<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0">
<channel>

<link>http://www.fortiguardcenter.com/</link>

<language>en</language>
<copyright>Copyright 2009 Fortinet Inc. All Rights Reserved</copyright>
<pubDate>Fri, 10 Jul 2009 09:10:22 -0800</pubDate>
	<item>
		<title>09-Jul SymbOS/Yxes.E!worm (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br />The repeated attempts by the worm to send SMS messages may yield:<ul><li>abnormally high bill</li><li>rapid battery power loss</li></ul><br>Presence of the following files:<ul><li>c:\sys\bin\AcsServer.exe</li><li>c:\sys\bin\Installer_0x20026CA6.exe</li><li>c:\private\101f875a\import\[20026CA5].rsc</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=SymbOS/Yxes.E!worm</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=SymbOS/Yxes.E!worm</guid>
		<pubDate>Thu, 09 Jul 2009 08:11:24 -0800</pubDate>
	</item>
	<item>
		<title>07-Jul SymbOS/HatiHati.A!worm (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><ul><li>Abnormally high phone bill.</li><br><li>Presence of any of the following files:</li><br><ul><li> C:\greetsita0.txt                    </li> <li> C:\system\apps\guardian\guardian.exe </li> </ul></ul><br>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=SymbOS/HatiHati.A!worm</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=SymbOS/HatiHati.A!worm</guid>
		<pubDate>Tue, 07 Jul 2009 11:43:29 -0800</pubDate>
	</item>
	<item>
		<title>07-Jul JS/FakeAVOnline.A!tr.dldr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>Possible firewall alert that an executable is attempting to connect to the internet. </li><br>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=JS/FakeAVOnline.A!tr.dldr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=JS/FakeAVOnline.A!tr.dldr</guid>
		<pubDate>Tue, 07 Jul 2009 11:43:03 -0800</pubDate>
	</item>
	<item>
		<title>07-Jul SymbOS/Cabir.E465!worm (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>Presence of the file <i>c:\system\apps\leslie\leslie.app</i>.<br><br>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=SymbOS/Cabir.E465!worm</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=SymbOS/Cabir.E465!worm</guid>
		<pubDate>Tue, 07 Jul 2009 11:05:19 -0800</pubDate>
	</item>
	<item>
		<title>06-Jul HackerTool/HelloCarbide (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>Protected directories (such as c:\sys) are accessible. This is the most reliable way to detect the malware.</li><li>In some cases (depending on malware and phone version), the phone may show an application named HelloCarbide (see Figure 1).</li><li>New applications cannot be started any longer</li></ul><br><div style="text-align:center"><br><img src="http://fgc.fortinet.com/virusimg/HackerTool-HelloCarbide.jpg"><br><i>Figure 1. HelloCarbide application </i></div><br><br>This hacking tool is often used along with the InstallServer tool, which disables Symbian's application signing verification, so that any application (signed or not) may be installed on the phone.]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=HackerTool/HelloCarbide</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=HackerTool/HelloCarbide</guid>
		<pubDate>Mon, 06 Jul 2009 10:39:58 -0800</pubDate>
	</item>
	<item>
		<title>06-Jul Adware/Trymedia (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The following folder is created:</li><ul><li>%CommonDesktopDir%\Downloads</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=Adware/Trymedia</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=Adware/Trymedia</guid>
		<pubDate>Mon, 06 Jul 2009 10:38:21 -0800</pubDate>
	</item>
	<item>
		<title>06-Jul Adware/OneStep (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The following files and folders are created:</li><ul><li>%WINDIR%\Temp\ONE{random_number}.tmp\upgrade.exe</li><li>%WINDIR%\Temp\{random_name}.tmp\Au_.exe</li><li>%PROGRAMFILES%\OneStep\OneStep_deleted0</li><li>%PROGRAMFILES%\OneStep\home.js</li><li>%PROGRAMFILES%\OneStep\onestep.dll</li><li>%PROGRAMFILES%\OneStep\onestep.exe</li><li>%PROGRAMFILES%\OneStep\OneStep_deleted_\onestep.dll</li><li>%PROGRAMFILES%\OneStep\OneStep_deleted_\onestep.exe</li><li>%PROGRAMFILES%\OneStep\osopt.exe</li><li>%PROGRAMFILES%\OneStep\readme.html</li><li>%PROGRAMFILES%\OneStep\uninstall.exe</li><li>C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla\Firefox\Profiles\foo</li><li>C:\Documents