MS06-010
This malware was reported by: Panda Software
Banbra.BTM
This malware was reported by: Panda Software
W32/Bagle-CO
This malware was reported by: Sophos
Troj/Dloadr-LI
This malware was reported by: Sophos
W32/Sality.o
This malware was reported by: Network Associates Inc
(Note: McAfee AVERT has observed instances of this threat, infected with W32/Sality.o, spreading in the wild)
W32/Bagle.dt@MM is a trojan downloader and mailing worm that uses its own SMTP engine to send itself to the email addresses th
W32/Bagle.dt
This malware was reported by: Network Associates Inc
TROJ_BAGLE.CW
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Behavior Diagram shown below.
W32/Sality.o
This malware was reported by: Network Associates Inc
The W32/Sality.o detection covers PE files that are partially infected with a W32/Sality variant. However, unlike other W32/Sality infections, W32/Sality.o does not contain the core W32/Sality.dll component. The entry point of such PE file
ELF_LUPPER.F
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Behavior Diagram shown below.
AdClicker-CF
This malware was reported by: Network Associates Inc
W32.Beagle.DS@mm
This malware was reported by: Symantec
W32.Beagle.DS@mm is a mass-mailing worm that uses its own SMTP engine and file sharing networks to spread. It opens a back door on the compromised computer and attempts to lower security settings. The worm also tries to download and execute remote files.
Bagle.DW
This malware was reported by: Computer Associates
Description Win32/Bagle.DW is a worm that spreads via e-mail and peer-to-peer file sharing networks. It also contains backdoor functionality that allows unauthorized
Troj/Hookie-B
This malware was reported by: Sophos
W32/Mytob-GW
This malware was reported by: Sophos
W32/Bagle.du@MM
This malware was reported by: Network Associates Inc
Note:
McAfee AVERT has observed instances of this threat, infected with W32/Sality.o, spreading in the wild
W32/Bagle.du@MM is a trojan downloader and mailing worm that uses its own SMTP engine to send itself to the email addresses that
Adware-Zeno
This malware was reported by: Network Associates Inc
W32/Bagle.dv.dldr
This malware was reported by: Network Associates Inc
OSX/Leap-A
This malware was reported by: Sophos
Troj/Spammit-A
This malware was reported by: Sophos
OSX/Leap
This malware was reported by: Network Associates Inc
-- Update:
February 16, 2006 --The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://www.theregister.co.uk/2006/02/16/mac_os-x_virus/
--
OSX/Leap is an instant messaging worm propagati
OSX.Leap.A
This malware was reported by: Symantec
OSX.Leap.A is a worm that targets installs of Macintosh OS X and spreads via iChat Instant Messenger program.
Note: It infects files on the Macintosh OS X version 10.4. The worm will execute on Intel Macs, but cannot spread to other systems from these
MS06-009
This malware was reported by: Panda Software
IRCBot.SS
This malware was reported by: Panda Software
 IRCBot.SS is a backdoor that connects to several IRC servers in order to receive remote control commands. It can be instructed to download files, send information about the bot version and the operating system of the affected computer, etc.Additionally,
Leap.A
This malware was reported by: F-Secure
Adware-SpyFalcon
This malware was reported by: Network Associates Inc
W32/Sdbot-DJA
This malware was reported by: Sophos
Troj/Teros-A
This malware was reported by: Sophos
Exploit-MS06-006.gen
This malware was reported by: Network Associates Inc
Linux.Backdoor.Kaiten
This malware was reported by: Symantec
Linux.Backdoor.Kaiten is a Trojan horse that opens a back door on the compromised computer.
Leap.A
This malware was reported by: Computer Associates
OSX/Leap!tgz
This malware was reported by: Network Associates Inc
This is a detection for the packed file in the tgz
format. For further information on this detection, please see the full decription for the OSX/Leap at:
http://vil.nai.com/vil/content/v_138578.htm
Top of Page
OSX_LEAP.A
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Behavior Diagram shown below.
Troj/BagleDl-BL
This malware was reported by: Sophos
Troj/Bancban-OE
This malware was reported by: Sophos
Adware-Sherv
This malware was reported by: Network Associates Inc
Adware-ZSearch.dr
This malware was reported by: Network Associates Inc
VBS/Babe
This malware was reported by: Network Associates Inc
This is a destructive virus written in VBScript. It requires Windows Scripting Host in order to execute.
