IT Right
Thursday, March 11, 2010  | 
Virus Alerts

Mal/Spy-H
11 March 2010 22:28:30 Z

Troj/Banker-EWP
11 March 2010 22:28:30 Z

Troj/DNSChan-MW
11 March 2010 22:28:30 Z

Troj/FakeAV-AZT
11 March 2010 22:28:30 Z

Troj/PDFJs-IN
11 March 2010 22:28:30 Z
AVG/Grisoft Top Threats

Downadup/Conficker worm

First version of this worm is known from december 2008. Nowadays it has 300+ several variants. More information could be found in Virus Lab Blog.



I-Worm/Nuwar

Propagation method of new Nuwar variant is still similar to its precedessors. Spammed mails with link in IP format directs users to the worm web pages where the users are prompted to download one of the worm files with the name funny.exe. Names of other downloadable files are kickme.exe and foolsday.exe. AVG detects this threat as I-Worm/Nuwar.R.



I-Worm/Nuwar

New Nuwar variant spreading method is similar to Nuwar.L last month propagation. Spammed emails are brief containing link in IP format to currently working pages with worm. Compromised page code is changed and and as a result user is prompted to download file with worm. Downloaded filename is valentine.exe it's about 110 - 130kB long and it's detected by AVG as I-Worm/Nuwar.N



I-Worm/Nuwar

We have a new wave of spammed mail messages containing link directing users to website where the worm could be downloaded. Emails contains short text and IP address of currently working pages with worm. In this case downloaded filename is withlove.exe and it's about 115kB in size. Websites and worm files changes every few minutes. AVG detects withlove.exe as I-Worm/Nuwar.L.



Win32/Mabezat.A

In last few days we`ve registered a larger amount of PE files infected by this virus. Win32/Mabezat is polymorphic file infector which infects PE files. More information could be found in our Virus Encyclopedia.


Sophos Top 10

Troj/Invo-Zip
1 New Troj/Invo-Zip 12%

W32/Netsky
2 3 W32/Netsky 9.5%

Mal/EncPk-EI
3 Re-entry Mal/EncPk-EI 7.8%

Troj/Pushdo-Gen
4 2 Troj/Pushdo-Gen 6.3%

Troj/Agent-HFU
5 1 Troj/Agent-HFU 5.6%

I.T. Right has moved!  Please notate our new address: P.O. Box 160  Bath, MI 48808
Our phone number has remained the same  517-318-0350

I.T. Right has moved!  Please notate our new address: P.O. Box 160  Bath, MI 48808
Our phone number has remained the same  517-318-0350

Copyright (c) 2010 itright.com Privacy StatementTerms Of Use