<rss version="2.0"><channel><title>Threat encyclopedia changes</title><link>http://www.microsoft.com/security/portal/</link><description>New and Updated antimalware definitions</description><language>en-us</language><lastBuildDate>Mon, 28 May 2012 21:36:56 -07:00</lastBuildDate><docs>http://blogs.law.harvard.edu/tech/rss</docs><generator>MMPC Portal v2.0</generator><managingEditor>mmpcfb@microsoft.com</managingEditor><webMaster>mmpcfb@microsoft.com</webMaster><ttl>60</ttl><item><title>Trojan:Win32/Mediyes.D</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Generic	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Protection starting from: </strong></td>
							<td scope="col">
							1.125.921.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">
<p xmlns="http://www.w3.org/1999/xhtml"><span class="notranslate">Trojan:Win32/Mediyes.D</span> is a <span class="notranslate">DLL</span> component of the <span class="notranslate">Mediyes</span> family, a multi-component family that steals your sensitive information from websites you visit.</p>
</div>]]></description><pubDate>Mon, 28 May 2012 06:31:00 PDT</pubDate><guid>Trojan:Win32/Mediyes.D@Mon, 28 May 2012 06:31:00 PDT</guid><link>
				/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan:Win32/Mediyes.D</link></item><item><title>Backdoor:Win32/Glacid.A</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Backdoor	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Protection starting from: </strong></td>
							<td scope="col">
							1.125.1048.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml"><span class="notranslate">Backdoor:Win32/Glacid.A</span> is a trojan that&#160;allows unauthorized access and control of your computer. It could connect to a&#160;command and control (C&#38;C) server to receive commands to perform certain payloads, such&#160;as remote file execution, data theft and downloading other malware.&#160;</div>]]></description><pubDate>Mon, 28 May 2012 06:29:24 PDT</pubDate><guid>Backdoor:Win32/Glacid.A@Mon, 28 May 2012 06:29:24 PDT</guid><link>
				/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Backdoor:Win32/Glacid.A</link></item><item><title>Worm:Win32/Gamarue.I</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Removable Drives	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Protection starting from: </strong></td>
							<td scope="col">
							1.127.836.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">
<p xmlns="http://www.w3.org/1999/xhtml"><span class="notranslate">Worm:Win32/Gamarue.I</span> is malware that may spread to other computers via removable drives. It also communicates with a remote server to report infection of your computer and to download arbitrary files.</p>
</div>]]></description><pubDate>Mon, 28 May 2012 06:18:33 PDT</pubDate><guid>Worm:Win32/Gamarue.I@Mon, 28 May 2012 06:18:33 PDT</guid><link>
				/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm:Win32/Gamarue.I</link></item><item><title>TrojanDownloader:Win32/Deyjalil.A</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Downloader	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Protection starting from: </strong></td>
							<td scope="col">
							1.127.696.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">
<p xmlns="http://www.w3.org/1999/xhtml"><span class="notranslate">TrojanDownloader:Win32/Deyjalil.A</span> is a cross-browser plugin used to implement the programming framework called <em><span class="notranslate">Lilyjade</span></em>. It takes advantage of the <span class="notranslate"><em>CrossRider</em> JavaScript</span> framework in order to push unwanted content or websites in the infected system.</p>
</div>]]></description><pubDate>Fri, 25 May 2012 09:10:01 PDT</pubDate><guid>TrojanDownloader:Win32/Deyjalil.A@Fri, 25 May 2012 09:10:01 PDT</guid><link>
				/security/portal/Threat/Encyclopedia/Entry.aspx?Name=TrojanDownloader:Win32/Deyjalil.A</link></item><item><title>Trojan:Win32/Rootkit.W</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Rootkit-Stealth	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Protection starting from: </strong></td>
							<td scope="col">
							1.125.1435.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">
<p xmlns="http://www.w3.org/1999/xhtml"><span class="notranslate">Trojan:Win32/Rootkit.W</span> is a trojan that may steal sensitive information by monitoring certain processes and visited websites.</p>
