<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link href="http://www.securelist.com/en/rss/descriptions" rel="self" type="application/rss+xml" />
<title>Securelist / Descriptions</title>
<link>http://www.securelist.com/en/</link>
<description></description>
<lastBuildDate>11 Feb 2012 17:23:54 +0400</lastBuildDate>
<image>
<title>Securelist / Descriptions</title>
<url>http://www.securelist.com/en/rss/klogo.gif</url>
<link>http://www.securelist.com/en/</link>	
</image>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan simulates an anti-virus program in order to obtain remuneration from the user for the detection and deletion of false threats. It is a Windows application (PE EXE file). It is 1 134 592...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.FakeAV.eya</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.FakeAV.eya</link>
		<pubDate>09 Feb 2012 14:54:00 +0400</pubDate>
		<title>Trojan.Win32.FakeAV.eya</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>The program's main window is shown below:



Once launched, the Trojan performs the following actions:

If it detects the following processes, it ceases running:...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Buzus.fbcr</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Buzus.fbcr</link>
		<pubDate>09 Feb 2012 14:32:00 +0400</pubDate>
		<title>Trojan.Win32.Buzus.fbcr</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This malicious program provides a malicious user with remote access to the infected computer and uses P2P network file sharing directories to distribute itself. It is a Windows application (PE EXE...</description>
		<guid>http://www.securelist.com/en/descriptions/P2P-Worm.Win32.Palevo.arxz</guid>
		<link>http://www.securelist.com/en/descriptions/P2P-Worm.Win32.Palevo.arxz</link>
		<pubDate>09 Feb 2012 14:17:00 +0400</pubDate>
		<title>P2P-Worm.Win32.Palevo.arxz</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This malicious program is part of other malicious adware. It is a Windows Dynamic Link Library (PE DLL file). It is 213 111 bytes in size. It is written in C++.</description>
		<guid>http://www.securelist.com/en/descriptions/not-a-virus:AdWare.Win32.FunWeb.di</guid>
		<link>http://www.securelist.com/en/descriptions/not-a-virus:AdWare.Win32.FunWeb.di</link>
		<pubDate>08 Feb 2012 19:21:00 +0400</pubDate>
		<title>not-a-virus:AdWare.Win32.FunWeb.di</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan belongs to the family of Trojans that steals passwords from online gaming user account records. It is a Windows application (PE EXE file) and is 116 736 bytes in size. It is packed using...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-GameThief.Win32.Magania.dlip</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-GameThief.Win32.Magania.dlip</link>
		<pubDate>08 Feb 2012 18:44:00 +0400</pubDate>
		<title>Trojan-GameThief.Win32.Magania.dlip</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>Once launched, the backdoor establishes a connection with this server:

in***aca.com

A combination of the following strings is used as a login and password:...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.MSIL.Agent.azy</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.MSIL.Agent.azy</link>
		<pubDate>08 Feb 2012 18:33:00 +0400</pubDate>
		<title>Trojan.MSIL.Agent.azy</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan downloads files from the Internet without the user's knowledge. It is a Windows .NET application (PE EXE file) and is 35 328 bytes in size.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.MSIL.Agent.azx</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.MSIL.Agent.azx</link>
		<pubDate>07 Feb 2012 17:32:00 +0400</pubDate>
		<title>Trojan.MSIL.Agent.azx</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This malicious program demands a ransom in exchange for the content of an encrypted archive, which users believe contains a file that they need. It is a Windows application (PE EXE file) and is 1 191...</description>
		<guid>http://www.securelist.com/en/descriptions/Hoax.Win32.ArchSMS.ong</guid>
		<link>http://www.securelist.com/en/descriptions/Hoax.Win32.ArchSMS.ong</link>
		<pubDate>07 Feb 2012 17:23:00 +0400</pubDate>
		<title>Hoax.Win32.ArchSMS.ong</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>Once launched, the Trojan creates the following system registry key:

[HKCU\Software\Stimul]

Then, the Trojan displays the following window:



After confirmation of &quot;I agree with the rules&quot;,...</description>
		<guid>http://www.securelist.com/en/descriptions/Hoax.Win32.ArchSMS.hewm</guid>
		<link>http://www.securelist.com/en/descriptions/Hoax.Win32.ArchSMS.hewm</link>
		<pubDate>07 Feb 2012 17:18:00 +0400</pubDate>
		<title>Hoax.Win32.ArchSMS.hewm</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>The Java class file &quot;gamesload&quot; includes a JAR archive and is part of a piece of malware. The following components of the Trojan are also stored in the archive:


