F-Secure Malware Descriptions http://www.f-secure.com These are F-Secure malware descriptions en Copyright, F-Secure Mon, 5 Jan 2009 17:46:24 +0200 Mon, 5 Jan 2009 17:46:24 +0200 http://blogs.law.harvard.edu/tech/rss webmaster@f-secure.com webmaster@f-secure.com Worm:W32/Downadup.AL http://www.f-secure.com/v-descs/worm_w32_downadup_al.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Exploit:SymbOS/SMSCurse.A http://www.f-secure.com/v-descs/exploit_symbos_smscurse_a.shtml Exploit:/SymbOS/SMSCurse.A is a Denial-of-Service (DoS) exploit that affects messaging components of phones that use Symbian Series 60 versions 2.6, 2.8, 3.0, 3.1, and Sony Ericsson UiQ devices.<br /> <br /> When the exploit crashes SMS messaging on a phone, the phone remains otherwise completely functional. The only effect is that it cannot receive any new SMS/MMS messages. Email-Worm:W32/Waledac.A http://www.f-secure.com/v-descs/email-worm_w32_waledac_a.shtml This type of worm is embedded in an e-mail attachment, and spreads using the infected computer's e-mailing networks. Trojan-Downloader:W32/Banload.FVQ http://www.f-secure.com/v-descs/trojan-downloader_w32_banload_fvq.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-Spy:W32/Banbra.RM http://www.f-secure.com/v-descs/trojan-spy_w32_banbra_rm.shtml This type of trojan secretly installs spy programs and/or keylogger programs. Trojan-Dropper:W32/Ambler.D http://www.f-secure.com/v-descs/trojan-dropper_w32_ambler_d.shtml This type of trojan contains one or more malicious programs, which it will secretly install and execute. Backdoor:W32/Agent.IFX http://www.f-secure.com/v-descs/backdoor_w32_agent_ifx.shtml Backdoors are Remote Administration Tools (RAT) that expose infected machines to external control via the Internet. Trojan-Spy:W32/Ambler.C http://www.f-secure.com/v-descs/trojan-spy_w32_ambler_c.shtml This type of trojan secretly installs spy programs and/or keylogger programs. Exploit:JS/Agent.IHL http://www.f-secure.com/v-descs/exploit_js_agent_ihl.shtml Exploit:JS/Agent.IHL is JavaScript, usually found on malicious or compromised websites. <br /><br /> It is used to silently install malicious software onto the website visitor's system. Worm:W32/AutoRun.DMO http://www.f-secure.com/v-descs/worm_w32_autorun_dmo.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Trojan:W32/DNSChanger.ARNF http://www.f-secure.com/v-descs/trojan_w32_dnschanger_arnf.shtml A trojan, or trojan horse, is a seemingly legitimate program which secretly performs other, usually malicious, functions. The program is often started by the user, and it does not usually replicate. Trojan-Dropper:W32/Agent.FLN http://www.f-secure.com/v-descs/trojan-dropper_w32_agent_fln.shtml This type of trojan contains one or more malicious programs, which it secretly installs and executes. Toolbar:W32/SweetIM http://www.f-secure.com/sw-desc/toolbar_w32_sweetim.shtml SweetIM is an instant messenger add on. Worm:W32/Downadup http://www.f-secure.com/v-descs/worm_w32_downadup.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Net-Worm:W32/Koobface.CY http://www.f-secure.com/v-descs/net-worm_w32_koobface_cy.shtml A type of worm that replicates by sending complete, independent copies of itself over a network. Net-Worm:W32/Koobface.CZ http://www.f-secure.com/v-descs/net-worm_w32_koobface_cz.shtml A type of worm that replicates by sending complete, independent copies of itself over a network. Backdoor:W32/TDSS http://www.f-secure.com/v-descs/backdoor_w32_tdss.shtml A remote administration utility which bypasses normal security mechanisms to secretly control a program, computer or network. Trojan:W32/Krap.B http://www.f-secure.com/v-descs/trojan_w32_krap_b.shtml This detection is of "packed" software. Packers are used to compress files and to disguise the malicious contents. Backdoor:W32/SdBot.CNJ http://www.f-secure.com/v-descs/backdoor_w32_sdbot_cnj.shtml Backdoor:W32/SdBot.CNJ is a piece of malicious software that tries to disable various firewalls and antivirus programs, steal passwords from the infected machine and spread through removable media devices Trojan-Downloader:W32/Agent.IDO http://www.f-secure.com/v-descs/trojan-downloader_w32_agent_ido.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Worm:W32/Autorun.KK http://www.f-secure.com/v-descs/worm_w32_autorun_kk.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Rogue:W32/VirusRemover2008.C http://www.f-secure.com/v-descs/rogue_w32_virusremover2008_c.shtml "Rogue" software is an antivirus or antispyware program that tricks users into buying or installing it, usually by infecting a user's computer, or by pretending the computer is infected. Worm:W32/AutoIt.Q http://www.f-secure.com/v-descs/worm_w32_autoit_q.shtml This malware spreads by copying itself to removable devices and replacing the autorun.inf of the device with its own copy to ensure automatic execution. Trojan:W32/Feedel http://www.f-secure.com/v-descs/trojan_w32_feedel.shtml A trojan, or trojan horse, is a seemingly legitimate program which secretly performs other, usually malicious, functions. It is usually user-initiated and does not replicate. Trojan-Downloader:OSX/Jahlev.A http://www.f-secure.com/v-descs/trojan-downloader_osx_jahlev_a.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Worm:W32/Autorun.KD http://www.f-secure.com/v-descs/worm_w32_autorun_kd.