Home Site Map
6/13: DwnLdr-DCY a Windows Trojan

Subject:
6/13: DwnLdr-DCY a Windows Trojan
Body:



*********************************************************************

eSecurityPlanet.com Is Sponsored By
Dr Dobbs

*********************************************************************
http://esecurityplanet.com/
Tuesday, June 13, 2006

eSecurityPlanet is part of the Earthweb network

All newsletters are sent from the domain "internet.com." Please use this domain name (not
the entire "from" address, which varies) when configuring e-mail or spam filter rules, if
you use them.

*********************************************************************

*********************************************************************
TRENDS
*********************************************************************

1. 6/13: DwnLdr-DCY a Windows Trojan
Troj/DwnLdr-DCY is a Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,5pne,22xx,gd02,3wbp

------------------------------------------------------------
2. 6/13: BlackAngel.B Worm Disables Security Processes
BlackAngel.B is a worm that attempts to disable the processes belonging to several
security tools, such as antivirus programs and firewalls, among others.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,idl2,fo3w,gd02,3wbp

------------------------------------------------------------
3. 6/13: MultiDropper-QT Drops, Executes Trojan Downloader
MultiDropper-QT is a multidropper that is intended to drop and execute a Trojan
downloader and worm on the target machine.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,951k,kxsh,gd02,3wbp

------------------------------------------------------------
4. 6/13: Rustock.C Backdoor Arrives as Dropped File
Bkdr_Rustock.C is a backdoor that usually arrives as a file dropped by other malware or
as a file downloaded unknowingly by a user when visiting malicious Web sites.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,4jrc,4m9c,gd02,3wbp

------------------------------------------------------------
5. 6/13: Backdoor.Daserf Trojan Dropped by .doc File
Backdoor.Daserf is a Trojan horse that opens a back door on the compromised computer, and
is reportedly dropped by a .doc file that uses a 0-day exploit.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,geaw,gilv,gd02,3wbp

------------------------------------------------------------
6. 6/13: Backdoor.Eterok.C Trojan Opens Back Door
Backdoor.Eterok.C is a Trojan horse that opens a back door on the compromised computer.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,gbhl,k1bl,gd02,3wbp

------------------------------------------------------------
7. 6/13: Zapchas-BM Trojan Gives Intruder Access
Troj/Zapchas-BM is a Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,c9yq,2kc3,gd02,3wbp

/-------------------------------------------------------------------

Dr. Dobb's Architecture & Design World 2006 Discount Offer!
July 17-20 in Chicago, IL -- Featuring over 70 educational sessions,
Dr. Dobb's Architecture & Design World delivers relevant training
you need taught by the top experts in the industry.
Register by June 9 with the code 6ADEVX & save up to $300!
Details are available at
http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,g34x,16li,gd02,3wbp

--------------------------------------------------------------adv.-/

------------------------------------------------------------
8. 6/13: Melo-E Worm Deletes Files on A: and C: Drives
W32/Melo-E is a worm for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,ediy,7rl8,gd02,3wbp

------------------------------------------------------------
9. 6/13: Mailbot-AJ Trojan Targets Windows
Troj/Mailbot-AJ is a Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,moj,31sk,gd02,3wbp

------------------------------------------------------------
10. 6/13: Zlob-NW a Downloader Trojan
Troj/Zlob-NW is a downloader Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,6fkr,14ms,gd02,3wbp

------------------------------------------------------------
11. 6/13: ZlobDrop-U Trojan Create Files Upon Installation
Troj/ZlobDrop-U is a Trojan dropper for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,dq8x,lcwp,gd02,3wbp

------------------------------------------------------------
12. Creating a Culture of Security
Fostering a secure environment takes work and money. More than anything, though, it takes
commitment by management.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,j6sv,19db,gd02,3wbp

------------------------------------------------------------
13. Microsoft Makes Security The 'ForeFront'
At Tech Ed, officials unveil the company's new security brand and a plan to prepare for
the Web services wave.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,ds6m,c9n3,gd02,3wbp

