Online Scanner Top Twenty for February 2007
Full article503 words · extracted from securelist.com · click to collapse
| Position | Change in position | Name | Percentage |
| 1. | ![]() Return |
Email-Worm.Win32.Mydoom.m | 1.66 |
| 2. | ![]() New! |
Trojan.Win32.Agent.qt | 1.50 |
| 3. | ![]() |
Email-Worm.Win32.Rays | 1.30 |
| 4. | ![]() +4 |
not-a-virus:Monitor.Win32.Perflogger.163 | 1.20 |
| 5. | ![]() +4 |
Email-Worm.Win32.Brontok.q | 1.11 |
| 6. | ![]() +7 |
Trojan.Win32.Dialer.cj | 0.99 |
| 7. | ![]() Return |
Backdoor.IRC.Zapchast | 0.87 |
| 8. | ![]() +3 |
not-a-virus:PSWTool.Win32.RAS.a | 0.84 |
| 9. | ![]() New! |
Trojan-Downloader.Win32.Small.ddp | 0.80 |
| 10. | ![]() New! |
Trojan-Downloader.Win32.Nurech.at | 0.63 |
| 11. | ![]() New! |
Email-Worm.Win32.Warezov.lk | 0.63 |
| 12. | ![]() New! |
not-a-virus:AdWare.Win32.Virtumonde.ha | 0.55 |
| 13. | ![]() +4 |
not-a-virus:Monitor.Win32.Perflogger.ad | 0.54 |
| 14. | ![]() New! |
Net-Worm.Win32.Mytob.bi | 0.52 |
| 15. | ![]() New! |
Trojan-Downloader.Win32.Bagle.bp | 0.51 |
| 16. | ![]() +4 |
Trojan-Spy.Win32.Bancos.zm | 0.50 |
| 17. | ![]() New! |
Trojan-Clicker.Win32.Small.kj | 0.48 |
| 18. | ![]() New! |
Email-Worm.Win32.Warezov.ls | 0.47 |
| 19. | ![]() -17 |
Trojan-Downloader.Win32.Small.edb | 0.46 |
| 20. | ![]() Return |
Email-Worm.Win32.Mydoom.l | 0.46 |
| Other malicious programs | 83.98 |
For the last few months, the Online Top Twenty has contained an unusually large number of Trojan dialers. They reached their peak in January, with five such programs in the rankings, and Diamin.fc in first place. The situation took a surprising turn in February: Diamin.fc dropped off the bottom of the table, and only Dialer.cj, which led the rankings in December 2006, was left.
Email worms, on the other hand, appear to be very active. In addition to Rays and Brontok, which have become something of a fixture in the online ratings, Mydoom.m has returned in first place. New worms such as Warezov.lk and Warezov.ls have also put in an appearance. It’s interesting that no Zhelatin variants showed up in the Online statistics, as they occupied a significant proportion of our mail traffic statistics. This may partly be due to the fact that Zhelatin epidemics were mostly cut off at mail server level, meaning that a relatively small number of infected emails actually reached end users.
The combination of old and new worms have succeeded in squeezing out Trojan Downloader programs, which previously have been extremely numerous. This month’s Top Twenty only has four Trojan downloaders, and those that remain are not in high positions.
True Trojan spy programs are continuing their decline: for the second month in a row, the only program from this category is the Brazilian Bancos.zm. However, other spy type programs are still widespread on users’ machines, as a look at fourth, eighth, and thirteenth place demonstrates. Virtumonde, an adware program, also seems to be common, with Virtumonde.ha in twelfth place, but is the only piece of adware in February’s rankings.
Summary:
- New: Trojan.Win32.Agent.qt, Trojan-Downloader.Win32.Small.ddp, Trojan-Downloader.Win32.Nurech.at, Email-Worm.Win32.Warezov.lk, not-a-virus:AdWare.Win32.Virtumonde.ha, Net-Worm.Win32.Mytob.bi, Trojan-Downloader.Win32.Bagle.bp, Trojan-Clicker.Win32.Small.kj, Email-Worm.Win32.Warezov.ls
- Moved up: not-a-virus:Monitor.Win32.Perflogger.163, Email-Worm.Win32.Brontok.q, Trojan.Win32.Dialer.cj, not-a-virus:PSWTool.Win32.RAS.a, not-a-virus:Monitor.Win32.Perflogger.ad, Trojan-Spy.Win32.Bancos.zm
- Moved down: Trojan-Downloader.Win32.Small.edb
- Re-entry: Email-Worm.Win32.Mydoom.m, Backdoor.IRC.Zapchast, Email-Worm.Win32.Mydoom.l
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/online-scanner-top-twenty-for-february-2007/36133/