and Settings\All Users\Documents\HBEPGUID.TXT</li><li>C:\Documents and Settings\LocalService\Local Settings\Application Data\Mozilla\Firefox\Profiles\foo\XPC.mfl</li><li>C:\INSTALLED\Mozilla Firefox\extensions\{C7E0B063-1DC2-4DD0-A502-1D67957B9ADE}\chrome\onestep.jar</li><li>C:\INSTALLED\Mozilla Firefox\extensions\{C7E0B063-1DC2-4DD0-A502-1D67957B9ADE}\chrome.manifest</li><li>C:\INSTALLED\Mozilla Firefox\extensions\{C7E0B063-1DC2-4DD0-A502-1D67957B9ADE}\defaults\preferences\prefs.js</li><li>C:\INSTALLED\Mozilla Firefox\extensions\{C7E0B063-1DC2-4DD0-A502-1D67957B9ADE}\install.rdf</li><li>C:\INSTALLED\Mozilla Firefox\searchplugins\onestep.xml</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=Adware/OneStep</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=Adware/OneStep</guid>
		<pubDate>Mon, 06 Jul 2009 10:38:13 -0800</pubDate>
	</item>
	<item>
		<title>06-Jul iPhoneOS/Trapsms.A!tr.spy (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The spyware connects to the Internet. Depending on your phone's subscription, this may lead to abnormally high phone bills</li><li>An application named STD is installed in Cydia (typical third party installation tool for jailbroken iPhones)</li>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=iPhoneOS/Trapsms.A!tr.spy</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=iPhoneOS/Trapsms.A!tr.spy</guid>
		<pubDate>Mon, 06 Jul 2009 06:21:52 -0800</pubDate>
	</item>
	<item>
		<title>02-Jul W32/Zbot.GH!tr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The following folder is created:</li><ul><li>%SYSTEM%\lowsec\</li></ul><li>The following files are created:</li><ul><li>%SYSTEM%\lowsec\local.ds</li><li>%SYSTEM%\lowsec\user.ds</li><li>%SYSTEM%\lowsec\user.ds.lll</li><li>%SYSTEM%\sdra64.exe</li></ul><li>Possible termination of the firewall or other security applications, including antivirus monitors.</li>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=W32/Zbot.GH!tr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=W32/Zbot.GH!tr</guid>
		<pubDate>Thu, 02 Jul 2009 10:54:16 -0800</pubDate>
	</item>
	<item>
		<title>02-Jul W32/Zbot.FG!tr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The following folder is created:</li><ul><li>%SYSTEM%\lowsec\</li></ul><li>The following files are created:</li><ul><li>%SYSTEM%\lowsec\local.ds</li><li>%SYSTEM%\lowsec\user.ds</li><li>%SYSTEM%\lowsec\user.ds.lll</li><li>%SYSTEM%\sdra64.exe</li></ul><li>Possible termination of the firewall or other security applications, including antivirus monitors.</li>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=W32/Zbot.FG!tr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=W32/Zbot.FG!tr</guid>
		<pubDate>Thu, 02 Jul 2009 10:54:08 -0800</pubDate>
	</item>
	<item>
		<title>26-Jun SymbOS/Acallno.A!tr.spy (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>Abnormally high phone bill.</li><br><li>The following files exist:</li><ul><li>!:\System\recogs\s60syss.mdl</li><li>!:\System\Apps\s60system.exe</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=SymbOS/Acallno.A!tr.spy</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=SymbOS/Acallno.A!tr.spy</guid>
		<pubDate>Fri, 26 Jun 2009 14:04:07 -0800</pubDate>
	</item>
	<item>
		<title>26-Jun Java/GoSms.B!tr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>Attempts to send SMS messages to a short number.</li>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=Java/GoSms.B!tr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=Java/GoSms.B!tr</guid>
		<pubDate>Fri, 26 Jun 2009 14:03:46 -0800</pubDate>
	</item>
	<item>
		<title>26-Jun Java/GoSms.A!tr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>An SMS message is sent to the short number <i>1171</i>.</li>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=Java/GoSms.A!tr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=Java/GoSms.A!tr</guid>
		<pubDate>Fri, 26 Jun 2009 14:03:31 -0800</pubDate>
	</item>
	<item>
		<title>26-Jun Java/Smarm.A!tr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>Abnormally high phone bill</li>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=Java/Smarm.A!tr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=Java/Smarm.A!tr</guid>
		<pubDate>Fri, 26 Jun 2009 14:03:14 -0800</pubDate>
	</item>
	<item>
