<?xml version="1.0" encoding="iso-8859-1" ?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<atom:link href="http://www.securelist.com/en/rss/popularvirusdescriptions" rel="self" type="application/rss+xml" />
<title>Securelist / Descriptions</title>
<link>http://www.securelist.com/en/</link>
<description></description>
<lastBuildDate>04 Feb 2012 06:13:55 +0400</lastBuildDate>
<image>
<title>Securelist / Descriptions</title>
<url>http://www.securelist.com/en/rss/klogo.gif</url>
<link>http://www.securelist.com/en/</link>	
</image>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan downloads other malicious programs from the Internet and launches them for execution without the user's knowledge. It is a Windows dynamic library (PE EXE file). It is 53 248 bytes in...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Agent.dlyf</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Agent.dlyf</link>
		<pubDate>02 Feb 2012 18:01:00 +0400</pubDate>
		<title>Trojan-Downloader.Win32.Agent.dlyf</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 352 256 bytes in size. It is written in Visual Basic.

Installation

When launching,...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.VB.aeke</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.VB.aeke</link>
		<pubDate>02 Feb 2012 17:51:00 +0400</pubDate>
		<title>Trojan.Win32.VB.aeke</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 142 848 bytes in size. It is written in Delphi.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Smardf.mlt</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Smardf.mlt</link>
		<pubDate>02 Feb 2012 17:10:00 +0400</pubDate>
		<title>Trojan.Win32.Smardf.mlt</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>When the infected page is opened, Java class code starts to run, which leads to the following actions:

The following file is created and launched:


&amp;Ntilde;:\Windows\pay.reg

This causes a change in...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Java.Payphish.a</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Java.Payphish.a</link>
		<pubDate>01 Feb 2012 13:17:00 +0400</pubDate>
		<title>Trojan.Java.Payphish.a</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan provides a malicious user with remote access to the infected computer. It is a Windows application (PE EXE file). It is 365 568 bytes in size. It is written in Delphi.

Installation

Once...</description>
		<guid>http://www.securelist.com/en/descriptions/Backdoor.Win32.Delf.ugd</guid>
		<link>http://www.securelist.com/en/descriptions/Backdoor.Win32.Delf.ugd</link>
		<pubDate>01 Feb 2012 13:03:00 +0400</pubDate>
		<title>Backdoor.Win32.Delf.ugd</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>Once launched, the Trojan decrypts its body and then downloads files from the following URL addresses:


http://195.***.144.79/psyim_dfgjkeqw.exe
http://195.***.144.79/setup.exe
http:...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Genome.atab</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Genome.atab</link>
		<pubDate>01 Feb 2012 12:39:00 +0400</pubDate>
		<title>Trojan-Downloader.Win32.Genome.atab</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This exploit program uses vulnerabilities in Adobe Reader and Acrobat to execute itself on the user's computer. It is a PDF document containing XML Forms Architecture and Java Script. It is 26,393...</description>
		<guid>http://www.securelist.com/en/descriptions/Exploit.JS.Pdfka.dna</guid>
		<link>http://www.securelist.com/en/descriptions/Exploit.JS.Pdfka.dna</link>
		<pubDate>26 Jan 2012 18:15:00 +0400</pubDate>
		<title>Exploit.JS.Pdfka.dna</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan downloads other malicious programs from the Internet and launches them for execution without the user's knowledge. It is a Windows application (PE EXE file). It is 21 504 bytes in size....</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Genome.asvq</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Genome.asvq</link>
		<pubDate>26 Jan 2012 15:41:00 +0400</pubDate>
		<title>Trojan-Downloader.Win32.Genome.asvq</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan downloads other malicious programs from the Internet and launches them for execution without the user's knowledge. It is a Windows application (PE EXE file). It is 21 504 bytes in size....</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Genome.asut</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-Downloader.Win32.Genome.asut</link>
		<pubDate>26 Jan 2012 14:54:00 +0400</pubDate>
		<title>Trojan-Downloader.Win32.Genome.asut</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>The Trojan creates a file named &quot;Deleteme.bat&quot; in its working directory and launches it for execution:

%WorkDir%\Deleteme.bat

The launched file deletes the Trojan's original body and deletes...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Slefdel.fpk</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Slefdel.fpk</link>
		<pubDate>26 Jan 2012 14:42:00 +0400</pubDate>
		<title>Trojan.Win32.Slefdel.fpk</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 18 944 bytes in size. It is written in C++.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Sasfis.rer</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Sasfis.rer</link>
		<pubDate>25 Jan 2012 17:55:00 +0400</pubDate>
		<title>Trojan.Win32.Sasfis.rer</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>Once launched, the Trojan decrypts and extracts the following file from its body to the current user's temporary directory:

%Temp%&amp;lt;rnd1&amp;gt;.tmp

where &amp;lt;rnd1&amp;gt; is a random set of numbers and...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Sasfis.ole</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Sasfis.ole</link>
		<pubDate>25 Jan 2012 17:46:00 +0400</pubDate>
		<title>Trojan.Win32.Sasfis.ole</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 16 384 bytes in size. It is written in C++.</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Qhost.nhn</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Qhost.nhn</link>
		<pubDate>25 Jan 2012 17:37:00 +0400</pubDate>
		<title>Trojan.Win32.Qhost.nhn</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>&amp;Ograve;&amp;eth;&amp;icirc;&amp;yuml;&amp;iacute;&amp;ntilde;&amp;ecirc;&amp;agrave;&amp;yuml; &amp;iuml;&amp;eth;&amp;icirc;&amp;atilde;&amp;eth;&amp;agrave;&amp;igrave;&amp;igrave;&amp;agrave;, &amp;iuml;&amp;icirc;&amp;eth;&amp;agrave;&amp;aelig;&amp;agrave;&amp;thorn;&amp;ugrave;&amp;agrave;&amp;yuml;...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan-SMS.J2ME.Agent.s</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan-SMS.J2ME.Agent.s</link>
		<pubDate>24 Jan 2012 15:51:00 +0400</pubDate>
		<title>Trojan-SMS.J2ME.Agent.s</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>The Trojan creates a copy of the original &quot;hosts&quot; file under the following name:

C:\h.tmp

The Trojan writes the following string in the file created:

85.***.206.115 u070***010u.com

It replaces the...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Qhost.mxb</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Qhost.mxb</link>
		<pubDate>24 Jan 2012 12:40:00 +0400</pubDate>
		<title>Trojan.Win32.Qhost.mxb</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 49 162 bytes in size. It is written in Delphi.

Installation

Once launched, the...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.fadd</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.fadd</link>
		<pubDate>24 Jan 2012 12:31:00 +0400</pubDate>
		<title>Trojan.Win32.Agent.fadd</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 48 650 bytes in size. It is written in Delphi.

Installation

Once launched, the...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.ezqu</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.ezqu</link>
		<pubDate>24 Jan 2012 12:20:00 +0400</pubDate>
		<title>Trojan.Win32.Agent.ezqu</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 47 114 bytes in size. It is written in Delphi.

Installation

Once launched, the...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.ezqk</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.ezqk</link>
		<pubDate>23 Jan 2012 16:18:00 +0400</pubDate>
		<title>Trojan.Win32.Agent.ezqk</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>This Trojan delivers a malicious payload to the user's computer. It is a Windows application (PE EXE file). It is 49 162 bytes in size. It is written in Delphi.

Installation

Once launched, the...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.ezqg</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.ezqg</link>
		<pubDate>23 Jan 2012 16:11:00 +0400</pubDate>
		<title>Trojan.Win32.Agent.ezqg</title>
	</item>
	<item>
		<author>webmaster@securelist.com ()</author>
		<description>Once launched, the Trojan decrypts and extracts the following file from its body to the current user's temporary directory:

%Temp%&amp;lt;rnd1&amp;gt;.tmp

where &amp;lt;rnd1&amp;gt; is a random set of numbers and...</description>
		<guid>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.dfab</guid>
		<link>http://www.securelist.com/en/descriptions/Trojan.Win32.Agent.dfab</link>
		<pubDate>23 Jan 2012 14:33:00 +0400</pubDate>
		<title>Trojan.Win32.Agent.dfab</title>
	</item>

</channel>
</rss>