The virus will also infect all .HTML files in the c: drive.
If the day is 15 or 30 of any month, the virus will overwrite c:au
VBS/Bagies
This malware was reported by: Network Associates Inc
Keylog-GSmon
This malware was reported by: Network Associates Inc
Keylog-Kidlogger
This malware was reported by: Network Associates Inc
KeySpy-Dks
This malware was reported by: Network Associates Inc
Adware-Zeno.dldr
This malware was reported by: Network Associates Inc
Oomp.A
This malware was reported by: Panda Software
 Oomp.A is a worm that only affects computers with the operating system Mac OS X installed.It replaces several system applications with a copy of itself that includes the original legitimate program. When the replaced file is executed, the worm is run an
Troj/Dropper-EH
This malware was reported by: Sophos
Troj/BagleDl-BI
This malware was reported by: Sophos
Inqtana.A
This malware was reported by: F-Secure
Troj/BankSnif-G
This malware was reported by: Sophos
TROJ_DROPPER.AKD
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Behavior Diagram shown below.
OSX.Inqtana.A
This malware was reported by: Symantec
OSX.Inqtana.A is a proof of concept worm that runs on Macintosh OS X and spreads by exploiting a the Apple Mac OS X BlueTooth Directory Traversal Vulnerability (as described in Bugtraq ID 13491).
Adware-WordsText
This malware was reported by: Network Associates Inc
W32/Bagle.gen!Sality
This malware was reported by: Network Associates Inc
This is a generic detection of files that infected with both W32/Bagle.gen as well as W32/Sality. W32/Bagle is a mass-mailing worm, while W32/Sality is a parasitic file infecting virus. Most of these Sality infections are not viable, how
OSX_INQTANA.A
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this Trojan, refer to the Behavior Diagram shown below.
W32/Bagle-CU
This malware was reported by: Sophos
Troj/Dloadr-LM
This malware was reported by: Sophos
W32.Alcra.F
This malware was reported by: Symantec
W32.Alcra.F is a worm that attempts to propagate through various file-share networks accessible with BearShare, LimeWire, Morpheus and
Shareaza applications. It also attempts to disable several programs on the compromised computer and drops a W32.Spybot
OSX/Inqtana-A
This malware was reported by: Sophos
W32/Sality-I
This malware was reported by: Sophos
PWSteal.Metafisher
This malware was reported by: Symantec
PWSteal.Metafisher is a Trojan horse that exploits the Microsoft Windows Graphics Rendering Engine WMF Format Unspecified Code Execution Vulnerability (as described in Microsoft Security Bulletin MS06-001) to download remote files. The Trojan also send
Bloodhound.Exploit.59
This malware was reported by: Symantec
Bloodhound.Exploit.59 is a heuristic detection for the Vulnerability in Windows Media Player Could Allow Remote Code Execution (described in Microsoft Security Bulletin MS06-005).
Troj/Bancos-PZ
This malware was reported by: Sophos
W32/Bagle-CO
This malware was reported by: Sophos
OSX/Inqtana.a
This malware was reported by: Network Associates Inc
-- Update February 20, 2006 --
The risk assessment of this threat has been updated to Low-Profiled due to media attention at:
http://news.com.com/Bluetooth+worm+targets+Mac+OS+OSXinqtana.html
For an Extra.Dat file for this threa
PERL_SHELLBOT.AI
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.
ELF_MARE.C
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this malware, refer to the Behavior Diagram shown below.
PERL_MARE.C
This malware was reported by: Trendmicro
Generic StartPage.b
This malware was reported by: Network Associates Inc
Generic StartPage.l
This malware was reported by: Network Associates Inc
StartPage-IZ
This malware was reported by: Network Associates Inc
W32.Beagle.DU
This malware was reported by: Symantec
W32.Beagle.DU is a Trojan that drops Trojan.Lodav.A and lowers security settings on the compromised computer.
Troj/Bdoor-QD
This malware was reported by: Sophos
Troj/Hookie-B
This malware was reported by: Sophos
Linux.Plupii.C
This malware was reported by: Symantec
Linux.Plupii.C is a worm with back door capabilities that spreads by exploiting vulnerabilities.
