<rss version="2.0"><channel><title>Threat encyclopedia changes</title><link>http://www.microsoft.com/security/portal/</link><description>New and Updated antimalware definitions</description><language>en-us</language><lastBuildDate>BUILD_DATE</lastBuildDate><docs>http://blogs.law.harvard.edu/tech/rss</docs><generator>MMPC Portal v2.0</generator><managingEditor>mmpcfb@microsoft.com</managingEditor><webMaster>mmpcfb@microsoft.com</webMaster><ttl>60</ttl><item><title>Trojan:Win32/FakeCog</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							high	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Rogue	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Up to date protection in definition version  </strong></td>
							<td scope="col">
							1.69.665.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">Trojan:Win32/FakeCog is a fake security program that displays false infections in the system to prompt the user into buying it.</div>]]></description><pubDate>2009-12-01T07:01:00.907</pubDate><guid>Trojan:Win32/FakeCog@2009-12-01T07:01:00.907</guid><link>
				http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan:Win32/FakeCog</link></item><item><title>Trojan:Win32/FlyStudio.G!inf</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Generic	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Up to date protection in definition version  </strong></td>
							<td scope="col">
							1.51.360.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">Trojan:Win32/FlyStudio.G!inf is the detection for the autorun configuration file "<em>autorun.inf</em>" that launches a copy of the trojan <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Backdoor%3aWin32%2fFlyAgent.F">Backdoor:Win32/FlyAgent.F</a>. The trojan may be present as a file named "<em>recycle.exe</em>".</div>]]></description><pubDate>2009-12-01T05:19:32.150</pubDate><guid>Trojan:Win32/FlyStudio.G!inf@2009-12-01T05:19:32.150</guid><link>
				http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan:Win32/FlyStudio.G!inf</link></item><item><title>Worm:Win32/Antiman.K</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Program-specific	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Up to date protection in definition version  </strong></td>
							<td scope="col">
							Pending	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">Worn:Win32/Antiman.K is a worm that spreads via peer-to-peer (P2P) file-sharing programs. It deletes certain multimedia files from the infected system and downloads other multimedia files.</div>]]></description><pubDate>2009-11-27T09:09:04.203</pubDate><guid>Worm:Win32/Antiman.K@2009-11-27T09:09:04.203</guid><link>
				http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Worm:Win32/Antiman.K</link></item><item><title>Trojan:Win32/Skintrim.C</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Downloader	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Up to date protection in definition version  </strong></td>
							<td scope="col">
							1.71.104.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">Trojan:Win32/Skintrim.C is the detection for malware belonging to the <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32%2fSkintrim">Win32/Skintrim</a> and <a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan%3aWin32%2fWintrim">Win32/Wintrim</a> families.</div>]]></description><pubDate>2009-11-27T07:21:01.987</pubDate><guid>Trojan:Win32/Skintrim.C@2009-11-27T07:21:01.987</guid><link>
				http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan:Win32/Skintrim.C</link></item><item><title>Backdoor:Win32/Qakbot.C!dll</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Backdoor	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Up to date protection in definition version  </strong></td>
							<td scope="col">
							1.71.240.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">Backdoor:Win32/Qakbot.C!dll is a detection for the DLL component of <a xmlns="http://www.w3.org/1999/xhtml" href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Backdoor%3aWin32%2fQakbot.C">Backdoor:Win32/Qakbot.C</a>.</div>]]></description><pubDate>2009-11-26T08:32:39.507</pubDate><guid>Backdoor:Win32/Qakbot.C!dll@2009-11-26T08:32:39.507</guid><link>
				http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Backdoor:Win32/Qakbot.C!dll</link></item><item><title>Backdoor:Win32/Qakbot.C</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Backdoor	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Up to date protection in definition version  </strong></td>
							<td scope="col">
							1.71.240.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">Backdoor:Win32/Qakbot.C is a trojan backdoor that connects to a remote server, allowing an attacker to access the infected system. This backdoor trojan can perform several actions including steal user information and log user keystrokes.</div>]]></description><pubDate>2009-11-26T08:27:10.397</pubDate><guid>Backdoor:Win32/Qakbot.C@2009-11-26T08:27:10.397</guid><link>
				http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Backdoor:Win32/Qakbot.C</link></item><item><title>TrojanDownloader:Win32/Rochap.L</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Downloader	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Up to date protection in definition version  </strong></td>
							<td scope="col">
							1.69.638.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">TrojanDownloader:Win32/Rochap.L is a trojan that displays a video from the media site "youtube.com" while downloading and running a variant of Trojan:Win32/Rochap.</div>]]></description><pubDate>2009-11-25T21:51:32.890</pubDate><guid>TrojanDownloader:Win32/Rochap.L@2009-11-25T21:51:32.890</guid><link>
				http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=TrojanDownloader:Win32/Rochap.L</link></item><item><title>TrojanClicker:Win32/Yabector.B</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Generic	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Up to date protection in definition version  </strong></td>
							<td scope="col">
							1.71.269.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div align="left" xmlns="http://www.w3.org/1999/xhtml">TrojanClicker:Win32/Yabector.B is a program that notifies a web server of its presence without user consent. It may be bundled with an installation program as a file "<em>eBayShortcuts.exe</em>".</div>]]></description><pubDate>2009-11-25T09:57:35.307</pubDate><guid>TrojanClicker:Win32/Yabector.B@2009-11-25T09:57:35.307</guid><link>
				http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=TrojanClicker:Win32/Yabector.B</link></item><item><title>Exploit:HTML/CVE-2009-3672.A</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Generic	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Up to date protection in definition version  </strong></td>
							<td scope="col">
							Pending	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">Exploit:HTML/CVE-2009-3672.A is a detection for specially crafted HTML scripts that are designed to attempt to exploit the vulnerability described by <a href="http://www.microsoft.com/technet/security/advisory/977981.mspx">Microsoft Security Bulletin 977981</a>. This vulnerability affects Internet Explorer versions 6 and 7.</div>]]></description><pubDate>2009-11-25T09:55:58.050</pubDate><guid>Exploit:HTML/CVE-2009-3672.A@2009-11-25T09:55:58.050</guid><link>
				http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Exploit:HTML/CVE-2009-3672.A</link></item><item><title>Trojan:Win32/Vundo.gen!BP</title><description><![CDATA[
						<div>
						<table cellspacing="0" rules="all" border="1" id="ctl00_ctl00_pageContent_leftside_gvAddedThreats" style="border-collapse:collapse;">				
						<tr>
							<td scope="col"><strong>Alert Level  </strong></td>
							<td scope="col">
							severe	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Category </strong></td>
							<td scope="col">
							Generic	
							</td>
						</tr>
						<tr>
							<td scope="col"><strong>Up to date protection in definition version  </strong></td>
							<td scope="col">
							1.67.773.0	
							</td>
						</tr>
					 
						</table>
						</div>
					
						<div xmlns="http://www.w3.org/1999/xhtml"> </div><div align="left" xmlns="http://www.w3.org/1999/xhtml"><strong>Description : </strong></div>
					<div xmlns="http://www.w3.org/1999/xhtml">Trojan:Win32/Vundo.gen!BP is a generic detection for members of the <a xmlns="http://www.w3.org/1999/xhtml" href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Win32%2fVundo">Win32/Vundo</a> family, which delivers out-of-context pop-up advertisements to the computer on which it is installed.</div>]]></description><pubDate>2009-11-25T08:27:13.617</pubDate><guid>Trojan:Win32/Vundo.gen!BP@2009-11-25T08:27:13.617</guid><link>
				http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Trojan:Win32/Vundo.gen!BP</link></item></channel></rss>