F-Secure Malware Descriptions http://www.f-secure.com These are F-Secure malware descriptions en Copyright, F-Secure Wed, 10 Mar 2010 04:05:44 +0200 Wed, 10 Mar 2010 04:05:44 +0200 http://blogs.law.harvard.edu/tech/rss webmaster@f-secure.com webmaster@f-secure.com Exploit:W32/PDFExploit.G http://www.f-secure.com/v-descs/exploit_w32_pdfexploit_g.shtml A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server. Trojan:W32/Buzus http://www.f-secure.com/v-descs/trojan_w32_buzus.shtml A trojan, or trojan horse, is a seemingly legitimate program which secretly performs other, usually malicious, functions. It is usually user-initiated and does not replicate. Trojan:W32/Generic http://www.f-secure.com/v-descs/trojan_w32_generic.shtml A trojan, or trojan horse, is a seemingly legitimate program which secretly performs other, usually malicious, functions. It is usually user-initiated and does not replicate. Trojan:W32/Autoruninf.gen http://www.f-secure.com/v-descs/trojan_w32_autoruninf_gen.shtml A trojan, or trojan horse, is a seemingly legitimate program which secretly performs other, usually malicious, functions. It is usually user-initiated and does not replicate. Exploit:JS/Pidief http://www.f-secure.com/v-descs/exploit_js_pidief.shtml A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server. Exploit:W32/PDF-Payload.Gen http://www.f-secure.com/v-descs/exploit_w32_pdf-payload_gen.shtml A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server. Adware:W32/Doubled.gen!C http://www.f-secure.com/sw-desc/adware_w32_doubled_gen!c.shtml This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware. Application:W32/WinVNC http://www.f-secure.com/sw-desc/application_w32_winvnc.shtml A legitimate application that may introduce additional security risks or be used for malicious purposes. Adware:W32/Popmenu http://www.f-secure.com/sw-desc/adware_w32_popmenu.shtml This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware. Rootkit:W32/Xanti.gen!A http://www.f-secure.com/v-descs/rootkit_w32_xanti_gen!a.shtml A program or set of programs which hides itself by subverting or evading the computer's security mechanisms, then allows remote users to secretly control the computer's operating system. Adware:W32/Adware http://www.f-secure.com/sw-desc/adware_w32_adware.shtml This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware. Adware:W32/Gibmedia http://www.f-secure.com/sw-desc/adware_w32_gibmedia.shtml This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware. Adware:W32/Yabelink http://www.f-secure.com/sw-desc/adware_w32_yabelink.shtml This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware. Riskware:W32/Riskware http://www.f-secure.com/sw-desc/riskware_w32_riskware.shtml Useful, legitimate software which could possibly be misused for malicious purposes. Adware:W32/Navipromo http://www.f-secure.com/sw-desc/adware_w32_navipromo.shtml This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware. Monitoring-Tool:SymbOS/Spyphone http://www.f-secure.com/sw-desc/monitoring-tool_symbos_spyphone.shtml A program that monitors and records all actions on a computer, including keystrokes entered. Suspicious:W32/Malware!Online http://www.f-secure.com/v-descs/suspicious_w32_malware!online.shtml The file appears to be suspicious, is potentially undesirable, or may be structured in a way or has characteristics that resembles known malware.<br /> <br /> This may indicate the presence of a malware infection, or that the suspect file is malicious. Suspicious:W32/Riskware!Online http://www.f-secure.com/sw-desc/suspicious_w32_riskware!online.shtml The file appears to be suspicious, is potentially undesirable, or may be structured in a way or has characteristics that resembles known riskware. Trojan:W32/SuspectBehavior_NetworkShareFileDrop http://www.f-secure.com/v-descs/trojan_w32_suspectbehavior_networksharefiledrop.shtml Also known as a trojan horse program, this is a deceptive program that performs additional actions without the user's knowledge or permission. It does not replicate. Worm:W32/Zimuse.B http://www.f-secure.com/v-descs/worm_w32_zimuse_b.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Worm:W32/Zimuse.A http://www.f-secure.com/v-descs/worm_w32_zimuse_a.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Other:W32/False Positive http://www.f-secure.com/v-descs/other_w32_false_positive.shtml A program which does not easily fit into any other category. Rogue:W32/XPAntivirus.gen!I http://www.f-secure.com/v-descs/rogue_w32_xpantivirus_gen!i.shtml Deceptive antivirus software that pressures users into buying or installing it (e.g., infecting a computer; displaying false or alarming warnings or scanning results). Once installed, it may not function as claimed. Rogue:W32/SpywareSheriff http://www.f-secure.com/v-descs/rogue_w32_spywaresheriff.shtml Dishonest antivirus software which tricks users into buying or installing it, usually by infecting a user's computer, or by pretending the computer is infected. Exploit:JS/Comele.A http://www.f-secure.com/v-descs/exploit_js_comele_a.shtml A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server. Email-Worm:MSIL/Agent.MXK http://www.f-secure.com/v-descs/email-worm_msil_agent_mxk.shtml A worm that spreads via e-mail, usually in infected executable e-mail file attachments. Worm:W32/Agent.IPZ http://www.f-secure.com/v-descs/worm_w32_agent_ipz.