</div>]]></description><pubDate>Fri, 25 May 2012 03:18:03 PDT</pubDate><guid>Trojan:Win32/Rootkit.W@Fri, 25 May 2012 03:18:03 PDT</guid><link>
				/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan:Win32/Rootkit.W</link></item><item><title>Trojan:Win32/Meroweq.A</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Generic	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Protection starting from: </strong></td>
							<td scope="col">
							1.127.470.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml" align="left"><span class="notranslate">Trojan:Win32/Meroweq.A</span> is a malicious program that is unable to spread of its own accord. It may perform a number of actions of an attacker's choice on an affected computer.</div>]]></description><pubDate>Fri, 25 May 2012 03:17:13 PDT</pubDate><guid>Trojan:Win32/Meroweq.A@Fri, 25 May 2012 03:17:13 PDT</guid><link>
				/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan:Win32/Meroweq.A</link></item><item><title>Trojan:JS/Iframe.BC</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Generic	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Protection starting from: </strong></td>
							<td scope="col">
							1.125.15.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml"><p xmlns="http://www.w3.org/1999/xhtml"><span class="notranslate">Trojan:JS/Iframe.BC</span> is a malicious <span class="notranslate">JavaScript</span> file embedded in malicious or hacked webpages. If you visit a website containing this malicious JavaScript, it may redirect you to another website that contains other malware.</p></div>]]></description><pubDate>Fri, 25 May 2012 03:16:34 PDT</pubDate><guid>Trojan:JS/Iframe.BC@Fri, 25 May 2012 03:16:34 PDT</guid><link>
				/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan:JS/Iframe.BC</link></item><item><title>Backdoor:Win32/Spycos.B</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Backdoor	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Protection starting from: </strong></td>
							<td scope="col">
							1.125.597.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">
<div xmlns="http://www.w3.org/1999/xhtml"><span class="notranslate">Backdoor:Win32/Spycos.B</span> is a trojan that allows unauthorized remote access to your computer. The trojan could steal your login credentials for online banking&#160;and web-based email services. The trojan may also lower your computer's security by disabling certain security software services.</div>
</div>]]></description><pubDate>Thu, 24 May 2012 18:43:16 PDT</pubDate><guid>Backdoor:Win32/Spycos.B@Thu, 24 May 2012 18:43:16 PDT</guid><link>
				/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Backdoor:Win32/Spycos.B</link></item><item><title>TrojanDownloader:Win32/Bradop.A</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Downloader	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Protection starting from: </strong></td>
							<td scope="col">
							1.127.519.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml"><p xmlns="http://www.w3.org/1999/xhtml"><span class="notranslate">TrojanDownloader:Win32/Bradop.A</span> is the downloader component of the <span class="notranslate">Win32/Bradop</span> family of trojans that steal online banking credentials credentials for customers of Brazilian banks, as well as email credentials. It is distributed via spam email messages that contain links to its download.</p></div>]]></description><pubDate>Thu, 24 May 2012 08:41:26 PDT</pubDate><guid>TrojanDownloader:Win32/Bradop.A@Thu, 24 May 2012 08:41:26 PDT</guid><link>
				/security/portal/Threat/Encyclopedia/Entry.aspx?Name=TrojanDownloader:Win32/Bradop.A</link></item><item><title>Virus:Win32/Quervar.A</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							File	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Protection starting from: </strong></td>
							<td scope="col">
							1.127.519.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">
<p xmlns="http://www.w3.org/1999/xhtml"><span class="notranslate">Virus:Win32/Quervar.A</span> is a virus that infects specific <span class="notranslate">Microsoft Office</span> document files and executable files.</p>
</div>]]></description><pubDate>Thu, 24 May 2012 01:54:07 PDT</pubDate><guid>Virus:Win32/Quervar.A@Thu, 24 May 2012 01:54:07 PDT</guid><link>
				/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Virus:Win32/Quervar.A</link></item></channel></rss>
