Skip to main content
22 entries found. Displaying page 1 of 2.
Updated on Dec 08, 2006
Alert level: severe
Updated on Jan 08, 2010
Trojan:WinNT/Bubnix.D is a kernel mode trojan that masks its presence on an affected computer by blocking registry and file access to itself. The trojan may report its installation to a remote server and download and execute arbitrary files.
Alert level: severe
Updated on Dec 07, 2006
Alert level: severe
Updated on Jul 30, 2010
Trojan:WinNT/Bubnix.I is a trojan that is downloaded and installed by other malware. It sends out spam email messages based on data received from a remote server.
Alert level: severe
Updated on Dec 13, 2007
Trojan:Win32/Srizbi.gen is a generic detection for Trojans that connect to remote sites to retrieve spam messages. It also uses rootkit techniques in order to hide itself from the affected user.
Alert level: severe
Updated on Apr 16, 2008
Spammer:WinNT/Srizbi.gen is a generic detection for Trojans that connect to remote sites to retrieve spam messages. It also uses rootkit techniques in order to hide itself from the affected user.
Alert level: severe
Updated on Nov 12, 2010
Backdoor:WinNT/Festi.C is a backdoor trojan that allows limited remote access and control. The trojan connects to a remote website and retrieves instructions and commands from a remote attacker. The commands could instruct Backdoor:WinNT/Festi.C to distribute spam.
Alert level: severe
Updated on Nov 26, 2007
TrojanDropper:Win32/Cutwail.E is the generic detection for a Trojan family that drops a system driver to conceal itself, and downloads additional malicious programs onto the infected computer. Downloaded files may be executed from disk or injected directly into another process. The functionality of the files that are downloaded may change, but Win32/Cutwail usually downloads a Trojan which is able to send spam. Win32/Cutwail also uses rootkit and other defensive techniques to avoid detection and removal.
Alert level: severe
Updated on Nov 23, 2007

VirTool:WinNT/Livuto.gen is a trojan that prevents access to certain security-related websites by modifying your Windows Hosts file. It also changes your Internet Explorer start page. It may be installed by TrojanDropper:Win32/Livuto.

Alert level: severe
Updated on Nov 29, 2007
VirTool:WinNT/Tibs.gen!A is generic detection for drivers used across multiple pieces of malware affiliated with the 'Tibs' malware distribution network. WinNT/Tibs malware uses rootkit methods to hide its presence on an infected computer.
Alert level: severe
Updated on Aug 21, 2008
VirTool:WinNT/Laqma.A is a detection for a rootkit driver which is dropped by TrojanSpy:Win32/Laqma.B. It is primarily used to hide the malware’s processes and files from an affected user
Alert level: severe
Updated on May 11, 2009
Virus:Win32/Cutwail.F is a member of Win32/Cutwail - a multi-component family of malware that downloads and executes arbitrary files. This functionality is mostly used to install additional Cutwail components, and other malware on an affected machine. In general, the Cutwail family is used to compromise machines and direct them in various ways at the attacker's will, usually for monetary gain. This could include using the affected machine to distribute additional malware, send spam, generate 'pay per click' advertising revenue, harvest e-mail addresses, and break captchas. Its components are varied, but include trojan downloaders and droppers, spammers, rootkits and viruses. Cutwail also employs a rootkit and other defensive techniques to avoid detection and removal.
Alert level: severe
Updated on May 19, 2009
Trojan:Win32/Opachki.A is a trojan that runs at Windows start and redirects search queries while monitoring user Internet traffic.
Alert level: severe
Updated on Oct 30, 2009
VirTool:WinNT/Bancos.A is a driver installed by Win32/Bancos to detect and remove installed components of a security application used by Brazilian banks to protect customers from Internet banking fraud.
Alert level: severe
Updated on Mar 18, 2010

Virus:Win32/Sirefef.A is a component of Win32/Sirefef - a multi-component family of malware that moderates your Internet experience by changing search results and generating pay-per-click advertising revenue for its controllers. The family consists of multiple parts that perform different functions, such as downloading updates and additional components, hiding existing components, or performing a payload.

Caution: Win32/Sirefef is a dangerous threat that uses advanced stealth techniques in order to hinder its detection and removal. If you are infected with Sirefef, we recommend you take the following steps to remove this threat from your computer:

Before you begin you will need:

- A computer that is not infected and is connected to the Internet. You will use this computer to download a copy of the Microsoft Safety Scanner
- A blank CD, DVD or USB drive. You will use this CD, DVD or USB drive to run the Scanner on your infected computer 

  1. Download a copy of the Microsoft Safety Scanner from a clean, uninfected computer
  2. Save a copy of the Scanner on a blank CD, DVD, or USB drive
  3. Restart the infected computer
  4. Insert the CD, DVD, or USB drive into your infected computer and run the Scanner
  5. Let the Scanner clean your computer and remove any infections it finds

After running the Scanner, ensure that your antivirus product is up-to-date. You can update Microsoft security products by downloading the latest definitions at this link: Get the latest definitions.

As a consequence of being infected with this threat, you may need to repair and reconfigure some Windows security features. Please see Additional remediation steps in this entry for more information.

Alert level: severe
Updated on Jul 14, 2010
Trojan:WinNT/Stuxnet.B is a trojan component that loads other malware and is installed by TrojanDropper:Win32/Stuxnet.A.
Alert level: severe
Updated on Aug 26, 2010
TrojanDropper:Win32/Resmu.A is a trojan that drops another malware in the computer.
Alert level: severe
Updated on Aug 27, 2010
Trojan:Win32/Resmu.A!rootkit is a kernel-mode rootkit that is installed by TrojanDropper:Win32/Resmu.A.
Alert level: severe
Updated on Sep 24, 2010
TrojanDropper:Win32/Otlard.A is a trojan that drops and registers Trojan:WinNT/Otlard.B as a service.
Alert level: severe
Updated on Nov 03, 2010
TrojanDropper:Win32/Festi.C is a trojan that installs Backdoor:WinNT/Festi.C, a trojan backdoor that allows backdoor access and control to an infected computer.
Alert level: severe