Win32/Virut

There were several new variants of Virut parasitic infector discovered in last days. We’ve added detection routines for this threat in last program update 7.5.484 so please update your AVG. Win32/Virut is polymorphic file infector which infects PE files with .exe extension.

I-Worm/Stration

This worm spreads by e-mail as an attachment or as a hyperlink in ICQ message. On the infected computer virus harvests e-mail addresses or ICQ contacts to which it sends its copies. Virus can download and install other unwanted programs from the Internet.

Exploit.ANI

There is a new breed of threat against a vulnerability known for over a year in Cursor and Icon Format Handling described in MS05-002. Microsoft fixed this vulnerability already but the fix wasn`t complete. Affected systems are Windows NT, 2000, XP, 2003 and Vista. AVG detects all known variants of this exploit as Exploit.ANI.

BackDoor.Generic3.GBB and .GBC

Trojan horses BackDoor.Generic3.GBB and BackDoor.Generic3.GBC are almost similar. Both of them exploiting MS Windows Server Service vulnerability described in Microsoft Security Bulletin MS06-040 for it`s spreading.

Worm/Generic.FX

This worm spreads by internet and contains one dangerous payload action – every 3rd day of month worm overwrites files with doc, xls, mdb, mde, ppt, pps, zip, rar, pdf, psd and dmp extensions.

Exploit.WMF

These files exploits WMF vulnerability in Windows Operating Systems that allows malware code execution while WMF format file is opening. Unfortunately security patch for this vulnerability is not available at this time. AVG detects these files as Exploit.WMF and also as Trojan horse Downloader.Agent.

I-Worm/Bagle.JH

It spreads thanks to massive SPAMing, messages contains attachements with zip extension and exe file inside with 9968 B size. Worm tries to download next component from the internet, but the link is no longer accessible.

I-Worm/Sober.CF

This virus comes in as an attachment to emails written in English or German language. The attachment is a Zip archive with random name which contains the random named executable file with 55,390 b size.

I-Worm/Sober.S, .T

This virus comes in as an attachment to emails written in English or German language. The attachment is a Zip archive which contains the file PW_Klass.Pic.packed-bitmap.exe (113,551 b) in case of .S variant or file Screen_Photo.jpeg-graphic1.exe (122,751 b) in case of .T variant.

Don’t download that YouTube video!

New variation of Storm worm drops ecard disguise for online movie masquerade
Sophos, a world leader in IT security and control, has warned internet users about the latest disguise being used by malware authors in their attempt to infect people’s PCs: an email claiming to point to a YouTube video.
Experts at SophosLabâ„¢ have proactively protected [...]