Archive for October, 2008

W32/Malware.EDXJ

W32/Malware.EDXJ is a warning of an application file with suspicious code inside. When a file is suspected it means that the heuristic scanner found virus-like or trojan-like activity/source code/techniques in the analyzed file.

Virus.Win32.Banload.FQJ

Virus.Win32.Banload.FQJ virus File Name : Project1.exe Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit

W32/Trymedia.A.gen!Eldorado

W32/Trymedia.A.gen!Eldorado virus file know as CountryJusticeRevRednecks-dm.exe
File Size : 142784 byte ,File Type : PE32 executable for MS Windows (GUI) Intel 80386 32-bit

Win32:Small-MHL

Win32:Small-MHL virus file named as LSPRN.EXE,virus File size: 16896 bytes, and also known as Win-Trojan/Xema.16896.M
W32/Heuristic-257!Eldorado

W32/Virut.BH

W32/Virut.BH is a virus that infects executable files and opens a back door on the compromised computer. Once W32/Virut.BH executed, the virus creates the mutex named “VT_3″ so that only one instance of the threat runs on the compromised computer.

Trojan.Zlob.LFD

Trojan.Zlob.LFD is Trojan.Zlob trojan,Trojan.Zlob.LFD is a back door Trojan that allows the remote attacker to perform various malicious actions on the compromised computer.Once Trojan.Zlob.LFD installed, it displays popup ads with appearance similar to real

Win32/TrojanDownloader.FakeAlert.LW

Win32/TrojanDownloader.FakeAlert.LW is a kind of win32 trojan downloader.it was detected at the same time with the following virus:Win32/Adware.PCProtectionCenter (6),

Trojan.Win32.Inject.ivx

Trojan.Win32.Inject.ivx is a Trojan for the Windows platform.Trojan.Win32.Inject.ivx as a trojan, also known as a trojan horse, is simply a program that pretends to be something else.Trojan.Win32.Inject.ivx PN attempts to load the following DLL into the explorer.exe process:

Trojan.FakeAlert.AJF

Trojan.FakeAlert.AJF will hijack the desktop background with an image alerting the user that their computer system has been infected with spyware. Trojan.FakeAlert.AJF also changes some settings of windows which include:- disabling permissions for the user to change the background image and setting the active desktop to ’show web content’.

Trojan.DownLoader.50219

Trojan.DownLoader.50219 virus file yenomk.exe and it has 4 dll imports: KERNEL32.DLL: LoadLibraryA, GetProcAddress, VirtualProtect, VirtualAlloc, VirtualFree, ExitProcess
advapi32.dll: RegOpenKeyW, comctl32.dll: MenuHelp, user32.dll: GetDC