------------------------------------------------------------
14. 6/12: Downloader-AWU Trojan Pulls Files From Site
Downloader-AWU is a Trojan that serves as a downloading/ updating component.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,7l1w,e9km,gd02,3wbp

------------------------------------------------------------
15. 6/12: PE_Detnat.E a File Infector
PE_Detnat.E is a file infector that propagates through network shares.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,4ob,73ut,gd02,3wbp

------------------------------------------------------------
16. 6/12: Skowr.A Trojan Encrypts Files
Trend Micro has received reports about Troj_Skowr.A spreading in the wild, especially in
Europe.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,314l,c1ul,gd02,3wbp

------------------------------------------------------------
17. 6/12: Detnat.G Virus Infects Executable Files
W32.Detnat.G is a virus that searches network shares and infects executable files.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,3ifv,5zr3,gd02,3wbp

------------------------------------------------------------
18. 6/12: Trojan.Skowr Encrypts Files, Ends Processes
Trojan.Skowr is a Trojan horse that encrypts files, ends processes, overwrites the hosts
file, disables Task Manager and drops files on the compromised computer.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,kbpw,gtjf,gd02,3wbp

------------------------------------------------------------
19. 6/12: JS.Yamanner Worm Exploits Yahoo Email Flaw
JS.Yamanner@m is a worm that is written in JavaScript.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,fs97,562x,gd02,3wbp

------------------------------------------------------------
20. 6/12: Small-BWB a Downloader Trojan
Troj/Small-BWB is a downloader Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,cxk,c7sy,gd02,3wbp

------------------------------------------------------------
21. 6/12: Zapchas-BL a Multi-Component Trojan
Troj/Zapchas-BL is a multi-component backdoor Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,5rz,iydm,gd02,3wbp

------------------------------------------------------------
22. 6/12: Opanki-BT Worm Gives Intruder Access
W32/Opanki-BT is a worm with backdoor functionality for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,ig5z,alng,gd02,3wbp

------------------------------------------------------------
23. Security Fixes in Microsoft's "Patch Tuesday"
Updates to Windows, Exchange and Office on Tap.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,c8sv,74ny,gd02,3wbp

------------------------------------------------------------
24. 6/9: Rbot-ECP Worm Exploits Weak Passwords
W32/Rbot-ECP is a network worm with backdoor functionality for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,fla8,4ks0,gd02,3wbp

------------------------------------------------------------
25. 6/9: Nopir.D Worm Spreads Via File Sharing
W32.Nopir.D is a worm that spreads through file-sharing networks.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,gv0,5h76,gd02,3wbp

------------------------------------------------------------
26. 6/9: GPCoder Trojan Encrypts Documents
GPCoder is a Trojan that encrypts documents, depending on the file extension, and then
attempts to extort money from the victim in order for them to obtain a decryptor tool to
recover the documents.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,ipuu,djxr,gd02,3wbp

------------------------------------------------------------
27. 6/9: Detnat.C a Parasitic File Infector and Worm
W32/Detnat.C is a parasitic file infector and network worm that searches local drives and
network shares for executable files and infects them.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,clko,ebg2,gd02,3wbp

------------------------------------------------------------
28. 6/9; Timeserv a Mass-Mailing Worm
W32.Timeserv@mm is a mass-mailing worm that opens a back door and sends emails to
addresses gathered from the compromised computer.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,fge8,k18m,gd02,3wbp

------------------------------------------------------------
29. 6/9: Bagle-JI Worm Targets Windows
W32/Bagle-JI is a worm for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,bq1i,8t7q,gd02,3wbp

------------------------------------------------------------
30. 6/9: Rbot-ECQ Worm Has Backdoor Functions
W32/Rbot-ECQ is a network worm with backdoor functionality for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,gfhx,37k,gd02,3wbp

------------------------------------------------------------
31. 6/9: Backdr-C Trojan Gives Intruder System Access
Troj/Backdr-C is a backdoor Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,gmy4,ldnd,gd02,3wbp

------------------------------------------------------------
32. 6/9: Banloa-AFG Tojan Downloads Other Malicious Code
Troj/Banloa-AFG is a Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,hzuj,5img,gd02,3wbp

