<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link href="http://www.securelist.com/en/rss/latestvirusdescriptions" rel="self" type="application/rss+xml" />
<title>Securelist / Descriptions</title>
<link>http://www.securelist.com/en/</link>
<description></description>
<lastBuildDate>21 May 2013 12:02:13 +0400</lastBuildDate>
<image>
<title>Securelist / Descriptions</title>
<url>http://www.securelist.com/en/rss/klogo.gif</url>
<link>http://www.securelist.com/en/</link>	
</image>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>If your computer has not been protected with anti-virus software and has been infected with malware, you will need to take the following actions to delete this:

Delete the original program file (its...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.JS.Agent.gdn</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.JS.Agent.gdn</link>
		<pubDate>31 Jan 2013 17:21:00 +0400</pubDate>
		<title>Trojan-Downloader.JS.Agent.gdn</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan program. It is a Windows application (PE-EXE file). 742912 bytes. Packed by an unknown packer. Unpacked size - around 788 kB.  Written in Delphi.

Installation

When launching, the...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Scar.dgje</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Scar.dgje</link>
		<pubDate>31 Jan 2013 17:17:00 +0400</pubDate>
		<title>Trojan.Win32.Scar.dgje</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>The malicious library exports the &quot;testall&quot; function which leads to the following actions being carried out.

If the system launches the &quot;avp.exe&quot; process, the trojan tries to download the following...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.KillAV.gcg</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.KillAV.gcg</link>
		<pubDate>31 Jan 2013 16:52:00 +0400</pubDate>
		<title>Trojan.Win32.KillAV.gcg</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>The malicious library is a component of a trojan program designed to steal the user's authentication data. It is a Windows dynamic-link library (PE-DLL file). 8192 bytes. Written in C++.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent2.dmdi</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent2.dmdi</link>
		<pubDate>30 Jan 2013 18:59:00 +0400</pubDate>
		<title>Trojan.Win32.Agent2.dmdi</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan program that uses the vulnerabilities in Oracle Java and Adobe Reader/Acrobat products to download and launch other malware. It is a HTML document containing Java Script. 88200 bytes.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.JS.Agent.gbj</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.JS.Agent.gbj</link>
		<pubDate>30 Jan 2013 18:42:00 +0400</pubDate>
		<title>Trojan-Downloader.JS.Agent.gbj</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan program that uses the vulnerabilities in Oracle Java and Adobe Reader/Acrobat products to download and launch other malware. It is a HTML document containing Java Script. 88518 bytes.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.JS.Agent.gaf</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.JS.Agent.gaf</link>
		<pubDate>30 Jan 2013 18:24:00 +0400</pubDate>
		<title>Trojan-Downloader.JS.Agent.gaf</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan that provides the attacker with remote access to the infected computer. It is a Windows application (PE-EXE file). 176640 bytes. UPX packed. Unpacked size - around 245 kB. Written in...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Jorik.Carberp.ar</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Jorik.Carberp.ar</link>
		<pubDate>29 Jan 2013 14:28:00 +0400</pubDate>
		<title>Trojan.Win32.Jorik.Carberp.ar</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>After launching, the trojan checks for the following branch in the system registry:

[HKCU\Software\Classes\CLSID\{82404416-4C60-47F8-BA06-90BA7261C3AE}\InprocServer32]


If the branch is missing, it...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent2.dmvt</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent2.dmvt</link>
		<pubDate>29 Jan 2013 14:20:00 +0400</pubDate>
		<title>Trojan.Win32.Agent2.dmvt</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan program designed to delete components of the security software Gbuster plugin for Internet Explorer. Implemented in the form of an NT kernel mode driver. 5632 bytes. Written in C++.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.KillFiles.afz</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.KillFiles.afz</link>
		<pubDate>29 Jan 2013 14:15:00 +0400</pubDate>
		<title>Trojan.Win32.KillFiles.afz</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan program that downloads files from the Internet without the user's knowledge and launches them. It is a Windows application (PE-EXE file). 6656 bytes. Written in C++.

