Thank you for being a valued part of the CNET community. As of December 1, 2020, the forums are in read-only format. In early 2021, CNET Forums will no longer be available. We are grateful for the participation and advice you have provided to one another over the years.

Thanks,

CNET Support

General discussion

VIRUS \ Spyware ALERTS - October 8, 2008

Oct 7, 2008 2:45PM PDT

Discussion is locked

- Collapse -
Troj/Dloadr-BUX
Oct 7, 2008 2:46PM PDT
- Collapse -
Troj/Dloadr-BUW
Oct 7, 2008 2:48PM PDT
- Collapse -
Troj/Dloadr-BUV
Oct 7, 2008 2:49PM PDT
- Collapse -
Troj/Dloadr-BUU
Oct 7, 2008 2:50PM PDT
- Collapse -
Troj/Dloadr-BUT
Oct 7, 2008 2:51PM PDT
- Collapse -
Troj/Bckdr-QPS
Oct 7, 2008 2:52PM PDT
- Collapse -
Troj/Bckdr-QPR
Oct 7, 2008 2:53PM PDT
- Collapse -
Troj/Bckdr-QPQ
Oct 7, 2008 2:54PM PDT
- Collapse -
Mal/GamePSW-D
Oct 7, 2008 2:55PM PDT
- Collapse -
W32/Malas-H
Oct 8, 2008 12:25AM PDT

Category Viruses and Spyware

Type Worm

W32/Malas-H is a worm for the Windows platform.

When first run W32/Malas-H copies itself to:

<Startup>\AdobeUpdate.exe
<User>\Application Data\usrinit.exe
<Temp>\systray.exe
<User>\Local Settings\startup.exe
<Common Files>\AdobeUpdate.exe
<Program Files>\XPCode\SexGame.exe
<Program Files>\XPCode\SexGameList.pif
<Program Files>\XPCode\SexScreenSaver.scr
<Root>\autoply.exe

http://www.sophos.com/security/analyses/viruses-and-spyware/w32malash.html?_log_from=rss

- Collapse -
Troj/Zlob-ALO
Oct 8, 2008 12:26AM PDT
- Collapse -
Troj/PsymeZ-Fam
Oct 8, 2008 12:27AM PDT
- Collapse -
Troj/KillAV-FA
Oct 8, 2008 12:28AM PDT
- Collapse -
Troj/FakeVir-GI
Oct 8, 2008 12:29AM PDT
- Collapse -
Troj/Dloadr-BVA
Oct 8, 2008 12:30AM PDT
- Collapse -
Troj/Dloadr-BUZ
Oct 8, 2008 12:31AM PDT
- Collapse -
Troj/Dloadr-BUY
Oct 8, 2008 12:32AM PDT
- Collapse -
Troj/Agent-HVZ
Oct 8, 2008 12:33AM PDT
- Collapse -
Troj/Agent-HVY
Oct 8, 2008 12:34AM PDT
- Collapse -
Alot Toolbar
Oct 8, 2008 12:35AM PDT
- Collapse -
Sus/BHO-L
Oct 8, 2008 12:36AM PDT
- Collapse -
Trojan.Hexzone
Oct 8, 2008 1:56AM PDT
- Collapse -
VBS/HeadTail-A
Oct 8, 2008 2:02AM PDT

Aliases Worm.VBS.Headtail.a
VBS/Nauj.A
VBS_INVADESYS.AN

Category Viruses and Spyware

Type Virus

VBS/HeadTail-A is a metamorphic Visual Basic virus.

VBS/HeadTail-A will attempt to copy itself to removable drives including the A: drive. It will copy itself as %USERNAME%.vbs where %USERNAME% is the name of the user who ran the virus.

VBS/HeadTail-A will attempt in infect HTM, HTML, HTA and ASP files.

VBS/HeadTail-A will attempt to delete MPG, RMVB, AVI and RM files.

http://www.sophos.com/security/analyses/viruses-and-spyware/vbsheadtaila.html?_log_from=rss

- Collapse -
Troj/FakeAV-EM
Oct 8, 2008 2:03AM PDT
- Collapse -
Troj/Dwnldr-HIV
Oct 8, 2008 2:04AM PDT

Category Viruses and Spyware

Type Trojan

When first run, Troj/Dwnldr-HIV copies itself to the following location:

<System>\vistaupgrade.exe

Troj/Dwnldr-HIV attempts to silently connect to an internet site.

The following registry entries are created to ensure Troj/Dwnldr-HIV is started when Windows starts:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\VistaUpgrade
C:\WINDOWS\System32\vistaupgrade.exe

Troj/Dwnldr-HIV also registers itself as a Browser Helper Object.

http://www.sophos.com/security/analyses/viruses-and-spyware/trojdwnldrhiv.html?_log_from=rss

- Collapse -
Troj/Buzus-R
Oct 8, 2008 2:05AM PDT
- Collapse -
Troj/Banker-ENR
Oct 8, 2008 2:06AM PDT
- Collapse -
Troj/Banker-ENQ
Oct 8, 2008 2:07AM PDT
- Collapse -
Troj/Agent-HWB
Oct 8, 2008 2:08AM PDT
- Collapse -
Troj/Agent-HWA
Oct 8, 2008 2:09AM PDT