W32/Sdbot-AGD
This malware was reported by: Sophos
W32/Sdbot-AGD is a worm and IRC backdoor Trojan for the Windows platform.
W32/Sdbot-AGD spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: RPC-DCOM (MS04-012), WKS (MS03-049) (CAN-2003-0812)
Adware-AdBlock
This malware was reported by: Network Associates Inc
WStudio
This malware was reported by: Network Associates Inc
Troj/Dloadr-ABQ
This malware was reported by: Sophos
Troj/Dloadr-ABQ is a Trojan for the Windows platform.
Troj/Dloadr-ABQ includes functionality to download, install and run new software.
W32/Agobot-UJ
This malware was reported by: Sophos
W32/Agobot-UJ is a worm and IRC backdoor Trojan for the Windows platform.
W32/Agobot-UJ spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: RPC-DCOM (MS04-012), WKS (MS03-049) (CAN-2003-0812)
W32/Korgo.worm.ab
This malware was reported by: Network Associates Inc
This self-executing worm spreads by exploiting a Microsoft Windows vulnerability:MS04-011 vulnerability (CAN-2003-0533)http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx
The worm spreads with a random filename and acts
Bootton.D
This malware was reported by: F-Secure
Bootton.D is a SIS file trojan that is quite similar to SymbOS/Bootton.A
Symbian trojan.
Bootton.D contains files from Skulls.A, Skulls.D and Bootton.A, Doomboot.A
and drops Doomboot.A and Cabir.G on the device.
Like Bootton.A Bootton.D replaces sy
Cardtrap.N
This malware was reported by: F-Secure
Cardtrap.N is a minor variation of Cardtrap.M.
Cardtrap.N is Symbian SIS file trojan that disables several Symbian built in applications, tries to damage
several anti-virus applications, and installs several Windows viruses worms and trojans to memo
WORM_MYTOB.LC
This malware was reported by: Trendmicro
Unlike most MYTOB variants, this memory-resident worm spreads copies of itself by sending out email messages that contain a link, which when clicked downloads a copy of itself onto target systems. It uses its own Simple Mail Transfer Protocol (SMTP)
BackDoor-BAC.gen.d
This malware was reported by: Network Associates Inc
SYMBOS_CABIR.L
This malware was reported by: Trendmicro
SYMBOS_SKULLS.R
This malware was reported by: Trendmicro
SYMBOS_CARDTRP.D
This malware was reported by: Trendmicro
This Symbian malware affects mobile devices running on Symbian operating system with the Series 60 Platform user interface. Some of the affected phone models are the following:
SYMBOS_SKULLS.T
This malware was reported by: Trendmicro
This Symbian malware propagates by sending copies of itself to other mobile devices via Bluetooth. It affects mobile devices running the Symbian operating system with the Series 60 Platform user interface.
WmaDownlder.B
This malware was reported by: Panda Software
SquareTrade
This malware was reported by: Network Associates Inc
SquareTrade.dr
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-055
This malware was reported by: Network Associates Inc
MS Vulnerability MS05-054
This malware was reported by: Network Associates Inc
SquareTrade.lnk
This malware was reported by: Network Associates Inc
Troj/Borobot-X
This malware was reported by: Sophos
Troj/Borobot-X is a Trojan for the Windows platform.
Troj/Borobot-X connects to a remote IRC server and awaits commands from attackers.
Troj/Bckdr-AWR
This malware was reported by: Sophos
Troj/Bckdr-AWR is a Trojan for the Windows platform.
Troj/Bckdr-AWR includes functionality to access the internet and communicate with a remote server via HTTP.
When first run Troj/Bckdr-AWR copies itself to <Windows>Windows.exe.
The
SymbOS.Skulls.O
This malware was reported by: Symantec
SymbOS.Skulls.O is a Trojan horsethat runs on the Symbian OS, which is used as the operating system for Nokia Series 60 cellular telephones.
SymbOS.Skulls.O disables several applications on the compromised device. It drops SymbOS.Cabir, SymbOS.Cabir.C,
Trojan.Zlob.G
This malware was reported by: Symantec
Trojan.Zlob.G is a Trojan horse that may download and execute remote files and redirect the Internet Explorer home page and search page.
