Prockill-DM
This malware was reported by: Network Associates Inc
Troj/IRCBot-CX
This malware was reported by: Sophos
Troj/IRCBot-CX is a Trojan for the Windows platform.
The Trojan connects to an IRC server and awaits commands from remote attackers.
Troj/Icyfox-B
This malware was reported by: Sophos
Troj/Icyfox-B is a backdoor Trojan for ASP servers. It allows an intruduer to run arbitary scripts on the server side.
Intruders can access the backdoor through HTTP Submit traffic, and embed the script in the request.
Troj/Icyfox-B may als
Backdoor-CWX
This malware was reported by: Network Associates Inc
W32/Fasong-H
This malware was reported by: Sophos
W32/Fasong-H is a worm for the Windows platform.
W32/Fasong-H spreads via file sharing on P2P networks.
W32/Rbot-BHT
This malware was reported by: Sophos
W32/Rbot-BHT is a worm with backdoor functionality for the Windows platform.
W32/Rbot-BHT attempts to spread by copying itself to network shares protected by weak passwords.
W32/Rbot-BHT runs continuously in the background, providing a back
BackDoor-CWT
This malware was reported by: Network Associates Inc
W32/Rbot-BHZ
This malware was reported by: Sophos
W32/Rbot-BHZ is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-BHZ spreads to other network computers by exploiting common buffer
overflow vulnerabilities, including: RPC-DCOM (MS04-012), PNP (MS05-039) and
ASN.1 (MS04-007
W32/Brontok-M
This malware was reported by: Sophos
W32/Brontok-M is a worm for the Windows platform.
When first run W32/Brontok-M may copy itself to:
<User>Local SettingsApplication Datar<4 random digits>on.exe
<User>Local SettingsApplication Datacsrss.exe
<User&
Troj/Progent-P
This malware was reported by: Sophos
Troj/Progent-P is a backdoor Trojan for the Windows platform.
Troj/Progent-P includes functionality to:
- access the internet and communicate with a remote server via HTTP
- steal information and passwords from a number of games and applica
W32.Looksky.F@mm
This malware was reported by: Symantec
W32.Looksky.F@mm is a mass-mailing worm that drops additional malware on the compromised computer.
Troj/Bandler-J
This malware was reported by: Sophos
Troj/Bandler-J is an information stealing Trojan for the Windows platform.
Troj/Bandler-J includes functionality to:
-access the internet and communicate with a remote server via HTTP
-download, install and run new software
-log keypresses
MS Vulnerability MS06-001
This malware was reported by: Network Associates Inc
PWS-Boots
This malware was reported by: Network Associates Inc
Troj/Stinx-K
This malware was reported by: Sophos
Troj/Stinx-K is a backdoor Trojan for the Windows platform.
Troj/Stinx-J
This malware was reported by: Sophos
Troj/Stinx-J is a backdoor Trojan for the Windows platform.
Troj/Stinx-J allows a remote attacker to gain access and control over the computer via IRC channels.
AdClicker-DW
This malware was reported by: Network Associates Inc
BKDR_BREPLIBOT.U
This malware was reported by: Trendmicro
This backdoor application arrives on a system as an attachment to email messages manually mass-mailed by a remote attacker. The said attached file uses the file name, Transaction and Billing.exe. It may also arrive on the system either downloaded fr
W32/IRCBot-BR
This malware was reported by: Sophos
W32/IRCBot-BR is a worm and IRC backdoor Trojan for the Windows platform.
W32/IRCBot-BR spreads to other network computers by exploiting common buffer overflow vulnerabilities, including ASN.1 (MS04-007).
W32/IRCBot-BR runs continuously in
W32/Rbot-BIA
This malware was reported by: Sophos
W32/Rbot-BIA is a worm and IRC backdoor Trojan for the Windows platform.
W32/Rbot-BIA spreads to other network computers by exploiting common buffer overflow vulnerabilities, including: LSASS (MS04-011), RPC-DCOM (MS04-012), WKS (MS03-049) (
W32.Loxbot.C
This malware was reported by: Symantec
W32.Loxbot.C is a worm that opens a back door and can receive commands from a remote attacker. It lowers security settings and can spread using AOL Instant Messenger.
StartPage-HR
This malware was reported by: Network Associates Inc
Troj/Bancban-NI
This malware was reported by: Sophos
Troj/Bancban-NI is a password-stealing Trojan for the Windows platform.
Troj/Bancban-NI includes functionality to send notification messages to remote locations.
W32/Loosky-M
This malware was reported by: Sophos
W32/Loosky-M is a worm for the Windows platform.
