Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - October 30, 2008

Oct 29, 2008 3:06PM PDT

Discussion is locked

- Collapse -
Troj/FakeVir-GV
Oct 29, 2008 3:07PM PDT
- Collapse -
Troj/Drop-BG
Oct 29, 2008 3:08PM PDT
- Collapse -
Troj/Agent-IBG
Oct 29, 2008 3:09PM PDT
- Collapse -
Troj/Dload-EE
Oct 30, 2008 12:12AM PDT

Category Viruses and Spyware

Type Trojan

Troj/Dload-EE is a backdoor Trojan which allows a remote intruder to gain access and control over the computer.

Troj/Dload-EE includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/Dload-EE is installed the following files are created:

<System>\kryo2.sys
<System>\kryostm.dll

The file kryostm.dll is detected as Mal/TinyDL-T, and the file kryo2.sys is also detected as Troj/Dload-EE.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojdloadee.html?_log_from=rss

- Collapse -
Troj/Delf-FBK
Oct 30, 2008 12:13AM PDT

Category Viruses and Spyware

Type Trojan

Troj/Delf-FBK is a Trojan for the Windows platform.

When first run Troj/Delf-FBK copies itself to <System>\wins\setup\msmgrs.exe and creates the file <Startup>\ntdll.lnk.

Troj/Delf-FBK sets the following registry entries, disabling the automatic startup of other software:

HKLM\SYSTEM\CurrentControlSet\Services\srservice
Start
4

The following registry entry is set:

HKCU\Software\Microsoft\Windows\CurrentVersion\Settings
LocationOld
<pathname of the Trojan executable>

http://www.sophos.com/security/analyses/viruses-and-spyware/trojdelffbk.html?_log_from=rss

- Collapse -
Mal/BHO-M
Oct 30, 2008 12:14AM PDT
- Collapse -
JS/Iframe-BJ
Oct 30, 2008 12:15AM PDT
- Collapse -
Troj/Zlob-AQA
Oct 30, 2008 12:16AM PDT
- Collapse -
Troj/Psyme-KJ
Oct 30, 2008 12:17AM PDT
- Collapse -
Troj/Multidr-FW
Oct 30, 2008 12:18AM PDT
- Collapse -
Troj/IRCFlood-U
Oct 30, 2008 12:18AM PDT
- Collapse -
Troj/FakeAV-FQ
Oct 30, 2008 12:19AM PDT
- Collapse -
Troj/Agent-ICH
Oct 30, 2008 12:20AM PDT
- Collapse -
Infostealer.Hibik.A
Oct 30, 2008 1:16AM PDT
- Collapse -
Infectious Invoices
Oct 30, 2008 1:19AM PDT

30 October 2008

One of the most common forms of malware distribution en mass is to spam it out with some enticing message however as administrators slowly lock down their spam rules and block questionable content the malware authors are needing to continually find new tricks?

One tried and tested method is the encrypted zip, as it prevents scanners from examining the archive content while still maintaining a perception of being legitimate. The password of course is in the message body which the recipient (often without thinking) employs with rather dire consequences.

In order to sound appealing, many of these new-wave spams relate to invoices, statements or UPS/FedEx tracking.

More: http://www.sophos.com/security/blog/2008/10/1907.html

- Collapse -
Troj/ZipCard-B
Oct 30, 2008 3:11AM PDT
- Collapse -
Troj/FakeAle-JF
Oct 30, 2008 3:12AM PDT

Category Viruses and Spyware

Type Trojan

Troj/FakeAle-JF is a Trojan for the Windows platform.

Troj/FakeAle-JF includes functionality to access the internet and communicate with a remote server via HTTP.

When Troj/FakeAle-JF is installed the following files are created:

<Current Folder>\delself.bat
<System>\brastk.exe
<System>\dllcache\beep.sys
<System>\dllcache\figaro.sys
<System>\wini10253.exe

The files beep.sys and figaro.sys are detected as Mal/FakeAle-C.

More: http://www.sophos.com/security/analyses/viruses-and-spyware/trojfakealejf.html?_log_from=rss

- Collapse -
Troj/BHO-HO
Oct 30, 2008 3:13AM PDT
- Collapse -
Troj/Bancos-BER
Oct 30, 2008 3:14AM PDT
- Collapse -
Troj/AutoIT-AD
Oct 30, 2008 3:15AM PDT
- Collapse -
Troj/Agent-ICI
Oct 30, 2008 3:16AM PDT
- Collapse -
Troj/Agent-ICG
Oct 30, 2008 3:17AM PDT
- Collapse -
Troj/Zlob-AQB
Oct 30, 2008 6:00AM PDT
- Collapse -
Troj/VB-EBK
Oct 30, 2008 6:01AM PDT
- Collapse -
Troj/Thyself-B
Oct 30, 2008 6:01AM PDT
- Collapse -
Troj/KeyGen-CQ
Oct 30, 2008 6:02AM PDT
- Collapse -
Troj/Iframe-BK
Oct 30, 2008 6:03AM PDT
- Collapse -
Troj/FakeAV-FR
Oct 30, 2008 6:04AM PDT
- Collapse -
Troj/FakeAle-JG
Oct 30, 2008 6:05AM PDT
- Collapse -
Troj/Banker-EOA
Oct 30, 2008 6:06AM PDT