Solutions Buy Download Information Partners Support Forum About us «Doctor Web» company news (RSS channel)

January 2007 virus review by Doctor Web, Ltd.

February 1, 2007

The beginning of 2007 demonstrated that virus writers hadn’t meant to hang around during New Year holidays. They were inventing new traps for users – such as spam letters offering a video of Saddam Hussein’s execution which took place on December 30th, 2006 in secrecy. Later on there emerged some mobile-made shots of it. A few malware upgrades, classified by Doctor Web, Ltd. experts as Trojan.DownLoader.17224, spread over the world. Being run, these malware downloaded and executed confidential information stealers – Trojan.PWS.Banker.6321, Trojan.PWS.Banker.6322, Trojan.PWS.Banker.6276. Since the video is run by media-player, users may simply have no notion about the information leak.

Another spam video, detected by Dr.Web Anti-virus as BackDoor.Groan, Trojan.Spambot, has proved the increased popularity of spread in spam political plots. According to mail servers’ statistics, e-mails with BackDoor.Groan comprise 87-90% of the whole infected traffic. Being run, the attached file adds to the infected system a driver, which further on downloads other malware. In addition BackDoor.Groan is able to run in peering systems, formed to manage certain hosts of the web, as well as initiate unauthorized downloads and launch of files on infected computers.

The malware downloaded by BackDoor.Groan has been regularly upgraded during quite a long term. As statistics quotes, the upgrades took place twice a day, making their detection even more difficult.

Yet, showy political headlines are not out of the ordinary. Remember Internet worm Win32.Dref, which copies spread all over the world with nuclear war alarm in the headline in November 2006.

Creators of Win32.HLLM.Limar mail worm released new upgrades of their "off-spring" on January 15th and 23rd , as if congratulating users and anti-virus companies on the New Year and celebrating the malware 5 months anniversary in this way. Several versions of the network-aware worm of the Chinese origin infecting exe-files, classified by Dr.Web Anti-virus as Win32.HLLP.Whboy, were detected in January, too by experts of Doctor Web, Ltd. Some of the versions had only a propagating function, without exe-files infecting mechanism. The warm resulted in local epidemics all around of North Korea and in some USA and European regions. Win32.HLLP.Whboy propagates through vulnerabilities in browsers when a user visits a specially designed web-page. In addition to its diffusion on the web, the worm copies itself onto movable media, if there are any connected to it at the moment of infection.

Virus statistics by Doctor Web, Ltd. in January, 2007

6368 entries were added to Dr.Web virus database in January, 2007.

Find below a short summary table of online check in January:

Virus name Quantity
Win32.HLLM.Limar.based 416
Trojan.Spambot 307
Win32.HLLM.Wukill 222
Win32.HLLM.Beagle 141
Win32.HLLW.Limar 143
Trojan.Popuper 128
VBS.Psyme.239 121
Win32.Sector.28682 58
Win32.HLLM.Perf 57
Trojan.Packed.2 42

Below goes a table of the most frequently detected viruses in mail servers and networks protected by Dr.Web Enterprise Suite in January, 2007:

Virus name Percentage rate
Trojan.Bankfraud.272 22.47
BackDoor.Groan 12.48
Win32.HLLM.Limar.based 10.92
Win32.HLLM.Beagle 8.89
Win32.HLLM.Perf 6.98
Win32.HLLP.Sector 6.42
Win32.HLLM.Netsky.35328 5.41
Trojan.Packed.4 4.03
Win32.HLLM.MyDoom.based 3.06
Win32.HLLM.Netsky.based 2.93
Trojan.DownLoader.17767 2.04
Win32.HLLM.MyDoom.33808 1.46
Trojan.Spambot 1.44
Win32.HLLM.Graz 0.87
Trojan.Packed.3 0.81
Trojan.Packed.5 0.75
Program.RemoteAdmin 0.61
Win32.HLLM.MyDoom.49 0.60
Win32.HLLM.Limar 0.58
Exploit.MS05-053 0.53
Other malware 6.72



     Other news

2008-07-03June virus activity review from Doctor Web, Ltd.
2008-07-032000 companies using services of OBLTELECOM experience reliable anti-virus protection with Dr.Web
2008-06-30Dr.Web AV-Desk guards information of corporate customers of Newcom Port
2008-06-27Doctor Web, Ltd. establishes a subsidiary company in France
2008-06-27Dr.Web AV-Desk will remove malware from networks of Volkhov-Online
2008-06-26Dr.Web AV-Desk comes to Kyrgyzstan
2008-06-26Deployment of Dr.Web AV-Desk reduced the workload of Ufanet support service
2008-06-23Dr.Web AV-Desk will deliver "clean" Internet to 50 000 users in Moscow region
2008-06-19STREAM-TV Izhevsk employs Dr.Web AV-Desk
2008-06-18Dr.Web Enterprise Suite protects UAZ
2008-06-10Doctor Web, Ltd. releases SpIDer Mail 4.44.2.
2008-06-05May 2008 virus activity review by Doctor Web, Ltd.
2008-06-04AKADO chooses Dr.Web AV-Desk and recommends Dr.Web to its subscribers
2008-06-04Spam doesn’t always mean "malware”
2008-05-29Yandex recommends Dr.Web CureIt! to tackle malware faking web-pages
2008-05-27The new version of Dr.Web for Windows anti-virus scanner released
2008-05-26Izhevsk.net launches Dr.Web AV-Desk
2008-05-13April 2008 virus activity review from Doctor Web, Ltd.
2008-05-13Twenty five thousand subscribers of Eltel get protection by Dr.Web AV-Desk™
2008-05-07Dr.Web AV-Desk shields four hundred educational institutions of the Russian university network RUNNet
2008-05-06New version of Dr.Web anti-virus scanner for Windows released
2008-05-06Win32.Ntldrbot (aka Rustock.C) no longer a myth, no longer a threat. New Dr.Web scanner detects and cures it for real
2008-05-05Another 17 Russian cities get anti-virus as a service with Dr.Web AV-Desk
2008-05-04Protection against viruses and spam from Doctor Web, Ltd. and Sun Microsystems thoroughly tested
2008-05-04Another Russian ISP launches Dr.Web AV-Desk

   Information



   My five cents
 
What is the screen size of your monitor?

12''
14''
15''
17''
19''
more than 19''
other



Doctor Web, Ltd. © 2008 Doctor Web, Ltd. - a Russian company developing and distributing Dr.Web® Anti-virus solutions.
Our customers can be found among home users from all regions of the world and in large enterprises, small companies and nationwide corporations. We thank all of them for support and long-term devotion to our product. State certificates and awards received by the Dr.Web Anti-virus, as well as the geography of our users are the best evidence of exceptional trust to the products created by the talented Russian programmers.