Proxy-SysNT
This malware was reported by: Network Associates Inc
PE_HONK.A
This malware was reported by: Trendmicro
This file infector arrives on a system either downloaded from the Internet or dropped by other malware programs.
W32/HLLP.Zori.c@M
This malware was reported by: Network Associates Inc
W32/HLLP.Zori.c@M is a parasitic file infector and mailing worm that uses its own SMTP engine to send itself to the email addresses that it harvests on the infected computer. W32/HLLP.Zori.c@M is written using Borland Delphi and also conta
Troj/IRCBot-CX
This malware was reported by: Sophos
Troj/IRCBot-CX is a Trojan for the Windows platform.
The Trojan connects to an IRC server and awaits commands from remote attackers.
W32.Loxbot.D
This malware was reported by: Symantec
W32.Loxbot.D is a worm that opens a back door on the compromised computer allowing a remote attacker to issue various commands and spreads using AOL Instant Messenger. The worm also uses rootkit capabilities to hide its process in memory.
Trojan.Zlob.H
This malware was reported by: Symantec
Trojan.Zlob.H is a Trojan horse that may download and execute remote files and redirect the Internet Explorer home page and search page.
W32/Fasong-H
This malware was reported by: Sophos
W32/Fasong-H is a worm for the Windows platform.
W32/Fasong-H spreads via file sharing on P2P networks.
Troj/Zlob-CD
This malware was reported by: Sophos
Troj/Zlob-CD is a Trojan for the Windows platform.
Troj/Zlob-CD contains functionality to download further malicious code.
PE_ZORI.E
This malware was reported by: Trendmicro
PE_ZORI.E-O
This malware was reported by: Trendmicro
This mother file infector infects by prepending its virus code to all the .EXE files it finds on the affected system. The infected files are detected by Trend Micro as PE_ZORI.E.
PWS-Raven
This malware was reported by: Network Associates Inc
Generic.l
This malware was reported by: Network Associates Inc
Generic.i
This malware was reported by: Network Associates Inc
Generic.f
This malware was reported by: Network Associates Inc
Downloader-ASN
This malware was reported by: Network Associates Inc
Generic.g
This malware was reported by: Network Associates Inc
Generic.c
This malware was reported by: Network Associates Inc
Troj/Zlob-CE
This malware was reported by: Sophos
Troj/Zlob-CE is a Trojan for the Windows platform.
Troj/Zlob-CE may download further malicious code.
Troj/Progent-P
This malware was reported by: Sophos
Troj/Progent-P is a backdoor Trojan for the Windows platform.
Troj/Progent-P includes functionality to:
- access the internet and communicate with a remote server via HTTP
- steal information and passwords from a number of games and applica
Troj/Lewor-U
This malware was reported by: Sophos
Troj/Lewor-U is a Trojan for the Windows platform.
Troj/Lewor-U may attempt to terminate processes.
Troj/Lewor-U includes functionality to access the internet and communicate with a remote server via HTTP.
Troj/Bandler-J
This malware was reported by: Sophos
Troj/Bandler-J is an information stealing Trojan for the Windows platform.
Troj/Bandler-J includes functionality to:
-access the internet and communicate with a remote server via HTTP
-download, install and run new software
-log keypresses
Troj/Stinx-K
This malware was reported by: Sophos
Troj/Stinx-K is a backdoor Trojan for the Windows platform.
Dialer-258.dll
This malware was reported by: Network Associates Inc
Dialer-257
This malware was reported by: Network Associates Inc
W32/Bagle-BP
This malware was reported by: Sophos
W32/Bagle-BP is an email worm for the Windows platform.
W32/Bagle-BP does not send email to addresses containing the following:
@derewrdgrs
@eerswqe
@messagelab
@microsoft
anyone@
certific
contract@
f-secur
free-av
gold-certs@
google
icroso
Troj/Bancban-NI
This malware was reported by: Sophos
Troj/Bancban-NI is a password-stealing Trojan for the Windows platform.
Troj/Bancban-NI includes functionality to send notification messages to remote locations.
Adware-Spywarestrike
This malware was reported by: Network Associates Inc
WORM_LOCKSKY.AB
This malware was reported by: Trendmicro
This memory-resident worm propagates by attaching a copy of itself to an email message, which it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine. Since its email propagation does not require any user intervention
TROJ_BAGLE.BW
This malware was reported by: Trendmicro
A Trojan application is a malware with no capability to spread into other systems. It is usually downloaded from the Internet and installed by unsuspecting users.
WORM_MYTOB.MR
This malware was reported by: Trendmicro
This worm propagates via email, which it sends to target addresses, using its own Simple Mail Transfer Protocol (SMTP) engine.