		<title>26-Jun SymbOS/Acallno.B!tr.spy (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><p>Since this Trojan Horse's purpose is to spy on the infected mobile device without its owner's knowledge, there are very few visible symptoms of the infection. The installation phase must either be performed on the targeted device by an attacker with physical access, or the attacker must trick the phone owner in doing so.<br><br>In the latter case, the phone owner should be particularly watchful if any of the following conditions are true:<br><ul><li>The SIS package does not contain a valid certificate. This is typical of malware, because they do not bear Symbian's signature</li><li>The sis package does not install any visible application icon (this is typical of spyware attempting to hide their presence on the phone)</li><li>The installer goes by the name Phantom v3.0 or demo</li><li>Abnormally high phone bill</li></ul>Finally, a reliable way to verify if a device is infected is to to check for the presence of the malware installed files with a file explorer application (see technical details below).</p>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=SymbOS/Acallno.B!tr.spy</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=SymbOS/Acallno.B!tr.spy</guid>
		<pubDate>Fri, 26 Jun 2009 14:02:43 -0800</pubDate>
	</item>
	<item>
		<title>23-Jun W32/FakeAlert.EI!tr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The following file exists:</li><ul><li>%SYSTEM%\sfcfiles.dat</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=W32/FakeAlert.EI!tr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=W32/FakeAlert.EI!tr</guid>
		<pubDate>Tue, 23 Jun 2009 10:08:47 -0800</pubDate>
	</item>
	<item>
		<title>19-Jun W32/Zbot.AA!tr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The following files exist:</li><ul><li>%System%\lowsec</li><li>%System%\sdra64.exe</li><li>%System%\lowsec\local.ds</li><li>%System%\lowsec\user.ds</li></ul><li>Possible termination of the firewall or other security applications, including antivirus monitors.</li>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=W32/Zbot.AA!tr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=W32/Zbot.AA!tr</guid>
		<pubDate>Fri, 19 Jun 2009 10:48:25 -0800</pubDate>
	</item>
	<item>
		<title>18-Jun W32/Skimmer.A!tr.bdr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The following files exist in the %WINDOWS% folder:</li><ul><li>trl2</li><li>kl</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=W32/Skimmer.A!tr.bdr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=W32/Skimmer.A!tr.bdr</guid>
		<pubDate>Thu, 18 Jun 2009 15:22:04 -0800</pubDate>
	</item>
	<item>
		<title>16-Jun HTML/Virut.CE (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>System is also infected with W32/Virut.CE.]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=HTML/Virut.CE</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=HTML/Virut.CE</guid>
		<pubDate>Tue, 16 Jun 2009 10:14:28 -0800</pubDate>
	</item>
	<item>
		<title>11-Jun JS/Redir.MR!tr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>Redirect to malicious websites.</li>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=JS/Redir.MR!tr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=JS/Redir.MR!tr</guid>
		<pubDate>Thu, 11 Jun 2009 10:37:45 -0800</pubDate>
	</item>
	<item>
		<title>11-Jun JS/Gumblar.A!tr.dldr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>Redirect to malicious websites.<li>Malicious files may be downloaded.]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=JS/Gumblar.A!tr.dldr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=JS/Gumblar.A!tr.dldr</guid>
		<pubDate>Thu, 11 Jun 2009 10:37:21 -0800</pubDate>
	</item>
	<item>
		<title>11-Jun W32/Dropper.CG!tr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>Drops files to folders such as the root folder and Temporary folder.]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=W32/Dropper.CG!tr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=W32/Dropper.CG!tr</guid>
		<pubDate>Thu, 11 Jun 2009 10:36:34 -0800</pubDate>
	</item>
	<item>
		<title>10-Jun VBS/Phel.I!exploit (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br />This threat attempts to use various tricks to exploit vulnerabilities in Windows-based systems that are unpatched against the implemented vulnerabilities.]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=VBS/Phel.I!exploit</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=VBS/Phel.I!exploit</guid>