SymbOS.Cardtrp.K
This malware was reported by: Symantec
W32/Sdbot-AGT
This malware was reported by: Sophos
W32/Sdbot-AGT is a network worm and IRC backdoor Trojan for the Windows
platform.
W32/Sdbot-AGT runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
Troj/Small-CAM
This malware was reported by: Sophos
Troj/Small-CAM is a Trojan for the Windows platform.
Troj/Small-CAM includes functionality to download additional files from a remote site.
Adware-Adroar.dll
This malware was reported by: Network Associates Inc
PERL_SPHP.A
This malware was reported by: Trendmicro
This PERL script exploits Web sites using the software, SimplePHPblog, which was found to have vulnerabilities in it that allowed unauthorized users to upload arbitrary files to a Web site using the said software.
SymbOS.Skulls.P
This malware was reported by: Symantec
SymbOS.Skulls.P is a Trojan horse that runs on the Symbian OS, which is used as the operating system for Nokia Series 60 cellular telephones, and disables several applications on the compromised device.
It also drops SymbOS.Skulls.O to the compromised
Bootton.D
This malware was reported by: F-Secure
SYMBOS_CARDTRP.F
This malware was reported by: Trendmicro
MS05-054
This malware was reported by: Panda Software
Troj/Dumador-ET
This malware was reported by: Sophos
Troj/Dumador-ET is a Trojan for the Windows platform.
Troj/IRCBot-AU
This malware was reported by: Sophos
Troj/IRCBot-AU is an IRC Trojan with backdoor functionality.
TROJ_HANLO.J
This malware was reported by: Trendmicro
SYMBOS_CARDTRP.G
This malware was reported by: Trendmicro
This Symbian malware may be downloaded from certain sites or received via Bluetooth. It drops the following malware:
MS05-055
This malware was reported by: Panda Software
Adware-GogoTools
This malware was reported by: Network Associates Inc
SYMBOS_CARDTRP.H
This malware was reported by: Trendmicro
This Symbian malware may be downloaded from certain sites or received via Bluetooth. It drops the following malware:
SYMBOS_CARDTRP.I
This malware was reported by: Trendmicro
Adware-MetaSearch.dr
This malware was reported by: Network Associates Inc
Adware-HMToolbar.dr
This malware was reported by: Network Associates Inc
ELF_SMALL.AYY
This malware was reported by: Trendmicro
This Unix-based Trojan takes advantage of the directory-traversal vulnerability discussed in this article.
ELF_SMALL.AYW
This malware was reported by: Trendmicro
This Unix-based Trojan takes advantage of the directory-traversal vulnerability discussed in this article.
Troj/Mainzz-F
This malware was reported by: Sophos
Troj/Mainzz-F is a Trojan DLL that provides malicious functionality to another worm or Trojan.
Troj/Mainzz-F contains functionality to exploit the LSASS (MS04-011) vulnerability and may be used by a worm to spread to remote network shares wi
Troj/Fasong-B
This malware was reported by: Sophos
Troj/Fasong-B is a Trojan for the Windows platform.
Downloader-AGR
This malware was reported by: Network Associates Inc
Downloader-ARD
This malware was reported by: Network Associates Inc
WORM_COMBRA.N
This malware was reported by: Trendmicro
W32/Rbot-BCC
This malware was reported by: Sophos
W32/Rbot-BCC is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-BCC runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channe
W32/Rbot-BBB
This malware was reported by: Sophos
W32/Rbot-BBB is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-BBB runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channe
Troj/Stinx-M
This malware was reported by: Sophos
W32/Rbot-AOH
This malware was reported by: Sophos
W32/Rbot-AOH is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-AOH spreads:
- to other network computers by exploiting common buffer overflow vulnerabilites, including: RPC-DCOM (MS04-012), PNP (MS05-039) and ASN.1 (MS04
Troj/BankDl-Z
This malware was reported by: Sophos
Troj/BankDl-Z is a downloading Trojan for the Windows platform.
Troj/VBbot-I
This malware was reported by: Sophos
Troj/VBbot-I is a backdoor Trojan for the Windows platform that allows access to the infected computer via an IRC channel.