W32/Pate.a.dll
This malware was reported by: Network Associates Inc
This is an encrypted parasitic file-infecting virus and network aware worm. It appends PE EXE and SCR files in the Windows directory and subdirectories on the local system, as well as on any accessible network share. The virus creates an a
W32/Maslan-I
This malware was reported by: Sophos
OSX/Leap-A
This malware was reported by: Sophos
Alcan.I
This malware was reported by: Computer Associates
Description Win32/Alcan.I is a worm that spreads via peer-to-peer file sharing networks. It has been distributed as a 210,432-byte, UPX-packed, Win32 executable.
Bagdrop.D
This malware was reported by: Computer Associates
Fantibag.R
This malware was reported by: Computer Associates
Description Win32.Fantibag.R is a trojan that creates filters for IPv4 packets to block access to many and varied antivirus company domains. It has been dropped as a
Glieder.CX
This malware was reported by: Computer Associates
Description Win32/Glieder.CX is a trojan that downloads and executes arbitrary files from a long, hardcoded list of particular URLs. It has been dropped as a 10,175-
Mitglieder.DQ
This malware was reported by: Computer Associates
Description Win32/Mitglieder.DQ is a trojan that opens a backdoor on an affected machine, and acts as a SOCKS 4/5 proxy. The trojan also periodically contacts web si
Glieder.DB
This malware was reported by: Computer Associates
W32/Rbot-CGC
This malware was reported by: Sophos
W32/Sdbot-DJA
This malware was reported by: Sophos
Mare.D
This malware was reported by: F-Secure
UNIX_MARE.D
This malware was reported by: Trendmicro
To get a one-glance comprehensive view of the behavior of this Unix malware, refer to the Behavior Diagram shown below.
PWS-WoW
This malware was reported by: Network Associates Inc
PWS-WoW.dll
This malware was reported by: Network Associates Inc
W32/Brontok-W
This malware was reported by: Sophos
Troj/BagleDl-BL
This malware was reported by: Sophos
JS_FEEBS.CZ
This malware was reported by: Trendmicro
To get a one glance comprehensive view of the behavior of this malicious JavaScript, refer to the Behavior Diagram shown below:
Inqtana.A
This malware was reported by: Panda Software
 Inqtana.A is a worm that only affects computers with the operating system Mac OS X 10.4 installed.Inqtana.A has no destructive effects, it only spreads itself in order to affect as many computers as possible.Inqtana.A spreads via Bluetooth. It follows t
Troj/Goldun-BX
This malware was reported by: Sophos
Troj/BankSnif-G
This malware was reported by: Sophos
Fantibag.S
This malware was reported by: Computer Associates
Description Win32.Fantibag.S is a trojan that creates filters for IPv4 packets to block access to many and varied antivirus company domains. It has been dropped as a
Fantibag.T
This malware was reported by: Computer Associates
Description Win32.Fantibag.T is a trojan that creates filters for IPv4 packets to block access to many and varied antivirus company domains. It has been dropped as a
Bagdrop.E
This malware was reported by: Computer Associates
Description Win32/Bagdrop.E is a trojan that drops and executes Win32/Fantibag.S and Win32/Glieder.CY. It has been distributed inside zip files via the eMule P2P net
Bagdrop.F
This malware was reported by: Computer Associates
Description Win32/Bagdrop.F is a trojan that drops and executes Win32/Fantibag.T and Win32/Glieder.CZ. It has been distributed inside zip files via the eMule P2P net
Bagdrop.G
This malware was reported by: Computer Associates
Description Win32/Bagdrop.G is a trojan that drops and executes Win32/Fantibag.S and Win32/Glieder.DA. It has been distributed inside zip files via the eMule P2P net
Glieder.CY
This malware was reported by: Computer Associates
Description Win32/Glieder.CY is a trojan that downloads and executes arbitrary files from a long, hardcoded list of particular URLs. It has been dropped as a 5,076-b
Glieder.CZ
This malware was reported by: Computer Associates
Description Win32/Glieder.CZ is a trojan that downloads and executes arbitrary files from a long, hardcoded list of particular URLs. It has been dropped as a 6,133-b