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Trojan:W32/Trojan http://www.f-secure.com/v-descs/trojan_w32_trojan.shtml A trojan, or trojan horse, is a seemingly legitimate program which secretly performs other, usually malicious, functions. It is usually user-initiated and does not replicate. Trojan-Downloader:W32/Renos.GEN http://www.f-secure.com/v-descs/trojan-downloader_w32_renos_gen.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan:W32/Krap.B http://www.f-secure.com/v-descs/trojan_w32_krap_b.shtml A trojan, or trojan horse, is a seemingly legitimate program which secretly performs other, usually malicious, functions. It is usually user-initiated and does not replicate. Trojan-Downloader:W32/Swizzor http://www.f-secure.com/v-descs/trojan-downloader_w32_swizzor.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Other:W32/Application http://www.f-secure.com/sw-desc/other_w32_application.shtml A legitimate application that may introduce additional security risks or be used for malicious purposes. Exploit:W32/AdobeReader.UZ http://www.f-secure.com/v-descs/exploit_w32_adobereader_uz.shtml A program or technique that takes advantage of a vulnerability to remotely access or attack a program, computer or server. Trojan-Downloader:W32/Agent.MRL http://www.f-secure.com/v-descs/trojan-downloader_w32_agent_mrl.shtml A trojan that secretly downloads malicious files from a remote server, then installs and executes the files. Trojan:W32/Agent.KOG http://www.f-secure.com/v-descs/trojan_w32_agent_kog.shtml Also known as a trojan horse program, this is a deceptive program that performs additional actions without the user's knowledge or permission. It does not replicate. Application:W32/Hoax http://www.f-secure.com/v-descs/application_w32_hoax.shtml A legitimate application that may introduce additional security risks or be used for malicious purposes. Trojan-Downloader:W32/DLoader http://www.f-secure.com/v-descs/trojan-downloader_w32_dloader.shtml A trojan that secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-Downloader:JS/Gumblar.X http://www.f-secure.com/v-descs/trojan-downloader_js_gumblar_x.shtml A trojan that secretly downloads malicious files from a remote server, then installs and executes the files. Rogue:W32/DatDoc http://www.f-secure.com/v-descs/rogue_w32_datdoc.shtml Deceptive antivirus software that pressures users into buying or installing it (e.g., infecting a computer; displaying false or alarming warnings or scanning results). Once installed, it may not function as claimed. Trojan:W32/DatCrypt http://www.f-secure.com/v-descs/trojan_w32_datcrypt.shtml Also known as a trojan horse program, this is a deceptive program that performs additional actions without the user's knowledge or permission. It does not replicate. Other:W32/Constructor http://www.f-secure.com/v-descs/other_w32_constructor.shtml A program or utility used to construct malware. Trojan:W32/Agent.ANWQ http://www.f-secure.com/v-descs/trojan_w32_agent_anwq.shtml Also known as a trojan horse program, this is a deceptive program that performs additional actions without the user's knowledge or permission. It does not replicate. Trojan:WinCE/Redoc http://www.f-secure.com/v-descs/trojan_wince_redoc.shtml Also known as a trojan horse program, this is a deceptive program that performs additional actions without the user's knowledge or permission. It does not replicate. Suspicious:W32/Malware!Gemini http://www.f-secure.com/v-descs/suspicious_w32_malware!gemini.shtml The file appears to be performing suspicious or potentially undesirable actions on the system. This may potentially indicate the presence of a malware infection, or that the suspect file is malicious. Trojan:OSX/Loosemaque.A http://www.f-secure.com/v-descs/trojan_osx_loosemaque_a.shtml Also known as a trojan horse program, this is a deceptive program that performs additional actions without the user's knowledge or permission. It does not replicate. Worm:iPhoneOS/Ikee.B http://www.f-secure.com/v-descs/worm_iphoneos_ikee_b.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Worm:iPhoneOS/Ikee http://www.f-secure.com/v-descs/worm_iphoneos_ikee.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Trojan:W32/Vilsel http://www.f-secure.com/v-descs/trojan_w32_vilsel.shtml A trojan, or trojan horse, is a seemingly legitimate program which secretly performs other, usually malicious, functions. It is usually user-initiated and does not replicate. Trojan-PSW:W32/OnlineGames http://www.f-secure.com/v-descs/trojan-psw_w32_onlinegames.shtml This type of trojan steals passwords and other sensitive information. It may also secretly install other malicious programs. Rogue:W32/SysGuard.D http://www.f-secure.com/v-descs/rogue_w32_sysguard_d.shtml Dishonest antivirus software which tricks users into buying or installing it, usually by infecting a user's computer, or by pretending the computer is infected.