Archive for August, 2008

W32/WBoy.a

W32/WBoy.a is for W32/WBoy.a infected files. Upon execution these files spawn a malicious process. The malicious programs are typically stored in following directory:
c:\windows\SYSTEMD32\XXXXX\

Trojan-Downloader.Win32.Tibs.klv

Trojan-Downloader.Win32.Tibs.klv has been dropped from the pattern file.Trojan-Downloader.Win32.Tibs.klv is a program typically installed through an exploit or some other

WORM_ALLAPLE.PF

WORM_ALLAPLE.PF propagates by dropping a copy of itself into all available network shares. It uses the login credentials of the currently logged on user to gain access to target network shares.

W32.Virut.S

W32.Virut.S is a virus for the Windows platform. W32.Virut.S spreads by infected files.
W32.Virut.S Also known as: W32/Virut.6540 (F-Secure), Virus.Win32.Virut.ai (Kaspersky), Virus:Win32/Virut.V (MS OneCare), W32.Virut.W (Symantec), PE_VIRUT.XZ (Trend), W32/Virut-S (Sophos) W32/Virut-S (Sophos), Virus:Win32/Virut.V (Microsoft)

W32/Onlinegames.2!Generic

W32/Onlinegames.2!Generic installs itself to the system by copying its file to Windows folder. It also creates a startup key value in the Registry for the copied file.,After installation the trojan locates the Explorer.exe process

Win32:Virut-C

Win32:Virut-C code is executed, it infects memory and Windows executable files which is formed PE(Portable Executable) , access the particular site by 65520 port and download Trojan or other malicious code.

Trojan-Downloader.Win32.Banload.ugf

Trojan-Downloader.Win32.Banload.ugf virus file locate in C:\Program Files\uTorrent\uTorrent.exe, uTorrent.exe is a fake program,just delete it will be ok.

Trojan-Downloader.Sin32.Hmir.koq

Trojan-Downloader.Sin32.Hmir.koq is false positive and it has been sorted .

Trojan.win32.monder.ggc

Trojan.win32.monder.ggc is a highly intrusive adware program that opens pop-up advertisements on the desktop. Trojan.win32.monder.ggc is also known to download and install additional unwanted software.

Trojan-Dropper.Win32.Small.bva

Trojan-Dropper.Win32.Small.bva is a trojan progarm.The trojan file has a name called i1[1].exe, C:\WINDOWS\system32\~.exe is also Trojan-Dropper.Win32.Small.bva virus file.