------------------------------------------------------------
33. Ringing (False?) Alarm Bells
IBM and HP are launching disaster recovery services as the hurricane season kicks off.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,ctut,5rbu,gd02,3wbp

------------------------------------------------------------
34. 6/8: PE_Detanat.D File Infector Spreads Via Shares
PE_Detanat.D is a file infector propagates through network shares.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,ecs3,5v52,gd02,3wbp

------------------------------------------------------------
35. 6/8: PornMagPass Adware Program Downloads Malware
PornMagPass is an adware program that downloads the following malware to the affected
computer: Adware/SpywareQuake.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,6xmu,91u9,gd02,3wbp

------------------------------------------------------------
36. 6/8: Sdbot-BUK Worm Exploits Multiple Flaws
W32/Sdbot-BUK is a worm for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,kce3,8bkk,gd02,3wbp

------------------------------------------------------------
37. 6/8: BackDoor.CGX Trojan Injects DLL Into .exe File
BackDoor.CGX is a backdoor Trojan that attempts to inject a DLL into the explorer.exe
then making a connection to a remote site.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,9o9o,1ugg,gd02,3wbp

------------------------------------------------------------
38. 6/8: SymbOS/Cabir.Q Virus Targets Series 60 Phones
SymbOS/Cabir.Q is a variant of the SymbOS/Cabir virus that affects Symbian Series 60 cell
phones.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,hsbv,98zx,gd02,3wbp

------------------------------------------------------------
39. 6/8: Dropper.BCU Trojan Arrives as Attachment
Troj_Dropper.BCU usually arrives on a system as an attachment to a spammed email message.


http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,kbtk,ajt1,gd02,3wbp

------------------------------------------------------------
40. 6/8: SB.Starbugs Macro Virus Written in StarBasic
SB.Starbugs a macro virus written in StarBasic that spreads through StarOffice and
OpenOffice documents.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,8gor,9qjk,gd02,3wbp

------------------------------------------------------------
41. 6/8: Perl.Lekbot Trojan Can Perform DDoS Attack
Perl.Lekbot is a Trojan horse that is written in Perl that can be used to perform a
Distributed Denial of Service attack.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,cr9f,m31j,gd02,3wbp

------------------------------------------------------------
42. 6/8: Trojan.Silm Exploits Flaw to Download Worm
Trojan.Silm is a Trojan horse that exploits a vulnerability to download a worm.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,5w6v,cyje,gd02,3wbp

------------------------------------------------------------
43. 6/8: Fijjy.A Worm Spreads Via Network Shares
W32.Fijjy.A is a worm that spreads through network shares and downloads and executes
remote files onto the compromised computer.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,8c3c,2y1u,gd02,3wbp

------------------------------------------------------------
44. 6/8: GPCode-A Trojan Encrypts User Documents
Troj/GPCode-A is a Trojan that encrypts user documents.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,2bdl,cdt2,gd02,3wbp

------------------------------------------------------------
45. 6/8: Tilebot-FD Worm Also a Backdoor Trojan
W32/Tilebot-FD is a worm and IRC backdoor Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,fepr,430a,gd02,3wbp

------------------------------------------------------------
46. 6/8: Spyjack-O a Windows Trojan
Troj/Spyjack-O is a Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,f5qu,6pr8,gd02,3wbp

------------------------------------------------------------
47. Laptop Thefts Highlight SMB Need for Data Security
Ernst & Young and Hotels.com are the latest corporations to suffer customer data loss
through a stolen notebook. Small businesses should stand up and take action.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,1wq1,9tem,gd02,3wbp

------------------------------------------------------------
48. McAfee Snags Preventsys, Releases Falcon
With Falcon, McAfee products will all be on a subscription-fee basis.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,lset,jwe4,gd02,3wbp

------------------------------------------------------------
49. 6/7: PGPCoder.D Trojan Encrypts Files
Troj_PGPCoder.D is a Trojan that may arrive as a file downloaded by TROJ_SMALL.AIT.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,b8e9,dpgt,gd02,3wbp

