PDT
- Collapse -
Mal/PDFEx-B
Oct 27, 2008 1:25AM PDT
- Collapse -
Mal/ObfJS-BH
Oct 27, 2008 1:26AM PDT
- Collapse -
Mal/ObfJS-BF
Oct 27, 2008 1:27AM PDT
- Collapse -
Trojan:Java/Konov.A
Oct 27, 2008 1:48AM PDT

Name : Trojan:Java/Konov.A
Detection Names : Trojan-SMS.J2ME.Konov.b
Trojan:Java/Konov.A

Aliases : Troj/Konov.A (Sophos)
Trojan.Konov.A (Symantec)

Type: Trojan
Category: Malware
Platform: Java

Summary
Konov is a Java (J2ME) trojan.

Konov will work on most phones capable of executing Java programs. Once executed Konov will send SMS messages to premium rate numbers.

http://www.f-secure.com/v-descs/trojan_java_konov_a.shtml

- Collapse -
W32.Slugin.A
Oct 27, 2008 2:26AM PDT
- Collapse -
W32.Slugin.A!inf
Oct 27, 2008 2:27AM PDT
- Collapse -
W32/Bagle-TZ
Oct 27, 2008 2:48AM PDT
- Collapse -
W32/Bagle-TY
Oct 27, 2008 2:49AM PDT

Aliases W32/Bagle.gen
Email-Worm.Win32.Bagle.of

Category Viruses and Spyware

Type Worm

W32/Bagle-TY is a worm for the Windows platform.

When first run W32/Bagle-TY copies itself to:

<System>\mdelk.exe
<System>\wintems.exe

W32/Bagle-TY sets the following registry entries, disabling the automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4

Note: disabling autostart for the SharedAccess service deactivates the Microsoft Internet Connection Firewall (ICF).

http://www.sophos.com/security/analyses/viruses-and-spyware/w32baglety.html?_log_from=rss

- Collapse -
W32/Bagle-TX
Oct 27, 2008 2:52AM PDT

Aliases W32/Bagle.gen
Win32/Bagle.PJ worm
Email-Worm.Win32.Bagle.of

Category Viruses and Spyware

Type Worm

W32/Bagle-TX is a worm for the Windows platform.

When first run W32/Bagle-TX copies itself to:

<System>\mdelk.exe
<System>\wintems.exe

W32/Bagle-TX sets the following registry entries, disabling the automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\SharedAccess
Start
4

Note: disabling autostart for the SharedAccess service deactivates the Microsoft Internet Connection Firewall (ICF).

http://www.sophos.com/security/analyses/viruses-and-spyware/w32bagletx.html?_log_from=rss

- Collapse -
Troj/Zlob-APW
Oct 27, 2008 2:53AM PDT
- Collapse -
Troj/Tiotua-U
Oct 27, 2008 2:54AM PDT

Category Viruses and Spyware

Type Trojan

Troj/Tiotua-U is a Trojan for the Windows platform.

Troj/Tiotua-U includes functionality to access the internet and communicate with a remote server via HTTP.

When first run Troj/Tiotua-U copies itself to:

<Windows>\chrome.exe
<System>\chrome.exe

and creates the file <System>\autorun.ini.

The following registry entry is created to run chrome.exe on startup:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Yahoo Messengger
<System>\chrome.exe

http://www.sophos.com/security/analyses/viruses-and-spyware/trojtiotuau.html?_log_from=rss

- Collapse -
Troj/Psyme-KJ
Oct 27, 2008 2:55AM PDT
- Collapse -
Troj/Dloadr-BXA
Oct 27, 2008 2:56AM PDT
- Collapse -
Troj/Agent-IBH
Oct 27, 2008 2:57AM PDT
- Collapse -
Troj/Agent-IBG
Oct 27, 2008 2:58AM PDT
- Collapse -
Troj/Agent-IBF
Oct 27, 2008 2:59AM PDT