W32/Loosky-S
This malware was reported by: Sophos
W32.Looksky.G@mm
This malware was reported by: Symantec
W32.Looksky.G@mm is a mass-mailing worm that lowers security settings, opens a back door, and drops additional malware on the compromised computer.
W32/Rbot-BJH
This malware was reported by: Sophos
Troj/Zlob-DV
This malware was reported by: Sophos
Troj/Zlob-CD
This malware was reported by: Sophos
Troj/Bancban-NM
This malware was reported by: Sophos
Troj/Bckdr-E
This malware was reported by: Sophos
W32/Zellome@M
This malware was reported by: Network Associates Inc
W32/Zellome@M is a polymorphic worm with SMTP functionality. The worm is written in Visual C and uses its own SMTP engine to send itself to the email addresses that it harvests on the infected machine.
Upon executing W32/Zellome@M:
C
MS06-001
This malware was reported by: Panda Software
Trojan.Goldun.I
This malware was reported by: Symantec
Trojan.Goldun.I is a Trojan horse program that steals passwords and bank account details and sends the information to a remote attacker. It uses rootkit techniques to hide any files and registry subkeys it creates.
Troj/Bandler-K
This malware was reported by: Sophos
Troj/Zlob-CE
This malware was reported by: Sophos
Troj/Lewor-U
This malware was reported by: Sophos
W32/Brepibot.gen
This malware was reported by: Network Associates Inc
Please see the description for W32/Brepibot for further details.
http://vil.nai.com/vil/content/v_133091.htm
Top of Page
W32/PPDoor-R
This malware was reported by: Sophos
WORM_MYTOB.NO
This malware was reported by: Trendmicro
This memory-resident worm spreads copies of itself as an attachment to an email message that it sends to target recipients using its own Simple Mail Transfer Protocol (SMTP) engine. Through this SMTP engine, it is able to easily send the said email
Mytob.LL
This malware was reported by: Computer Associates
Rector.A
This malware was reported by: Computer Associates
Description Win32/Rector.A is a trojan that displays a fake message on the desktop informing the user that their system is infected with spyware.
TROJ_WMFCRASH.C
This malware was reported by: Trendmicro
This Trojan is a .WMF file that takes advantage of an unpatched vulnerability found in Windows Picture and Fax Viewer.
TROJ_WMFCRASH.B
This malware was reported by: Trendmicro
This Trojan is a .WMF file that takes advantage of an unpatched vulnerability found in Windows Picture and Fax Viewer.
W32/Sdbot-ALZ
This malware was reported by: Sophos
W32/Bagle-BP
This malware was reported by: Sophos
Phishbank.ABP
This malware was reported by: Computer Associates
Fox
This malware was reported by: F-Secure
W32/Floppy-E
This malware was reported by: Sophos
Spymaster.A
This malware was reported by: Panda Software
Spymaster.A is a keylogger type Trojan that logs the keystrokes typed by the user, in order to obtain passwords or any other sensitive information, and monitors the accessed websites.Additionally, it can view the programs that are being run, and the file
W32/Mytob-GN
This malware was reported by: Sophos
W32/Loosky-S
This malware was reported by: Sophos
Generic PWS.u
This malware was reported by: Network Associates Inc
Mitglieder.HE
This malware was reported by: Panda Software
Mitglieder.HE is a Trojan with backdoor characteristics that opens the port 9031 and acts a proxy server. Additionally, it waits for remote control commands to carry out on the affected computer, such as download and run files, start an SMTP server, modi
Exploit-WMF.b
This malware was reported by: Network Associates Inc
Exploit-WMF.c
This malware was reported by: Network Associates Inc
Bloodhound.Exploit.57
This malware was reported by: Symantec
Bloodhound.Exploit.57 is a heuristic detection for the TNEF Decoding in Microsoft Outlook and Microsoft Exchange Remote Code Execution vulnerability, (as described in Microsoft Security Bulletin MS06-003).
MS Vulnerability MS06-003
This malware was reported by: Network Associates Inc
MS Vulnerability MS06-002
This malware was reported by: Network Associates Inc
W32/Alcra-E
This malware was reported by: Sophos
W32/Rbot-BJH
This malware was reported by: Sophos
W32/Rbot-BKA
This malware was reported by: Sophos
Troj/Zlob-DV
This malware was reported by: Sophos
Troj/Vixup-AF
This malware was reported by: Sophos
Troj/Bancban-NM
This malware was reported by: Sophos
MS06-002
This malware was reported by: Panda Software
MS06-003
This malware was reported by: Panda Software
W32/Rbot-BJW
This malware was reported by: Sophos
Troj/Bandler-K
This malware was reported by: Sophos
Troj/Bifrose-DB
This malware was reported by: Sophos