<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0">
<channel>
<title>Securelist / Descriptions</title>
<link>http://www.securelist.com/en/</link>
<description></description>
<lastBuildDate>02 Sep 2010 19:38:23 +0400</lastBuildDate>
<image>
<title>Securelist / Descriptions</title>
<url>http://www.securelist.com/en/rss/klogo.gif</url>
<link>http://www.securelist.com/en/</link>	
</image>
	<item>
		<description>The malicious program intercepts the user&amp;#8217;s requests to various sites and redirects them to a malicious URL. It also contains a tool for sending phishing messages. It propagates via e-mail and...</description>
		<link>http://www.securelist.com/en/descriptions/P2P-Worm.Win32.BlackControl.g</link>
		<pubDate>20 Aug 2010 13:51:00 +0400</pubDate>
		<title>P2P-Worm.Win32.BlackControl.g</title>
	</item>
	<item>
		<description>The program connects to the server:

http://*****lo.ru

where it sends the following request (some of the data may vary):

GET...</description>
		<link>http://www.securelist.com/en/descriptions/Backdoor.Win32.Bredolab.eua</link>
		<pubDate>12 Jul 2010 15:33:00 +0400</pubDate>
		<title>Backdoor.Win32.Bredolab.eua</title>
	</item>
	<item>
		<description>This malicious program is intended for the unauthorized downloading and launching of other malware on a computer.
 
Installation

When launched, the malicious program extracts from itself and creates...</description>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Oficla.w</link>
		<pubDate>07 Jul 2010 15:08:00 +0400</pubDate>
		<title>Trojan.Win32.Oficla.w</title>
	</item>
	<item>
		<description>This Trojan is designed to steal the user's confidential data, as well as providing a remote malicious user with access to the victim machine.  It is a Windows PE EXE file.  It is approximately 85...</description>
		<link>http://www.securelist.com/en/descriptions/Trojan-PSW.Win32.Qbot.mk</link>
		<pubDate>02 Jul 2010 12:11:00 +0400</pubDate>
		<title>Trojan-PSW.Win32.Qbot.mk</title>
	</item>
	<item>
		<description>This Trojan is designed to install and launch other malicious programs on the victim machine without the user&amp;#8217;s knowledge or consent.  It is a Windows PE EXE file.  It is 1083904 bytes in size....</description>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Vilsel.ato</link>
		<pubDate>02 Jul 2010 11:27:00 +0400</pubDate>
		<title>Trojan.Win32.Vilsel.ato</title>
	</item>
	<item>
		<description>This malicious program is designed to steal user data that has to do with banking systems, e-money and plastic cards issued by Brazilian banks. It is a Windows PE EXE file.  It is 942047 bytes in...</description>
		<link>http://www.securelist.com/en/descriptions/Trojan-Banker.Win32.Banz.cri</link>
		<pubDate>16 Jun 2010 16:17:00 +0400</pubDate>
		<title>Trojan-Banker.Win32.Banz.cri</title>
	</item>
	<item>
		<description>This file virus infects Windows executable files. It is a malicious code contained in Windows PE EXE files. The virus body is about 17 Kb, though the use of polymorphic encryption means its size may...</description>
		<link>http://www.securelist.com/en/descriptions/Virus.Win32.Virut.ce</link>
		<pubDate>15 Apr 2010 17:10:00 +0400</pubDate>
		<title>Virus.Win32.Virut.ce</title>
	</item>
	<item>
		<description>This malicious program infects files on the victim computer.  It is designed to download and launch other malicious programs on the victim computer without the user&amp;#8217;s knowledge or consent. It is...</description>
		<link>http://www.securelist.com/en/descriptions/Virus.Win32.Sality.ag</link>
		<pubDate>12 Apr 2010 16:51:00 +0400</pubDate>
		<title>Virus.Win32.Sality.ag</title>
	</item>
	<item>
		<description>This Trojan downloads and runs malicious scripts on the victim machine without the user's knowledge or consent. It is a JavaScript scenario. It is 809 bytes in size.</description>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.JS.Gumblar.x</link>
		<pubDate>03 Dec 2009 17:30:00 +0300</pubDate>
		<title>Trojan-Downloader.JS.Gumblar.x</title>
	</item>
	<item>
		<description>If your computer does not have an up-to-date antivirus, or does not have an antivirus solution at all, follow the instructions below to delete the malicious program:


Use Task Manager to terminate...</description>
		<link>http://www.securelist.com/en/descriptions/Backdoor.Win32.Clampi.a</link>
		<pubDate>25 Sep 2009 14:51:00 +0400</pubDate>
		<title>Backdoor.Win32.Clampi.a</title>
	</item>
	<item>
		<description>This Trojan has a malicious payload.  It is a Windows PE EXE file.  It is 23552 bytes in size. 
Installation
The Trojan copies its executable file as follows: 
%WinDir%\system\svhost.exe
In order to...</description>
		<link>http://www.securelist.com/en/descriptions/Trojan-Dropper.Win32.Agent.albv</link>
		<pubDate>15 Apr 2009 12:17:00 +0400</pubDate>
		<title>Trojan-Dropper.Win32.Agent.albv</title>
	</item>
	<item>
		<description>This Trojan provides a remote malicious user with access to the victim machine.  It is a Windows PE EXE file.  It is 22528 bytes in size.
Installation
Once launched, the Trojan copies its body to the...</description>
		<link>http://www.securelist.com/en/descriptions/Backdoor.Win32.Agent.abgg</link>
		<pubDate>15 Apr 2009 12:15:00 +0400</pubDate>
		<title>Backdoor.Win32.Agent.abgg</title>
	</item>
	<item>
		<description>This malicious program is a Windows DLL file.  
Installation
The malware copies its executable file with random names to the following directories:
%Program Files%\Internet Explorer\&amp;lt;...</description>
		<link>http://www.securelist.com/en/descriptions/Trojan-Dropper.Win32.Kido.a</link>
		<pubDate>18 Mar 2009 16:36:00 +0300</pubDate>
		<title>Trojan-Dropper.Win32.Kido.a</title>
	</item>
	<item>
		<description>This worm spreads as an attachment to infected emails and also via file-sharing networks and removable media.  The worm itself is a Windows PE EXE file.  The worm&amp;#8217;s executable file can vary...</description>
		<link>http://www.securelist.com/en/descriptions/Email-Worm.Win32.Merond.a</link>
		<pubDate>12 Mar 2009 19:36:00 +0300</pubDate>
		<title>Email-Worm.Win32.Merond.a</title>
	</item>
	<item>
		<description>This malicious program is a Trojan.  It is a Windows PE EXE file.  It is 417792 bytes in size. It is packed using UPX.  The unpacked file is approximately 439KB in size.  It is written in...</description>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.azsy</link>
		<pubDate>12 Mar 2009 19:29:00 +0300</pubDate>
		<title>Trojan.Win32.Agent.azsy</title>
	</item>
	<item>
		<description>This Trojan calls premium rate numbers without the knowledge or consent of the user.  It is a Windows PE EXE file.  It is 25131 bytes in size. It is written in Delphi.</description>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent2.dtb</link>
		<pubDate>12 Mar 2009 19:23:00 +0300</pubDate>
		<title>Trojan.Win32.Agent2.dtb</title>
	</item>
	<item>
		<description>This Trojan downloads other files via the Internet and launches them for execution on the victim machine without the user&amp;#8217;s knowledge or consent.  It is a Windows PE EXE file.  It is 34816 bytes...</description>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Small.ydh</link>
		<pubDate>24 Feb 2009 11:45:00 +0300</pubDate>
		<title>Trojan-Downloader.Win32.Small.ydh</title>
	</item>
	<item>
		<description>This Trojan downloads another malicious program via the Internet and launches it on the victim machine without the user&amp;#8217;s knowledge or consent.  It is a Windows PE EXE file.  It is 9216 bytes in...</description>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Agent.ahoe</link>
		<pubDate>24 Feb 2009 11:32:00 +0300</pubDate>
		<title>Trojan-Downloader.Win32.Agent.ahoe</title>
	</item>
	<item>
		<description>This Trojan downloads other files via the Internet and launches them for execution on the victim machine.  The program is an HTML page which contains Java Script scenarios.  It is 1070 bytes in size.</description>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.JS.Agent.crh</link>
		<pubDate>20 Feb 2009 12:06:00 +0300</pubDate>
		<title>Trojan-Downloader.JS.Agent.crh</title>
	</item>
	<item>
		<description>This network worm spreads via local networks and removable storage media.  The program itself is a Windows PE DLL file.  The worm components vary in size from 155KB to 165KB. It is packed using UPX....</description>
		<link>http://www.securelist.com/en/descriptions/Net-Worm.Win32.Kido.ih</link>
		<pubDate>20 Feb 2009 11:41:00 +0300</pubDate>
		<title>Net-Worm.Win32.Kido.ih</title>
	</item>

</channel>
</rss>