Troj/Dloadr-ABQ
This malware was reported by: Sophos
Troj/Dloadr-ABQ is a Trojan for the Windows platform.
Troj/Dloadr-ABQ includes functionality to download, install and run new software.
Trojan.Oxtic
This malware was reported by: Symantec
Trojan.Oxtic is a Trojan horse that performs random nuisance actions on the compromised computer. The Trojan also disables the Task Manager and the Registry Editor.
Adware-HMToolbar.dll
This malware was reported by: Network Associates Inc
Keylog-AllinOne
This malware was reported by: Network Associates Inc
Troj/Bancban-LZ
This malware was reported by: Sophos
Troj/Bancban-LZ is a Trojan for the Windows platform.
Troj/Bancban-LZ includes functionality to send notification messages to remote locations.
Troj/Borobot-X
This malware was reported by: Sophos
Troj/Borobot-X is a Trojan for the Windows platform.
Troj/Borobot-X connects to a remote IRC server and awaits commands from attackers.
Banbra.BOK
This malware was reported by: Panda Software
Banbra.BOK is a password stealer type Trojan that monitors if the user acesses websites belonging to certain banking entities, in order to obtain passwords. Then, it sends the data it has gathered to a certain email address.Banbra.BOK spreads via instant
Keylog-Ardamax
This malware was reported by: Network Associates Inc
PWSteal.MSNBancos
This malware was reported by: Symantec
PWSteal.MSNBancos is a Trojan horse that monitors user activity on financial Web sites.
SymbOS.Doomboot.R
This malware was reported by: Symantec
SymbOS.Doomboot.R is a Trojan horse that installs corrupt files on the compromised device preventing it from restarting correctly. The Trojan runs on the Symbian OS, which is the operating system for Nokia Series 60 cellular telephones.
The Trojan rep
SymbOS.Skulls.Q
This malware was reported by: Symantec
SymbOS.Skulls.Q is a Trojan horse that runs on the Symbian OS, which is used as the operating system for Nokia Series 60 cellular telephones. It disables some applications installed on the device and drops threats onto the compromised device.
The Troj
ELF_CODORDA.A
This malware was reported by: Trendmicro
This Unix-based backdoor program allows a remote malicious user to specify a remote IP address as well as a TCP port to connect to.
Adware-SpotOn
This malware was reported by: Network Associates Inc
SymbOS.Cabir.W
This malware was reported by: Symantec
SymbOS.Cabir.W is minor variant of SymbOS.Cabir. This worm also spreads through Bluetooth-enabled devices running the Symbian OS, which is used as the operating system for Nokia Series 60 cellular telephones.
The worm arrives on a Bluetooth-enabled de
Adware-Shorty
This malware was reported by: Network Associates Inc
JS_MHTREDIR.ET
This malware was reported by: Trendmicro
TROJ_BAGLE.CD
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this worm, refer to the Behavior Diagram shown below.
W32/Bagle.gen!D1511020
This malware was reported by: Network Associates Inc
Troj/BagleDl-AN
This malware was reported by: Sophos
Troj/BagleDl-AN is a Trojan for the Windows platform.
When first run, Troj/BagleDl-AN opens a graphics file named ntimage.gif with the default image viewer.
The latest Bagle Trojan horse open a graphics file when first run.
Troj/B
W32/Sdbot-AGT
This malware was reported by: Sophos
W32/Sdbot-AGT is a network worm and IRC backdoor Trojan for the Windows
platform.
W32/Sdbot-AGT runs continuously in the background, providing a backdoor server
which allows a remote intruder to gain access and control over the computer via
Trojan.Lodear.E
This malware was reported by: Symantec
Trojan.Lodear.E is a Trojan horse that attempts to download remote files.
Bancos.LU
This malware was reported by: Panda Software
Bancos.LU is a password stealer type Trojan with backdoor characteristics that monitors the accessed web addresses that contain certain text strings, which belong to banking entities.Then, it attemtps to redirect such websites to a certain web server, wh
SymbOS.Cardtrp.I
This malware was reported by: Symantec
W32.Beagle.CX@mm
This malware was reported by: Symantec
W32.Beagle.CX@mm is a mass-mailing worm that uses its own SMTP engine to send out copies of another threat, Trojan.Lodear.E. The worm also opens a back door on the compromised computer using TCP port 80 and lowers security settings.
