W32.Beagle.CK@mm
This malware was reported by: Symantec
Bagle.CT
This malware was reported by: Computer Associates
Description Win32.Bagle.CT is a worm that spreads via e-mail and peer-to-peer file sharing. It has been distributed as a 21,392-byte, FSG-packed, Win32 executable.
Bagle.CU
This malware was reported by: Computer Associates
Description Win32.Bagle.CU is a worm that spreads via e-mail and peer-to-peer file sharing networks. It has been distributed as a 21,232-byte, FSG-packed, Win32 exec
W32.Erkez.G@mm
This malware was reported by: Symantec
W32.Erkez.G@mm is a mass-mailing worm that sends itself to email addresses gathered from the compromised computer.
Downloader-AFW
This malware was reported by: Network Associates Inc
Downloader-AFP
This malware was reported by: Network Associates Inc
Adware-GotSmiley
This malware was reported by: Network Associates Inc
Downloader-UP
This malware was reported by: Network Associates Inc
Downloader-UP.dll
This malware was reported by: Network Associates Inc
Sober.S.dr1
This malware was reported by: F-Secure
On October 6th, 2005 there appeared another dropper for Sober.S worm.
This dropper drops exactly the same Sober.S variant that started to
spread early in the morning on October 6th. When the dropper is run,
it shows a messagebox as a decoy:
The des
WORM_MYTOB.KZ
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this worm, refer to the Behavior Diagram shown below.
BackDoor-IQ
This malware was reported by: Network Associates Inc
TROJ_AGENT.ABT
This malware was reported by: Trendmicro
This Trojan attempts to download and execute a file from a specific Web site before terminating itself. Trend Micro detects the file it attempts to download as of this writing as WORM_MYTOB.GEN.
TROJ_PSPBRICK.A
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Behavior Diagram shown below.
Downloader.FHO
This malware was reported by: Panda Software
Downloader.FHO is a Trojan that downloads from a certain web page another Trojan detected as Rivarts.A to the affected computer.Additionally, Downloader.FHO is able to update itself by connecting to the Internet.Downloader.FHO does not spread a
Rivarts.A
This malware was reported by: Panda Software
Rivarts.A is a Trojan that logs the keystrokes entered by the user, blocks web addresses and stores the certificates used in the affected computer. Then it connects to several PHP scripts hosted in different websites in order to send the data it has gath
WORM_MYTOB.LA
This malware was reported by: Trendmicro
Similar to other MYTOB variants, this memory-resident worm spreads copies of itself as an attachment to an email message that it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine, hence, this worm does not need oth
W32.Beagle.CL@mm
This malware was reported by: Symantec
Adware-Mirar
This malware was reported by: Network Associates Inc
W32.Mytob.KE@mm
This malware was reported by: Symantec
PERL_SHELLBOT.P
This malware was reported by: Trendmicro
This memory-resident PERL script malware connects to the Internet Relay Chat (IRC) server, eu.undernet.org using TCP port 6667. Once a connection is established, it joins the IRC channel #NewLuxor, where it listens for certain commands from a remote
W32.Toxbot.AL
This malware was reported by: Symantec
SymbOS.Cardtrp.C
This malware was reported by: Symantec
SymbOS.Cardtrp.C is a Trojan horse program that runs on the Symbian operating system, which is used in Nokia Series 60 cellular telephones. It installs SymbOS.Mabir, SymbOS.Cabir.B, SymbOS.Lasco.A, SymbOS.Commwarrior.B, and disables several application
SymbOS.Skulls.N
This malware was reported by: Symantec
SymbOS.Skulls.N is a Trojan horse that affects Symbian series 60 phones and disables several applications on the compromised device.
QLowZones-26.bat
This malware was reported by: Network Associates Inc
Generic StartPage.g
This malware was reported by: Network Associates Inc
WORM_SPYBOT.AJX
This malware was reported by: Trendmicro
This memory-resident worm propagates through network shares by dropping a copy of itself into specific shared folders. If these folders are password-protected, this worm uses a list of user names and passwords to gain access.
WORM_MYTOB.LD
This malware was reported by: Trendmicro
This worm arrives as an attachment to an email message that poses as an account notification. The email disguise aims to trick users into downloading and executing the malicious attachment.
WORM_MYTOB.LF
This malware was reported by: Trendmicro
This worm arrives as an attachment to certain email messages. The email message usually poses as an account notification in order to trick a user into downloading and executing the attachment. This worm uses its own Simple Mail Transfer Protocol (SM
Zafi.G
This malware was reported by: F-Secure
A new variant of Zafi worm - Zafi.F is spreading. While the
original Zafi.A uses only Hungarian, the Zafi.F spreads in
email in English, Italian, Spanish, Russian, Swedish and
several other languages.
The worm sends itself in infected messages attach
Adware-KlikSearch
This malware was reported by: Network Associates Inc
Zafi.F
This malware was reported by: F-Secure
A new variant of Zafi worm - Zafi.F is spreading. While the
original Zafi.A uses only Hungarian, the Zafi.F spreads in
email in English, Italian, Spanish, Russian, Swedish and
several other languages.