Game.class - 672...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.Java.OpenStream.av</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Java.OpenStream.av</link>
		<pubDate>06 Feb 2012 17:43:00 +0400</pubDate>
		<title>Trojan-Downloader.Java.OpenStream.av</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan downloads another program to the computer and launches it for execution without the user's knowledge. It is a Windows application (PE EXE file) and is 56 320 bytes in size. It is packed...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Agent.fwcp</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Agent.fwcp</link>
		<pubDate>06 Feb 2012 17:37:00 +0400</pubDate>
		<title>Trojan-Downloader.Win32.Agent.fwcp</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan downloads files from the Internet and launches them without the user's knowledge. It is a Windows application (PE EXE file) and is 53 760 bytes in size. It is written in...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Agent.ejui</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Agent.ejui</link>
		<pubDate>06 Feb 2012 17:31:00 +0400</pubDate>
		<title>Trojan-Downloader.Win32.Agent.ejui</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>Once launched, the backdoor uses the function &quot;GetSystemDefaultLCID&quot; to obtain the ID for the group of national settings that the operating system uses by default. If the value obtained corresponds...</description>
		<guid>http://www.securelist.com/en/descriptions/Backdoor.Win32.Agent.amps</guid>
		<link>http://www.securelist.com/en/descriptions/Backdoor.Win32.Agent.amps</link>
		<pubDate>03 Feb 2012 19:28:00 +0400</pubDate>
		<title>Backdoor.Win32.Agent.amps</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan stops the computer from functioning normally in order to obtain a ransom for restoring the system to its initial condition. It is a Windows application (PE EXE file) and is 40 448 bytes in...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Ransom.Win32.XBlocker.bcp</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Ransom.Win32.XBlocker.bcp</link>
		<pubDate>03 Feb 2012 19:23:00 +0400</pubDate>
		<title>Trojan-Ransom.Win32.XBlocker.bcp</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan stops the computer from functioning in order to obtain a ransom for restoring it. It is a Windows application (PE EXE file) and is 355 328 bytes in size. It is packed using UPX. The...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Ransom.Win32.Gimemo.ns</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Ransom.Win32.Gimemo.ns</link>
		<pubDate>03 Feb 2012 18:57:00 +0400</pubDate>
		<title>Trojan-Ransom.Win32.Gimemo.ns</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan downloads other malicious programs from the Internet and launches them for execution without the user's knowledge. It is a Windows dynamic library (PE EXE file). It is 53 248 bytes in...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Agent.dlyf</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Agent.dlyf</link>
		<pubDate>02 Feb 2012 18:01:00 +0400</pubDate>
		<title>Trojan-Downloader.Win32.Agent.dlyf</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 352 256 bytes in size. It is written in Visual Basic.

Installation

When launching,...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.VB.aeke</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.VB.aeke</link>
		<pubDate>02 Feb 2012 17:51:00 +0400</pubDate>
		<title>Trojan.Win32.VB.aeke</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 142 848 bytes in size. It is written in Delphi.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Smardf.mlt</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Smardf.mlt</link>
		<pubDate>02 Feb 2012 17:10:00 +0400</pubDate>
		<title>Trojan.Win32.Smardf.mlt</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>When the infected page is opened, Java class code starts to run, which leads to the following actions:

The following file is created and launched:


&amp;Ntilde;:\Windows\pay.reg

This causes a change in...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Java.Payphish.a</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Java.Payphish.a</link>
		<pubDate>01 Feb 2012 13:17:00 +0400</pubDate>
		<title>Trojan.Java.Payphish.a</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan provides a malicious user with remote access to the infected computer. It is a Windows application (PE EXE file). It is 365 568 bytes in size. It is written in Delphi.

Installation

Once...</description>
		<guid>http://www.securelist.com/en/descriptions/Backdoor.Win32.Delf.ugd</guid>
		<link>http://www.securelist.com/en/descriptions/Backdoor.Win32.Delf.ugd</link>
		<pubDate>01 Feb 2012 13:03:00 +0400</pubDate>
		<title>Backdoor.Win32.Delf.ugd</title>
	</item>

</channel>
</rss>