------------------------------------------------------------
50. 6/7: Tigs Worm Spreads Via Floppy and Shared Folders
W32/Tigs.worm is a worm that propagates via floppy and shared folders.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,a7wz,9iki,gd02,3wbp

------------------------------------------------------------
51. 6/7: Tored.A a Malicious Macro Script
W2KM_Tored.A is a malicious macro script that usually arrives as a file dropped by other
malware or as a file downloaded unknowingly by a user when visiting malicious Web sites.


http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,k9me,8lv4,gd02,3wbp

------------------------------------------------------------
52. 6/7: SymbOS.Commdropper.E Trojan Hits Cell Phones
SymbOS.Commdropper.E is a Trojan horse that affects Symbian series 60 phones.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,g3g3,d0dx,gd02,3wbp

------------------------------------------------------------
53. 6/7: Trojan.Emcodec.D Drops, Executes Other Trojan
Trojan.Emcodec.D is a Trojan horse that drops and executes a copy of a member of the
Downloader family of Trojans.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,lo11,1dr0,gd02,3wbp

------------------------------------------------------------
54. 6/7: Backdoor.Haxdoor.L Trojan Opens Covert Proxy
Backdoor.Haxdoor.L is a Trojan horse that opens a covert proxy on the compromised
computer.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,8spn,bi3o,gd02,3wbp

------------------------------------------------------------
55. 6/7: Tored.A Macro Virus Infects Word Documents
W97M.Tored.A is a macro virus that infects Microsoft Word documents and drops other
threats onto the compromised computer.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,b9qy,lafz,gd02,3wbp

------------------------------------------------------------
56. 6/7: Banloa-ADN Trojan Communicates With Server
Troj/Banloa-ADN is a downloading Trojan for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,kgx4,hi8p,gd02,3wbp

------------------------------------------------------------
57. 6/7: Zasran-E a Mass-Mailing Worm
W32/Zasran-E is a mass-mailing worm with backdoor functionality for the Windows platform.


http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,and9,28lv,gd02,3wbp

------------------------------------------------------------
58. 6/7: Sdbot-BUQ Worm Exploits Several Flaws
W32/Sdbot-BUQ is a worm for the Windows platform.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,7zvb,c9jo,gd02,3wbp

------------------------------------------------------------

*********************************************************************



*********************************************************************
PRODUCTS AND SERVICES
*********************************************************************

*********************************************************************


*********************************************************************
VIEWS
*********************************************************************

1. Updating our Thinking on Software Updates
eSecurityPlanet columnist Ken van Wyk looks at the issue of software updates --
particularly the lack there of for mobile devices.

http://nl.internet.com/ct.html?rtr=on&s=1,2im4,1,ll7n,mfcu,gd02,3wbp

------------------------------------------------------------

*********************************************************************


*********************************************************************
Earthweb.com's Family of Online Services for IT Insiders
*********************************************************************

IT MANAGEMENT
http://itmanagement.earthweb.com/
HARDWARE & SYSTEMS
http://hardware.earthweb.com/
NETWORKING & COMMUNICATIONS
http://networking.earthweb.com/
WEB DEVELOPMENT
http://webdeveloper.earthweb.com/
SOFTWARE DEVELOPMENT
http://softwaredev.earthweb.com/

Get the latest technical tips, tools, and resources via Earthweb's
extensive collection of free e-mail newsletters!

*********************************************************************

You are subscribed to the eSecurity Planet newsletter as 1@informationstreams.com. To unsubscribe from eSecurity Planet please send an email to: u-1cabc-ba5d22c665-1768@nl.internet.com

To manage your newsletter subscription preferences, visit this location: http://nl.internet.com/profilepage.html?uid=ba5d22c665&eid=14470072

To unsubscribe via postal mail, please contact us at:

Jupitermedia Corp.
Attn: Newsletter Subscription Dept.
475 Park Avenue South
New York, NY 10016

Please include the email address which you have been contacted with.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

This email is powered by EmailLabs (http://www.emaillabs.com)
Contact us for a FREE demo
Date: 2006-06-13 - 18:40:10

Back