The worm sends itself in infected messages attach
Zafi.G
This malware was reported by: F-Secure
For more information about this Zafi variant, see description of
Zafi.F at:
http://www.f-secure.com/v-descs/zafi_f.shtml
Multidropper.AXY
This malware was reported by: Panda Software
Multidropper.AXY is a Trojan that drops on the affected computer the Trojan detected as Ranky.DH and the worm detected as Sdbot.BWJ.Multidropper.AXY is a self-extracting file, that is, a compressed file with an embedded executable to decompress itself.Mu
W32/Zafi.f@MM
This malware was reported by: Network Associates Inc
This new variant contains the following characteristics:
contains its own SMTP engine to construct outgoing messages
spoofs the From: address
harvests target email addresses from the victim machine
outgoing email message bod
Backdoor.Nibu.O
This malware was reported by: Symantec
Backdoor.Nibu.O is a Trojan horse that opens a back door on a compromised computer. It also runs a keylogger and sends the information it gathers to a predetermined email address.
Downloader.FFD
This malware was reported by: Panda Software
Trojan.DSBrick.A
This malware was reported by: Symantec
Trojan.DSBrick.A is a Trojan horse that overwrites critical portions of memory on Nintendo DS portable devices, preventing the device from operating correctly.
BKDR_VIPGSM.C
This malware was reported by: Trendmicro
This memory-resident backdoor program may arrive on a system as a downloaded file of other malware, such as TROJ_AGENT.ABT.
Trojan.DSBrick.B
This malware was reported by: Symantec
Trojan.DSBrick.B is a Trojan horse that overwrites critical portions of memory on Nintendo DS portable devices, preventing the device from operating correctly.
Adware-PalToolbar
This malware was reported by: Network Associates Inc
TROJ_HARBAG.B
This malware was reported by: Trendmicro
This memory-resident Trojan arrives on an affected system as
WORM_MYTOB.LB
This malware was reported by: Trendmicro
This memory-resident worm arrives as an attachment to email messages. The email message usually poses as an account notification in order to trick a user into downloading and executing the attachment.
PE_BOBAX.AM
This malware was reported by: Trendmicro
This memory-resident virus infects all running .EXE files by appending its code to target files. These files may fail to function correctly once they have been infected with this virus.
TROJ_DSBRICK.A
This malware was reported by: Trendmicro
This malware may delete firmware on the Nintendo DS system.
WORM_ZAFI.F
This malware was reported by: Trendmicro
DSTaihen.a
This malware was reported by: Network Associates Inc
PSPBrick
This malware was reported by: Network Associates Inc
TROJ_DSBRICK.B
This malware was reported by: Trendmicro
This Trojan may delete firmware on the Nintendo DS system.
Bloodhound.Exploit.48
This malware was reported by: Symantec
Bloodhound.Exploit.48 is a heuristic detection for the Web View Script Injection Vulnerability (as described in Microsoft Security Bulletin MS05-049).
Bloodhound.Exploit.47
This malware was reported by: Symantec
Bloodhound.Exploit.47 is a heuristic detection for the Vulnerability in AVI Processing Could Allow Remote Code Execution (as described in Microsoft Security Bulletin MS05-050).
Bloodhound.Exploit.46
This malware was reported by: Symantec
Bloodhound.Exploit.46 is a heuristic detection for the Vulnerabilities in Windows Shell Could Allow Remote Code Execution (as described in Microsoft Security Bulletin MS05-049).
WORM_RONTOKBRO.D
This malware was reported by: Trendmicro
This memory-resident worm drops several copies of itself into various folder locations on the affected system. It then overwrites the file AUTOEXEC.BAT, which is located in C:, with the following string:
DSTahen.a
This malware was reported by: Network Associates Inc
Exploit-MSDDS
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-052
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-051
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-050
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-049
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-048
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-047
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-046
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-045
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-044
This malware was reported by: Network Associates Inc
WORM_RONTOKBRO.C
This malware was reported by: Trendmicro
This memory-resident worm drops several copies of itself into various folder locations on the affected system, depending on the platform of the affected user. It then overwrites the file AUTOEXEC.BAT, which is located in C:, with the following stri
Swizzor.gen
This malware was reported by: Network Associates Inc
Adware-Searchwords
This malware was reported by: Network Associates Inc
Backdoor.Graybird.R
This malware was reported by: Symantec
Backdoor.Graybird.R is a Trojan horse that hides its presence on the compromised computer and downloads remote files.
WORM_MYTOB.LH
This malware was reported by: Trendmicro
Like other WORM_MYTOB variants, this memory-resident worm spreads by attaching a copy of itself to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.
W32.Mytob.KM@mm
This malware was reported by: Symantec
W32.Mytob.KM@mm is a mass-mailing worm that opens a back door and lowers security settings on the compromised computer.
