Archive for October, 2008

Win32/TrojanDownloader.Small.OBC

Win32/TrojanDownloader.Small.OBC was detected with the following virus:
VBS/AutoRun.AD (2), Win32/Adware.AdMedia, Win32/Adware.AntiSpySpider (2), Win32/Adware.PowerAntivirus (2)

BackDoor-DOQ

BackDoor-DOQ virus file name known as C:\Documents and Settings\[UserName]\Start Menu\Programs\startup\userinit.exe
C:\Windows\System32 \drivers\services.exe

W32.Vbac.A

W32.Vbac.A virus file known as VGod.DLL,Visible Symptoms
The hidden file VGod.DLL or VCab.dll exists in the Temporary folder.
Infected EXE and DLL files have increased in size.

W32/Socks.AF.worm

W32/Socks.AF.worm also known as SHeur.BAQW (AVG),Trojan.Spambot.3092 (DrWeb),32/Socks.af (TheHacker),W32/Socks.E.worm (Panda),Win32:Socks-AE (Avast),Worm.Socks.af (Ewido)

Win32.Worm.Socks.2

Win32.Worm.Socks.2 is a network-aware worm that attempts to replicate across the existing network(s),Threat Level: High

BackDoor.FireOn.6

BackDoor.FireOn.6 virus files commonly on the path of C:\System Volume Information\_restore{B37680B2-BA0A-4E5D-BF30- 83E44C588624} or related C:\System Volume Information\_restore path

Dropper.Agent.HHL

Dropper.Agent.HHL virus file know as zip.dll,commonly on the path as C:\WINDOWS\Installer \{9ee01140-4ce8-4ec8-ac27-ac56b5e0cd7d}

Worm/Generic.GWR

Worm/Generic.GWR spreads by emails as a message attachment and via P2P networks.Worm/Generic.GWR copies itself as scanregw.exe,

Trojan.Sockrypt.Gen

Trojan.Sockrypt.Gen virus File MD5: 0×407A8F344B57607DA49CEB991DB4972F ,Filesize: 24,064 bytes ,Trojan.Sockrypt.Gen Alias: Trojan.Sockrypt.Gen [PCTools], Trojan.Win32.Nosok.ac [Kaspersky Lab], W32.SillyP2P [Symantec], BackDoor-DOQ [McAfee]
The following Registry Keys were created:
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host
HKEY_CURRENT_USER\Software\Microsoft\Windows Script Host\Settings

AdWare.Win32.Virtumonde.alud

AdWare.Win32.Virtumonde.alud virus file known as edyehkbt.dll.AdWare.Win32.Virtumonde.alud characteristics of Vundo ,AdWare.Win32.Virtumonde.alud cause popups and advertises rogue antispyware programs. Vundo can be installed by visiting a Web site link contained in a spammed email. It is known to create a DLL file in the Windows system32 directory and inject it into system processes winlogon.exe and explorer.exe.