Installation

After...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.fajk</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.fajk</link>
		<pubDate>24 Jan 2013 15:25:00 +0400</pubDate>
		<title>Trojan.Win32.Agent.fajk</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan program that carries out destructive actions on the user's computer. It is a Windows application (PE-EXE file). 56832 bytes. Packed by an unknown packer. Unpacked size - around 53 kB....</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Jorik.Buterat.dp</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Jorik.Buterat.dp</link>
		<pubDate>24 Jan 2013 14:51:00 +0400</pubDate>
		<title>Trojan.Win32.Jorik.Buterat.dp</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>Adware designed to redirect user searches to other web resources. It is a Windows application (PE-EXE file). 1135840 bytes. Written in C++.

Installation
The trojan is installed as an add-in for the...</description>
		<guid>http://www.securelist.com/en/descriptions/AdWare.Win32.Gamevance.hfti</guid>
		<link>http://www.securelist.com/en/descriptions/AdWare.Win32.Gamevance.hfti</link>
		<pubDate>24 Jan 2013 14:34:00 +0400</pubDate>
		<title>AdWare.Win32.Gamevance.hfti</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan program that downloads files from the internet without the user's knowledge and launches them. It is a Windows application (PE-EXE file). 7168 bytes. Written in C++.

Installation

When...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Small.bven</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Small.bven</link>
		<pubDate>23 Jan 2013 14:40:00 +0400</pubDate>
		<title>Trojan-Downloader.Win32.Small.bven</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan program. It is a Windows application (PE-EXE file). 244927 bytes. This malware is created using the system to create the installation packages Nullsoft Scriptable Install...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.NSIS.Miner.a</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.NSIS.Miner.a</link>
		<pubDate>23 Jan 2013 12:50:00 +0400</pubDate>
		<title>Trojan.NSIS.Miner.a</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan program that downloads files from the Internet without the user's knowledge and launches them. It is a JAR-archive containing a set of Java-classes (class-files). 15661 bytes.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Java.Agent.an</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Java.Agent.an</link>
		<pubDate>23 Jan 2013 12:40:00 +0400</pubDate>
		<title>Trojan.Java.Agent.an</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>After launching the malicious HTML-document, using Java Script tools, it is decoded and a code is recorded in its body which carries out the following actions:

it launches a script, the location of...</description>
		<guid>http://www.securelist.com/en/descriptions/Exploit.JS.CVE-2010-4452.t</guid>
		<link>http://www.securelist.com/en/descriptions/Exploit.JS.CVE-2010-4452.t</link>
		<pubDate>22 Jan 2013 15:39:00 +0400</pubDate>
		<title>Exploit.JS.CVE-2010-4452.t</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>After opening the malicious HTML page in the browser, it displays the following message:

404 Not Found

Then, using Java Script, the trojan collects system information, in particular:

The type of OS...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.JS.Agent.gcv</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.JS.Agent.gcv</link>
		<pubDate>22 Jan 2013 15:29:00 +0400</pubDate>
		<title>Trojan-Downloader.JS.Agent.gcv</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>If the path to the trojan file does not contain a sequence of &quot;ommon&quot; symbols, the trojan will retrieve a script from its body and will launch this script under the following name:

%ProgramFiles%\&amp;lt...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Dropper.Win32.StartPage.eba</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Dropper.Win32.StartPage.eba</link>
		<pubDate>22 Jan 2013 13:22:00 +0400</pubDate>
		<title>Trojan-Dropper.Win32.StartPage.eba</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>A trojan program that installs and launches other software on the infected computer without the user's knowledge. It is a Windows application (PE-EXE file). 231124 bytes. Written in C++.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Dropper.Win32.Agent.ezqm</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Dropper.Win32.Agent.ezqm</link>
		<pubDate>21 Jan 2013 13:00:00 +0400</pubDate>
		<title>Trojan-Dropper.Win32.Agent.ezqm</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>When launching, the trojan downloads a file from the internet using the following link:


http://&amp;lt;rnd&amp;gt;.***heker.com


Where &amp;lt;rnd&amp;gt; is a random sequence of digits.

The link did not work...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.VB.aiqx</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.VB.aiqx</link>
		<pubDate>21 Jan 2013 12:56:00 +0400</pubDate>
		<title>Trojan-Downloader.Win32.VB.aiqx</title>
	</item>

</channel>
</rss>