Note: Virus definitions dated prior to October 12, 2005 detect this risk as W32.Mytob@mm.
WORM_KELVIR.CL
This malware was reported by: Trendmicro
Similar to most WORM_KELVIR variants, this memory-resident worm propagates via the instant messaging application MSN Messenger. It sends an instant message to all the online contacts of an affected user. Users are advised to be wary of clicking link
WORM_RBOT.CLS
This malware was reported by: Trendmicro
This memory-resident worm arrives as a dropped file of another malware that Trend Micro detects as WORM_KELVIR.CL. It propagates across networks by dropping a copy of itself into network shares. It forces its way into password-protected systems usin
Tahen.A
This malware was reported by: Computer Associates
Description Tahen.A is a trojan that affects the Nintendo DS. It has a destructive payload that overwrites system critical components, rendering the machine unbootab
Tahen.B
This malware was reported by: Computer Associates
Description Tahen.B is a trojan that affects the Nintendo DS. It has a destructive payload that overwrites system critical components, rendering the machine unbootab
Brick.A
This malware was reported by: Computer Associates
Description PSP/Brick.A is a trojan that affects Sony Playstation Portable devices, possibly making them unbootable.
MS05-052
This malware was reported by: Panda Software
W32/Kelvir.worm.cl
This malware was reported by: Network Associates Inc
This threat was proactively detected as W32/Kelvir.worm.gen.
This worm spreads via MSN Messenger (Note: Not the Windows Messenger service). The worm, sends the following message to contact list recipients:
"hey
its you!
http://www.y
MS05-050
This malware was reported by: Panda Software
MS05-051
This malware was reported by: Panda Software
Format.A
This malware was reported by: Panda Software
Tahen.A is a Trojan that affects Nintendo DS portable videogame consoles. It pretends to be a homebrew application for this console, but once installed, it overwrites certain areas of the firmware (software embedded in certain hardware) in the following
Format.B
This malware was reported by: Panda Software
Tahen.B is a Trojan that affects Nintendo DS portable videogame consoles. It pretends to be a homebrew application for this console, but once installed, it overwrites certain areas of the firmware (software embedded in certain hardware) in the following
WORM_MYTOB.LJ
This malware was reported by: Trendmicro
Like other WORM_MYTOB variants, this worm spreads by attaching a copy of itself to an email message that it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine.
Tahen.B
This malware was reported by: Panda Software
Tahen.B is a Trojan that affects Nintendo DS portable videogame consoles. It pretends to be a homebrew application for this console, but once installed, it overwrites certain areas of the firmware (software embedded in certain hardware) in the following
Tahen.A
This malware was reported by: Panda Software
Tahen.A is a Trojan that affects Nintendo DS portable videogame consoles. It pretends to be a homebrew application for this console, but once installed, it overwrites certain areas of the firmware (software embedded in certain hardware) in the following
Sdbot.FHG
This malware was reported by: Panda Software
Sdbot.FHG is a worm that connects to several IRC servers in order to receive remote control commands, acting as a backdoor. It can be instructed to download and run files, obtain Protected Storage service keys, including Outlook or Internet Explorer pass
Malformed Archive
This malware was reported by: Network Associates Inc
WORM_OPANKI.AD
This malware was reported by: Trendmicro
Upon execution, this memory-resident worm drops a copy of itself as LOCKX.EXE in the Windows system folder. It also drops the file MSDIRECTX.SYS in the same folder, which Trend Micro detects as TROJ_ROOTKIT.H. This worm uses this dropped malware to
W32.Rontokbro.D@mm
This malware was reported by: Symantec
W32.Rontokbro.D@mm is a mass-mailing worm that causes system instability.
W32.Lile.A
This malware was reported by: Symantec
W32.Lile.A is a file infector worm that can spread by copying itself into local folders and mapped network drives, infecting files inside P2P transfer folders and through Instant Messaging programs. The worm also can download and execute remote files and
SilentCaller.V
This malware was reported by: Computer Associates
WORM_MYTOB.LL
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this worm, refer to the Behavior Diagram shown below.
Multidropper.AYC
This malware was reported by: Panda Software
WORM_AGOBOT.AXJ
This malware was reported by: Trendmicro
This worm propagates via network shares. It attempts to drop copies of itself in available network shared folders. It uses its own list of user names and passwords to access password-protected shares. It also generates IP addresses to drop copies o
MS05-047
This malware was reported by: Panda Software
MS05-046
This malware was reported by: Panda Software
W32.Mytob.KP@mm
This malware was reported by: Symantec
MS05-048
This malware was reported by: Panda Software
MS05-049
This malware was reported by: Panda Software
Commwarrior.C
This malware was reported by: F-Secure
Commwarrior.C is a Bluetooth and MMS worm that is similar to Commwarrior.B,
but also has significant new functionality.
The Commwarrior.C is capable of spreading over Bluetooth, MMS and MMC cards
that are inserted into an infected phone.
When Commw
SymbOS/Commwarrior.C
This malware was reported by: Network Associates Inc