F-Secure Malware Descriptions http://www.f-secure.com These are F-Secure malware descriptions en Copyright, F-Secure Tue, 18 Nov 2008 14:27:59 +0200 Tue, 18 Nov 2008 14:27:59 +0200 http://blogs.law.harvard.edu/tech/rss webmaster@f-secure.com webmaster@f-secure.com Trojan-Spy:W32/ZBot.XF http://www.f-secure.com/v-descs/trojan-spy_w32_zbot_xf.shtml Trojan-Spy:W32/ZBot.XF is a trojan-spy. <br /><br /> Trojan-spy applications attempt to steal online banking login-information and other sensitive data from the infected computer. <br /><br /> ZBot.XF also targets online poker and gaming sites. Trojan:Java/Konov.A http://www.f-secure.com/v-descs/trojan_java_konov_a.shtml Konov is a Java (J2ME) trojan. <br /><br /> Konov will work on most phones capable of executing Java programs. Once executed Konov will send SMS messages to premium rate numbers. Trackware:W32/Tracking Cookie http://www.f-secure.com/sw-desc/trackware_w32_tracking_cookie.shtml Tracking cookies are files that track your web browsing habits.<br /> <br /> Tracking cookies are browser settings that provide websites a unique ID for the user. The tracking cookies are constantly recreated when you browse the web. Trojan-Spy:W32/Gimmiv.A http://www.f-secure.com/v-descs/trojan-spy_w32_gimmiv_a.shtml This type of trojan secretly installs spy programs and/or keylogger programs. Trojan-Downloader:W32/FakeAlert.BG http://www.f-secure.com/v-descs/trojan-downloader_w32_fakealert_bg.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-Downloader:W32/Renos.GEN http://www.f-secure.com/v-descs/trojan-downloader_w32_renos_gen.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Worm:W32/AutoRun.NOI http://www.f-secure.com/v-descs/worm_w32_autorun_noi.shtml AutoRun worm. Net-Worm:W32/Koobface.BM http://www.f-secure.com/v-descs/net-worm_w32_koobface_bm.shtml A type of worm that replicates by sending complete, independent copies of itself over a network. Rootkit:W32/Agent.UI http://www.f-secure.com/v-descs/rootkit_w32_agent_ui.shtml A program or set of programs which hides itself by subverting or evading the computer's security mechanisms, then allows remote users to secretly control the computer's operating system. Backdoor:W32/Hupigon.OGA http://www.f-secure.com/v-descs/backdoor_w32_hupigon_oga.shtml A remote administration utility which bypasses normal security mechanisms to secretly control a program, computer, or network. Trojan-Downloader:W32/Tibs.VX http://www.f-secure.com/v-descs/trojan-downloader_w32_tibs_vx.shtml This malware downloads files into the system and executes them. Trojan-Spy:W32/Goldun.RR http://www.f-secure.com/v-descs/trojan-spy_w32_goldun_rr.shtml A type of trojan that includes a variety of spy programs and keyloggers. Trojan-Dropper:W32/Hoaxer.B http://www.f-secure.com/v-descs/trojan-dropper_w32_hoaxer_b.shtml This type of trojan contains one or more malicious files, which it will secretly install on the system. Trojan-Downloader:W32/Agent.HSM http://www.f-secure.com/v-descs/trojan-downloader_w32_agent_hsm.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Monitoring Tool:WinCE/BopSmiley.A http://www.f-secure.com/sw-desc/monitoring_tool_wince_bopsmiley_a.shtml BopSmiley is a spying application for mobile phones using Windows PocketPC or Windows Smartphone operating systems. <br /><br /> When the application is active on a phone, it records both voice call and SMS information and sends the details to a third party server. Adware:W32/AdRotator.GEN http://www.f-secure.com/sw-desc/adware_w32_adrotator_gen.shtml Adware: A type of Advertising Display Software that delivers advertising content potentially in a manner or context that may be unexpected and unwanted by consumers. <br /><br /> Many adware applications also perform tracking functions, and therefore may also be categorized as Tracking Technologies. Trojan:W32/Monder.GEN http://www.f-secure.com/v-descs/trojan_w32_monder_gen.shtml Trojan.Win32.Monder.gen is generic detection of trojans that are involved in the installation of "Virtumonde" adware/spyware. Backdoor:W32/IRCBot.DIG http://www.f-secure.com/v-descs/backdoor_w32_ircbot_dig.shtml A remote administration tool (RAT) which bypasses normal security mechanisms to secretly control a program, computer or network. Trojan-Downloader:W32/Agent.HPS http://www.f-secure.com/v-descs/trojan-downloader_w32_agent_hps.shtml Trojan-downloaders attempt to download and install new malware, spyware, or adware on the targeted computer. No graphical user interface can be seen; it will run in the background. Backdoor:W32/IRCBot http://www.f-secure.com/v-descs/backdoor_w32_ircbot.shtml Backdoors are Remote Administration Tools (RAT) that expose infected machines to external control via the Internet. <br /><br /> IRCBots are a type of "bot" that receive commands and are controlled via Internet Relay Chat (IRC). <br /><br /> Botnets have been used for sending spam remotely, installing more malware without consent, and other illicit purposes. Rootkit:W32/Agent.UG http://www.f-secure.com/v-descs/rootkit_w32_agent_ug.shtml A program or set of programs which hides itself by subverting or evading the computer's security mechanisms, then allows remote users to secretly control the computer's operating system. Worm:W32/AutoRun.GM http://www.f-secure.com/v-descs/worm_w32_autorun_gm.