		<pubDate>Wed, 10 Jun 2009 12:33:03 -0800</pubDate>
	</item>
	<item>
		<title>10-Jun W32/DCERPC!exploit.MS08067 (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br />The related samples are POC files (Proof-Of-Concept).]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=W32/DCERPC!exploit.MS08067</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=W32/DCERPC!exploit.MS08067</guid>
		<pubDate>Wed, 10 Jun 2009 12:32:54 -0800</pubDate>
	</item>
	<item>
		<title>10-Jun Misc/Freechal (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The following folder exists:</li><ul><li>%Program Files%\Smarton\</li></ul><li>The following files exist: </li><ul><li>%Program Files%\Smarton\st_rwd_1j.dll</li><li>%Program Files%\Smarton\st_src_1b.dll</li><li>%Program Files%\Smarton\stsv.dll</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=Misc/Freechal</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=Misc/Freechal</guid>
		<pubDate>Wed, 10 Jun 2009 12:32:44 -0800</pubDate>
	</item>
	<item>
		<title>09-Jun SymbOS/Yxes.A!worm (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The repeated attempts by the worm to send SMS messages or connect to the Internet may yield:</li><ul>  <li>Abnormally high phone bills</li>  <li>Rapid battery power loss</li></ul><li>Presence of the following files :</li><ul><li>c:\sys\bin\EConServer.exe<li>c:\private\101f875a\import\[2001EB45].rsc</ul><li>Impossible to launch the following applications: </li><ul><li>AppMgr<li>TaskSpy<li>Y-Tasks<li>ActiveFile<li>TaskMan</ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=SymbOS/Yxes.A!worm</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=SymbOS/Yxes.A!worm</guid>
		<pubDate>Tue, 09 Jun 2009 17:57:03 -0800</pubDate>
	</item>
	<item>
		<title>09-Jun SymbOS/Yxes.C!worm (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><ul><li> The repeated attempts by the worm to send SMS messages may yield:</li><br/><ul>  <li>Rapid battery power loss</li>  <li>Abnormally high phone bills</li></ul><br/><li>Presence of the following file:</li><br/><ul>  <li>C:\sys\bin\Transmitter.exe</li></ul></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=SymbOS/Yxes.C!worm</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=SymbOS/Yxes.C!worm</guid>
		<pubDate>Tue, 09 Jun 2009 17:56:30 -0800</pubDate>
	</item>
	<item>
		<title>09-Jun SymbOS/Yxes.D!worm (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><ul><li> The repeated attempts by the worm to send SMS messages may yield:</li><br/><ul>  <li>Rapid battery power loss</li>  <li>Abnormally high phone bills</li></ul><br/><li>Presence of the following files:</li><br/><ul>  <li>c:\sys\bin\BootHelper.exe</li>  <li>c:\private\101f875a\import\[20017741].rsc</li></ul></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=SymbOS/Yxes.D!worm</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=SymbOS/Yxes.D!worm</guid>
		<pubDate>Tue, 09 Jun 2009 16:37:19 -0800</pubDate>
	</item>
	<item>
		<title>09-Jun W32/Conficker.B!worm (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The following files exist:</li><ul><li>%System%\{random lower case characters}.dll</li><li>%Program Files%\Internet Explorer\{random lower case characters}.dll</li><li>%Program Files%\Movie Maker\{random lower case characters}.dll</li><li>%Documents and Settings%\All Users\Application Data\{random lower case characters}.dll</li><li>%Temp%\{random lower case characters}.dll</li><li>%Temp%\{random}.tmp</li></ul><li>Access to security-related websites is hindered</li>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=W32/Conficker.B!worm</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=W32/Conficker.B!worm</guid>
		<pubDate>Tue, 09 Jun 2009 16:37:10 -0800</pubDate>
	</item>
	<item>
		<title>09-Jun W32/Agent.KTBW!tr.dldr (Level 1)</title>
		<description>
		<![CDATA[<b>Visible Symptoms</b><br /><br /><li>The following file exists:</li><ul><li>%Temp%/install-1557.exe</li></ul>]]>
		</description>
		<link>http://www.fortiguardcenter.com/ve?vn=W32/Agent.KTBW!tr.dldr</link>
		<guid>http://www.fortiguardcenter.com/ve?vn=W32/Agent.KTBW!tr.dldr</guid>
		<pubDate>Tue, 09 Jun 2009 11:54:00 -0800</pubDate>
	</item>
</channel>
</rss>

