Prevent Online Threats

Archive for November, 2006

Trojan-Downloader.Win32.Leodon.a

Tuesday, November 14th, 2006

This Trojan downloads files via the Internet without the user’s knowledge or consent. It is a Windows PE EXE file. The file is 11,350 bytes in size. It is packed using UPX. The unpacked file is approximately 45KB in size. It is written in Borland Delphi.

Trojan-Downloader.Win32.IMCdown

Tuesday, November 14th, 2006

This Trojan downloads files via the Internet without the user’s knowledge or consent.

It is a Windows PE EXE file. It is written in Borland C++. It has the following components:

CLIENT.EXE — 57 344 bytes
SERVER.EXE — 65 024 bytes
X.EXE — 4 096 bytes

Nuker.Win32.Nonuker

Tuesday, November 14th, 2006

This program is designed to listen on port 139. It is a Windows PE EXE file. The file is 238,592 bytes in size. It is written in Borland Delphi.

Trojan-Spy.Win32.Dks.12.a

Tuesday, November 14th, 2006

This Trojan logs the user’s keystrokes. It is a Windows PE EXE file. It is written in Visual C++. The file is 12,288 bytes in size. It is packed using ASPack. The unpacked file is approximately 20KB in size.

Installation

Once launched, the Trojan copies itself to the Windows system…

Trojan.Win32.Patched.e

Monday, November 13th, 2006

This Trojan is a Windows PE EXE file. The file is 190,976 bytes in size.

Backdoor.Win32.Agent.lw

Monday, November 13th, 2006

This Trojan provides a remote malicious user with access to the victim machine. It is a Windows PE EXE file. The size of the backdoor components varies between 8KB to 80KB.

Installation

When launched, the backdoor copies its executable file to the Windows system directory:…

Backdoor.Win32.Rbot.bnb

Monday, November 13th, 2006

This Trojan provides a remote malicious user with access to the victim machine. It is managed via IRC. It is a Windows PE EXE file. The file is 40,717 bytes in size. It is packed using FSG. The unpacked file is approximately 120KB in size.

Installation

When installing, the backdoor launches an…

Trojan-Downloader.Win32.Small.crd

Monday, November 13th, 2006

This Trojan downloads files via the Internet without the user’s knowledge or consent. It is a Windows DLL file. The file is 4096 bytes in size. It is written in Assembler.

Trojan-Downloader.Win32.Delf.dg

Friday, November 10th, 2006

This Trojan downloads files via the Internet without the user’s knowledge or consent. It is a Windows PE EXE file. It is written in Delphi. The file is 25,088 bytes in size.

Trojan-Dropper.Win32.Small.rd

Friday, November 10th, 2006

This Trojan is designed to install other Trojan programs to the victim machine without the knowledge or consent of the user. The Trojan itself is a Windows PE EXE file 27,648 bytes in size.

Trojan-Dropper.Win32.Small.ra

Friday, November 10th, 2006

This Trojan is designed to install other Trojan programs to the victim machine without the knowledge or consent of the user. The Trojan itself is a Windows PE EXE file 7200 bytes in size. It is packed using UPX. The unpacked file is approximately 22KB in size.

Trojan.Win32.Qhost.gg

Friday, November 10th, 2006

This Trojan is a modified Windows %System%\drivers\etc\hosts file, which is used to translate domain names (DNS) to IP addresses. The file is modified in such a way as to prevent the user from viewing the sites listed below.

The following strings are added to the hosts file.

216.81.27.1…

Trojan.Win32.Agent.aan

Friday, November 10th, 2006

This Trojan is designed to install other malicious programs. It is a Windows PE EXE file. The file is 19,456 bytes in size. It is packed using UPX. The unpacked file is approximately 40KB in size.

Trojan.Win32.Qhost.ii

Friday, November 10th, 2006

This Trojan is a modified Windows %System%\drivers\etc\hosts file, which is used to translate domain names (DNS) to IP addresses. The modified file is 46 599 bytes in size. The file is modified in such a way as to prevent the user from viewing the sites listed below.

Trojan-Downloader.Win32.IstBar.or

Friday, November 10th, 2006

This Trojan downloader is a Windows PE EXE file. The file is 32,256 bytes in size. The unpacked file is approximately 90KB in size. It is written in Visual C++.


Spyware Removal Spyware Protection Tools