Articles in the F-Secure Category

Backdoor:W32/Spyrat.D
Posted in F-Secure on 10 March 2011

A remote administration utility that bypasses normal security mechanisms to secretly control a program, computer or network.

Rogue:W32/SystemTool
Posted in F-Secure on 10 March 2011

This detection identifies a malicious program, typically used to deceive users into purchasing a fake application.

Adware:W32/ClickPotato.A
Posted in F-Secure on 10 March 2011

This program delivers advertising content to the user. It is usually annoying but harmless, unless it is combined with spyware or trackware.

Worm:ACAD/Kenilfe.A
Posted in F-Secure on 10 March 2011

The worm is a malicious AutoCAD program that propagates via removable drives. It also attempts to download Visual Basic Scripts from remote servers, if certain conditions are met.

Rogue:W32/SystemTool
Posted in F-Secure on 2 March 2011

This detection identifies a malicious program, typically used to deceive users into purchasing a fake application.

Backdoor:W32/Bohu.A
Posted in F-Secure on 27 January 2011

This program installs various files onto the system. Among the components installed are: a backdoor which connects to an external site to optain updates and other settings; and a component that monitors web traffic to various search engines in China and the domains of certain antivirus (AV) vendors.

Packed:W32/PeCan.A
Posted in F-Secure on 24 January 2011

This program is packed using a packer program associated with numerous other malware.

Backdoor:W32/Zxshell.A
Posted in F-Secure on 23 December 2010

Backdoor:W32/Zxshell.A is a DLL file with an exported function (”Install”), which is called to install the backdoor.

Rootkit:W32/Zxshell.B
Posted in F-Secure on 23 December 2010

Rootkit:W32/Zxshell.B is dropped by Backdoor:W32/Zxshell.A and basically functions as a protection mechanism for its main payload file.

Other:W32/False Positive
Posted in F-Secure on 10 December 2010

This detection was unintentionally triggered on a JavaScript file associated with Google Analytics. A Hydra exclusion for this detection (2010-12-10_01) was released at 0052 UTC on 10th December, followed by an Aquarius database update (2010-12-10_03) released at 0215 UTC which removes the detection entirely. Please ensure your database is updated to resolve this issue.