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Trojan-Spy:W32/ZBot.XF http://www.f-secure.com/v-descs/trojan-spy_w32_zbot_xf.shtml Trojan-Spy:W32/ZBot.XF is a trojan-spy. <br /><br /> Trojan-spy applications attempt to steal online banking login-information and other sensitive data from the infected computer. <br /><br /> ZBot.XF also targets online poker and gaming sites. Trojan:Java/Konov.A http://www.f-secure.com/v-descs/trojan_java_konov_a.shtml Konov is a Java (J2ME) trojan. <br /><br /> Konov will work on most phones capable of executing Java programs. Once executed Konov will send SMS messages to premium rate numbers. Trackware:W32/Tracking Cookie http://www.f-secure.com/sw-desc/trackware_w32_tracking_cookie.shtml Tracking cookies are files that track your web browsing habits.<br /> <br /> Tracking cookies are browser settings that provide websites a unique ID for the user. The tracking cookies are constantly recreated when you browse the web. Trojan-Spy:W32/Gimmiv.A http://www.f-secure.com/v-descs/trojan-spy_w32_gimmiv_a.shtml This type of trojan secretly installs spy programs and/or keylogger programs. Trojan-Downloader:W32/FakeAlert.BG http://www.f-secure.com/v-descs/trojan-downloader_w32_fakealert_bg.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-Downloader:W32/Renos.GEN http://www.f-secure.com/v-descs/trojan-downloader_w32_renos_gen.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Worm:W32/AutoRun.NOI http://www.f-secure.com/v-descs/worm_w32_autorun_noi.shtml AutoRun worm. Rootkit:W32/Agent.UI http://www.f-secure.com/v-descs/rootkit_w32_agent_ui.shtml A program or set of programs which hides itself by subverting or evading the computer's security mechanisms, then allows remote users to secretly control the computer's operating system. Backdoor:W32/Hupigon.OGA http://www.f-secure.com/v-descs/backdoor_w32_hupigon_oga.shtml A remote administration utility which bypasses normal security mechanisms to secretly control a program, computer, or network. Trojan-Downloader:W32/Tibs.VX http://www.f-secure.com/v-descs/trojan-downloader_w32_tibs_vx.shtml This malware downloads files into the system and executes them. Trojan-Spy:W32/Goldun.RR http://www.f-secure.com/v-descs/trojan-spy_w32_goldun_rr.shtml A type of trojan that includes a variety of spy programs and keyloggers. Trojan-Dropper:W32/Hoaxer.B http://www.f-secure.com/v-descs/trojan-dropper_w32_hoaxer_b.shtml This type of trojan contains one or more malicious files, which it will secretly install on the system. Trojan-Downloader:W32/Agent.HSM http://www.f-secure.com/v-descs/trojan-downloader_w32_agent_hsm.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Monitoring Tool:WinCE/BopSmiley.A http://www.f-secure.com/sw-desc/monitoring_tool_wince_bopsmiley_a.shtml BopSmiley is a spying application for mobile phones using Windows PocketPC or Windows Smartphone operating systems. <br /><br /> When the application is active on a phone, it records both voice call and SMS information and sends the details to a third party server. Adware:W32/AdRotator.GEN http://www.f-secure.com/sw-desc/adware_w32_adrotator_gen.shtml Adware: A type of Advertising Display Software that delivers advertising content potentially in a manner or context that may be unexpected and unwanted by consumers. <br /><br /> Many adware applications also perform tracking functions, and therefore may also be categorized as Tracking Technologies. Trojan:W32/Monder.GEN http://www.f-secure.com/v-descs/trojan_w32_monder_gen.shtml Trojan.Win32.Monder.gen is generic detection of trojans that are involved in the installation of "Virtumonde" adware/spyware. Backdoor:W32/IRCBot.DIG http://www.f-secure.com/v-descs/backdoor_w32_ircbot_dig.shtml A remote administration tool (RAT) which bypasses normal security mechanisms to secretly control a program, computer or network. Trojan-Downloader:W32/Agent.HPS http://www.f-secure.com/v-descs/trojan-downloader_w32_agent_hps.shtml Trojan-downloaders attempt to download and install new malware, spyware, or adware on the targeted computer. No graphical user interface can be seen; it will run in the background. Backdoor:W32/IRCBot http://www.f-secure.com/v-descs/backdoor_w32_ircbot.shtml Backdoors are Remote Administration Tools (RAT) that expose infected machines to external control via the Internet. <br /><br /> IRCBots are a type of "bot" that receive commands and are controlled via Internet Relay Chat (IRC). <br /><br /> Botnets have been used for sending spam remotely, installing more malware without consent, and other illicit purposes. Rootkit:W32/Agent.UG http://www.f-secure.com/v-descs/rootkit_w32_agent_ug.shtml A program or set of programs which hides itself by subverting or evading the computer's security mechanisms, then allows remote users to secretly control the computer's operating system. Worm:W32/AutoRun.GM http://www.f-secure.com/v-descs/worm_w32_autorun_gm.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Backdoor:W32/Hupigon.EMV http://www.f-secure.com/v-descs/backdoor_w32_hupigon_emv.shtml A backdoor is a Remote Administration Tools (RAT) that expose infected machines to external control via the Internet by remote attackers. Trojan-Downloader:W32/ConHook.APX http://www.f-secure.com/v-descs/trojan-downloader_w32_conhook_apx.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Worm:W32/Autorun.NDS http://www.f-secure.com/v-descs/worm_w32_autorun_nds.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network.