Bagle.FU
This malware was reported by: Panda Software
Bagle.FU is a worm that sends out an email message that contains the Trojan detected as Mitglieder.GK as an attached file, which has a ZIP extension. It also ends some processes that belong to previous variants of Bagle, and it attempts to download a fil
Trojan.Lodear.F
This malware was reported by: Symantec
Trojan.Lodear.F is a Trojan horse that attempts to download remote files.
Troj/BagleDl-AO
This malware was reported by: Sophos
Troj/BagleDl-AO is a Trojan for the Windows platform.
When first run, Troj/BagleDl-AO opens a graphics file named ntimage.gif with the default image viewer.
The latest Bagle Trojan horse open a graphics file when first run.
Troj/Dumador-ET
This malware was reported by: Sophos
Troj/Dumador-ET is a Trojan for the Windows platform.
Glieder.CK
This malware was reported by: Computer Associates
Description Win32.Glieder.CK is a trojan that downloads and executes arbitrary files from a long, hardcoded list of particular URLs. It has been mass-mailed as a 9,9
Glieder.CL
This malware was reported by: Computer Associates
Description Win32.Glieder.CL is a trojan that downloads and executes arbitrary files from a long, hardcoded list of particular URLs. It has been mass-mailed as a 9,7
WORM_BAGLE.CD
This malware was reported by: Trendmicro
Downloader-ASE
This malware was reported by: Network Associates Inc
W32/Bagle-AX
This malware was reported by: Sophos
W32/Bagle-AX is a mass-mailing worm for the Windows platform.
W32/Bagle-AX sends a ZIP file as an email attachment. The ZIP file contains an executable detected as Troj/BagleDl-AO.
Once installed, this executable attempts to download furthe
Troj/Mainzz-F
This malware was reported by: Sophos
Troj/Mainzz-F is a Trojan DLL that provides malicious functionality to another worm or Trojan.
Troj/Mainzz-F contains functionality to exploit the LSASS (MS04-011) vulnerability and may be used by a worm to spread to remote network shares wi
W32.Dasher.B
This malware was reported by: Symantec
W32.Dasher.B is a worm that exploits the Microsoft Windows Distributed Transaction Coordinator Remote Exploit (as described in Microsoft Security Bulletin MS05-051) on TCP port 1025.
W32.Dasher.A
This malware was reported by: Symantec
W32.Dasher.A is a worm that exploits the Microsoft Windows Distributed Transaction Coordinator Remote Exploit (as described in Microsoft Security Bulletin MS05-051) on TCP port 1025.
The worm arrives as a self-extract RAR file.
Adware-Sipspi
This malware was reported by: Network Associates Inc
Elite
This malware was reported by: Panda Software
Elite belongs to the category of Potentially Unwanted Programs, also known as PUPs. It logs the keystrokes typed by the user, captures screenshots and monitors the content of the clipboard, among other actions.It can also be used to view the emails that
WORM_DASHER.B
This malware was reported by: Trendmicro
This worm takes advantage of the MSDTC vulnerability in Windows. It scans a vulnerable IP address within a network and exploits the said machine when found. For more information on the said vulnerability, please refer to the following Web page:
WORM_DASHER.A
This malware was reported by: Trendmicro
WORM_LOCKSKY.O
This malware was reported by: Trendmicro
Similar to other WORM_LOCKSKY variants, this memory-resident worm propagates by sending copies of itself as an attachment to email messages.
Mitglieder.GK
This malware was reported by: Panda Software
Mitglieder.GK is a Trojan that connects every four hours to a random URL selected from a list of websites that are included in its code, in order to download and run a file, which can be of any nature, including malware.Mitglieder.GK has been massively s
Troj/Nuclear-O
This malware was reported by: Sophos
Troj/Nuclear-O is a backdoor Trojan for the Windows platform.
W32/Rbot-BCC
This malware was reported by: Sophos
W32/Rbot-BCC is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-BCC runs continuously in the background, providing a backdoor server which allows a remote intruder to gain access and control over the computer via IRC channe