General Trojans

Trojan.Vundo.EWZ

11-21-2008
The vundo trojan is usually a dll with a random name located in system32 directory. The length of the file name is usually 5 to 7 characters (depending on the version). The malware usually consists of 6 threads named Main thread, Protection thread, R... [More]

Views:0

Trojan.FakeAlert.ZV

11-21-2008
In the infection process an exectuable drops a dll to %windir%\System32\zgyhw.dll. This dll is then registered to load at startup using the following registry keys:HKLM\Software\Classes\CLSID\{2f199d0e-f3e7-41a7-a060-816c24cceea0}\InProcServer... [More]

Views:0

Trojan.FakeAlert.AAH

11-21-2008
When the process starts, it drops in %system% folder three files with random names. One of them is a .bmp file that is set as wallpaper, another one is a .scr and the last one is a executable file that is a copy of the virus.Then it is deletes itself... [More]

Views:0

Trojan.HTML.IFrame.F

11-21-2008
The malware is really just an invisible iframe inserted into clean webpages code, probably trough SQL Injection attacks similar to Trojan.Asprox infections, except for the fact that the infections occur at the end of the initially clean html code.The... [More]

Views:0

Trojan.FakeAlert.ACR

11-21-2008
When executed, this malware will drop the following files in %SYSDIR%:blphc9pvj0e1ac.scr - this file will be set as the new screensaver andit is detected by BitDefender as Trojan.FakeAlert.AAIlphc9pvj0e1ac.exe - a copy of the initial filephc9pvj0e1ac... [More]

Views:0

Trojan.FakeAlert.ABZ

11-21-2008
As the name says the malware displays fake alerts and pushes a rogue antivirus software (XP Antivirus)onto the affected computer.It creates the following files (Ill give a hint how the files are usually named and an example) : * %Program Files%rhc** ... [More]

Views:0

Trojan.Fakeav.BC

11-21-2008
The malware simulates an antivirus product that scans the computer, alerting the user that some threats were found but they cannot be removed unless the user registers (pays) for the full version of the product.In fact, all those infections are unrea... [More]

Views:0

Trojan.Disabler.N

11-21-2008
- The Trojan disables the Windows Firewall and Update services. More specifically, the dropped batch file adds two Registry keys in the Windows Update section of the Registry. Upon successfully completing the task, the batch script automatically remo... [More]

Views:0

Trojan.JS.Injector.A

11-21-2008
The script is a javascript piece of code that gets injected in every html file viewed by the infected user. The presence of the script is usually accompanied by Trojan.Vundo.FKW or Trojan.Vundo.FCB although other versions can be also responsable. Vun... [More]

Views:0

Trojan.Exploit.JS.RealPlr.S

11-21-2008
The malicious script written in JavaScript just puts on new layers of encryption over the well known recent exploits described in other malware like Exploit.SinaDloader.B, as well see later on.First lets describe this protection layer that the script... [More]

Views:0

Computer Virus Encyclopedia provides this virus information for people learn more, so a large number information for your reference.

©Virus-Encyclopedia.com All Rights Reserved.