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Backdoor:W32/Hupigon.EMV http://www.f-secure.com/v-descs/backdoor_w32_hupigon_emv.shtml A backdoor is a Remote Administration Tools (RAT) that expose infected machines to external control via the Internet by remote attackers. Trojan-Downloader:W32/ConHook.APX http://www.f-secure.com/v-descs/trojan-downloader_w32_conhook_apx.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Worm:W32/Autorun.NDS http://www.f-secure.com/v-descs/worm_w32_autorun_nds.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Rootkit:W32/Agent.TZ http://www.f-secure.com/v-descs/rootkit_w32_agent_tz.shtml A program or set of programs which hides itself by subverting or evading the computer's security mechanisms, then allows remote users to secretly control the computer's operating system. Trojan-Spy:W32/Banbra.RH http://www.f-secure.com/v-descs/trojan-spy_w32_banbra_rh.shtml This type of trojan secretly installs spy programs and/or keylogger programs. Trojan-Dropper:W32/Agent.FBB http://www.f-secure.com/v-descs/trojan-dropper_w32_agent_fbb.shtml This type of trojan contains one or more malicious programs, which it will secretly install and execute. Worm:W32/Autorun.GA http://www.f-secure.com/v-descs/worm_w32_autorun_ga.shtml A standalone malicious program which uses computer or removable drives to make complete copies of itself. Worm:W32/VB.KQ http://www.f-secure.com/v-descs/worm_w32_vb_kq.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. <br /><br /> May include code or other malware to damage both the system and the network. Worm:W32/Kaxela.A http://www.f-secure.com/v-descs/worm_w32_kaxela_a.shtml A standalone malicious program which uses computer or network resources to make complete copies of itself. May include code or other malware to damage both the system and the network. Backdoor:W32/Zapchast http://www.f-secure.com/v-descs/backdoor_w32_zapchast.shtml A remote administration utility which bypasses normal security mechanisms to secretly control a program, computer or network. Trojan-Spy:W32/Zbot http://www.f-secure.com/v-descs/trojan-spy_w32_zbot.shtml This type of trojan secretly installs spy programs and/or keylogger programs. Backdoor:W32/Hupigon.OET http://www.f-secure.com/v-descs/backdoor_w32_hupigon_oet.shtml A remote administration utility which bypasses normal security mechanisms to secretly control a program, computer or network. Email-Worm:VBS/Gedza.B http://www.f-secure.com/v-descs/email-worm_vbs_gedza_b.shtml This type of worm is embedded in an e-mail attachment, and spreads using the infected computer's e-mailing networks. Trojan-Downloader:HTML/IFrame.SV http://www.f-secure.com/v-descs/trojan-downloader_html_iframe_sv.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-Downloader:W32/Small.AAFH http://www.f-secure.com/v-descs/trojan-downloader_w32_small_aafh.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-Downloader:W32/Exchanger.AJ http://www.f-secure.com/v-descs/trojan-downloader_w32_exchanger_aj.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-Downloader:JS/Agent.CTL http://www.f-secure.com/v-descs/trojan-downloader_js_agent_ctl.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-Downloader:JS/Agent.CKK http://www.f-secure.com/v-descs/trojan-downloader_js_agent_ckk.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-Downloader:HTML/IFrame.SU http://www.f-secure.com/v-descs/trojan-downloader_html_iframe_su.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-Downloader:JS/Agent.CKL http://www.f-secure.com/v-descs/trojan-downloader_js_agent_ckl.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Trojan-PSW:W32/Nilage.AFZ http://www.f-secure.com/v-descs/trojan-psw_w32_nilage_afz.shtml Trojan-PSW:W32/Nilage.AFZ attempts to steal username and password information for the Lineage MMORPG. Trojan-Downloader:JS/Agent.CTK http://www.f-secure.com/v-descs/trojan-downloader_js_agent_ctk.shtml This type of trojan secretly downloads malicious files from a remote server, then installs and executes the files. Worm:SymbOS/Commwarrior http://www.f-secure.com/v-descs/worm_symbos_commwarrior.shtml Commwarrior is a worm that operates on Symbian Series 60 2nd Edition devices. <br /><br /> The worm is capable of spreading itself via Bluetooth and MMS. Rogue:W32/Rogue antispyware http://www.f-secure.com/sw-desc/rogue_w32_rogue_antispyware.shtml Dishonest antivirus software which tricks users into buying or installing it, usually by infecting a user's computer, or by pretending the computer is infected. Rogue:W32/XPAntivirus http://www.f-secure.com/sw-desc/rogue_w32_xpantivirus.shtml XP Antivirus is a "rogue" security program that claims to detect and remove malicious software, but gives fake and exaggerated scan results in an attempt to trick people into purchasing the program. <br /><br /> This rogue program is commonly downloaded and installed via trojans without consent and even hijacks the user's desktop to display misleading and alarming messages. Trojan-Downloader:W32/Exchanger http://www.f-secure.com/v-descs/trojan-downloader_w32_exchanger.shtml Trojan-Downloader:W32/Exchanger variants download additional malicious software onto the infected system. Worm:W32/Autorun.BHX http://www.f-secure.com/v-descs/worm_w32_autorun_bhx.shtml Worm:W32/Autorun.BHX spreads by copying itself to removable drives and attempts to steal username and password information for several different online games. Trojan:W32/Agent.FVO http://www.f-secure.com/v-descs/trojan_w32_agent_fvo.shtml Trojans are malicious programs that pretend be to benign. Trojans do not replicate themselves.