Saltar al contenido principal

Online Scanner Top Twenty for March 2008

1 de abril de 2008

Amazingly, for the second month in a row, not only has the leader of our Top Twenty not changed but the three programs at the top of the ranking have remained the same.


Amazingly, for the second month in a row, not only has the leader of our Top Twenty not changed but the three programs at the top of the ranking have remained the same.

The adware program Virtumonde or, to be more precise, an entire family that we detect as Virtumonde.gen, remains firmly in top place. This adware program has been actively circulating for almost a year and the situation is deteriorating with every passing month.

Exactly the same can be said about the second entry in the rankings, which is the latest modification of the Bagle worm. However, in Bagle's case, it's been in circulation for four years rather than one. Bagle was first detected back in January 2004. The authors, whose identities still remain a mystery, are responsible for a substantial share of Internet spam.

Keeping Bagle.of company in the March Top Twenty are a couple of related programs - the Trojan-Downloader programs Bagle.jh and Bagle.ij. Both of them are newcomers to the ratings; March saw them being used to prepare the ground for new versions of Bagle. That means we can expect these worms to be widespread in April as well. Unfortunately, last month's forecast that the Virut.n epidemic would subside proved to be premature. After ranking sixteenth last month, Virut.n, the sole survivor of the Virut family, rose ten places to end March in sixth place. A repeat of the third-place finish by Virut.av in January could well be on the cards.

The simultaneous emergence of two Autorun programs - Worm.Win32.Autorun.byt and Virus.Win32.Autorun.abt - also deserves a mention. They make use of exactly the same propagation method as the veteran Brontok.q and Rays worms (which have been ever-present amongst the most widespread malicious programs over the last few years). As well being able to propagate independently, this latest pair of malicious programs also steals user data, which undoubtedly makes them a serious threat.

The Ardamax keylogger family continues to pester users - Ardamax.n, which dropped to the bottom of the Top Twenty in March, was joined by the 'legitimate' program Ardamax.ae in thirteenth place.

All in all, March differed very little from previous months - users were spied on, their passwords were stolen and their PCs were used to send spam and display adware.

Summary

New: Trojan-Downloader.Win32.Bagle.jh, Worm.Win32.AutoRun.byt, P2P-Worm.Win32.Malas.d, not-a-virus:Monitor.Win32.Ardamax.ae, Virus.Win32.AutoRun.abt, Backdoor.Win32.Bifrose.bgn, Packed.Win32.PolyCrypt.h, Trojan-Downloader.Win32.Bagle.ij

Went up: not-a-virus:PSWTool.Win32.RAS.a, Email-Worm.Win32.Brontok.q, Virus.Win32.Virut.n, not-a-virus:AdWare.Win32.BHO.xq, Trojan.Win32.Delf.aam,

Went down: Email-Worm.Win32.Rays, Trojan-Spy.Win32.Ardamax.n

Re-entry: Virus.Win32.Parite.b, Email-Worm.Win32.NetSky.q

No change: not-a-virus:AdWare.Win32.Virtumonde.gen, Email-Worm.Win32.Bagle.of, Trojan.Win32.Dialer.yz

Online Scanner Top Twenty for March 2008

Amazingly, for the second month in a row, not only has the leader of our Top Twenty not changed but the three programs at the top of the ranking have remained the same.
Kaspersky logo

Sobre Kaspersky

Kaspersky es una empresa de ciberseguridad y privacidad digital global fundada en 1997. Con más de mil millones de dispositivos protegidos hasta la fecha ante ciberamenazas emergentes y ataques dirigidos, la enorme experiencia de Kaspersky en cuestión de información y seguridad ante amenazas se transforma de forma constante en soluciones y servicios innovadores que ofrecen protección a negocios, infraestructuras vitales, gobiernos y consumidores de todo el mundo. El completísimo catálogo de la compañía incluye los mejores productos y servicios de protección de terminales, así como soluciones de ciberinmunidad para combatir amenazas digitales sofisticadas y en constante evolución. Ayudamos a que más de 200 000 clientes corporativos protejan aquello que más les importa. Más información en www.kaspersky.es.

Artículo relacionado Comunicados de prensa