<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Antivirus Advice &#187; top twenty lists</title>
	<atom:link href="http://www.antivirus-advice.com/tag/top-twenty-lists/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.antivirus-advice.com</link>
	<description>Computer Security News</description>
	<lastBuildDate>Tue, 23 Aug 2011 12:14:40 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.2.1</generator>
		<item>
		<title>Monthly Malware Statistics: February 2010</title>
		<link>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-february-2010/</link>
		<comments>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-february-2010/#comments</comments>
		<pubDate>Mon, 08 Mar 2010 14:30:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[top twenty lists]]></category>
		<category><![CDATA[trojan downloader win32]]></category>

		<guid isPermaLink="false">http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-february-2010/</guid>
		<description><![CDATA[Malicious programs detected on users’ computers The first Top Twenty lists malicious programs, adware and potentially unwanted programs that were detected and neutralized when accessed for the first time, i.e. by the on-access scanner. Position Change in position Name Number of infected computers 1   0 Net-Worm.Win32.Kido.ir   274729   2   1 Virus.Win32.Sality.aa  <br /><span class="excerpt_more"><a href="http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-february-2010/">[continue reading...]</a></span>

<h3>Related Posts</h3>

No related posts.
]]></description>
			<content:encoded><![CDATA[<h3>Malicious programs detected on users’ computers</h3>
<p>The first Top Twenty lists malicious programs, adware and potentially unwanted programs that were detected and neutralized when accessed for the first time, i.e. by the on-access scanner.</p>
<p>
<div align="center">
<table width="75%" cellpadding="4px" cellspacing="0" border="0">
<tr align="center" valign="center" style="font-weight:bold;">
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Position </td>
<td width="17%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Change in position       </td>
<td width="50%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Name   </td>
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Number of infected computers      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   1          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.ir     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      274729     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   2          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">  Virus.Win32.Sality.aa      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      179218     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   3          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.ih    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      163467     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   4          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_down.gif">     -2      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.iq     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      121130     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   5          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.FlyStudio.cu    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      85345      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   6          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       3       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.Win32.VB.eql     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      56998      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   7          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">       New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Exploit.JS.Aurora.a        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      49090      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   8          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       9       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.AutoIt.tc       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      48418      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   9          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Virut.ce       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      47842      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   10         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       4       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Krap.l        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      47375      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   11         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_down.gif">     -3      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.WMA.GetCodec.s           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      43295      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   12         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Induc.a        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      40257      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   13         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.RK.aw     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      39608      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   14         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_down.gif">     -3      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.Boran.z           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      39404      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   15         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.Mabezat.b       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      38905      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   16         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">   New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Agent.bau        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      34842      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   17         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       3       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Black.a       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      32439      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   18         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Dropper.Win32.Flystud.yo    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      32268      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   19         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_ret.gif">      Return     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.AutoRun.dui     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      32077      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   20         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.FunWeb.q          </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      30942      </td>
</tr>
</table>
</div>
<p>
<p>There was no change to the top 5 malicious programs this month and judging by the number of infections, the Kido epidemic has eased off slightly.</p>
<p>Exploit.JS.Aurora.a, which, as its name suggests, is a program designed to take advantage of vulnerabilities in a variety of software products. This exploit was widely used in February and consequently entered in the ratings in seventh place. Further details are given in the section “Malicious programs on the Internet”. </p>
<p>Other newcomers in February included two adware programs.<br />
FunWeb.q in 20th place is a perfect example of an adware program. It’s a toolbar for popular browsers and provides users with easy access to resources on some websites (usually those with multimedia content). It also modifies the pages visited so that these pages display adverts. </p>
<p>The case of not-a-virus: AdWare.Win32.RK.aw (in thirteenth place) is rather more complex. This RelevantKnowledge application spreads and is installed along with other software products. The company’s privacy policy and ULA states that the program tracks virtually all user activity, particularly Internet activity, automatically collecting personal information and saving it to the company’s servers. It also says that all the data collected is used exclusively to “help shape the future of the Internet” and that the data is well secured. Whether this is true or not is up to the individual to decide. </p>
<h3>Malicious programs on the Internet</h3>
<p>The second Top Twenty presents data generated by the web antivirus component, and reflects the online threat landscape. This ranking includes malicious programs detected on web pages and malware downloaded to victim machines from web pages.</p>
<p>
<div align="center">
<table width="75%" cellpadding="4px" cellspacing="0" border="0">
<tr align="center" valign="center" style="font-weight:bold;">
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Position </td>
<td width="17%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Change in position</td>
<td width="50%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Name</td>
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Number of attempted downloads       </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   1          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_ret.gif">      Return  </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Gumblar.x     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      453985     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   2          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_down.gif">     -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Redirector.l     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      346637     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   3          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Pegel.b       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      198348     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   4          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       3       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.Boran.z           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      80185      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   5          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_down.gif">     -2      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Zapchast.m    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      80121      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   6          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Clicker.JS.Iframe.ea        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      77067      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   7          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Popupper.ap      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      77015      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   8          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_up.gif">       3       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Popupper.t       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      64506      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   9          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Exploit.JS.Aurora.a        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      54102      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   10         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Agent.aui        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      53415      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   11         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Pegel.l       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      51019      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   12         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.Java.Agent.an    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      47765      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   13         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Clicker.JS.Agent.ma         </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      45525      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   14         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.Java.Agent.ab    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      42830      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   15         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Pegel.f       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      41526      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   16         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_ret.gif">      Return  </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Krap.ai       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      38567      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   17         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.Win32.Lipler.axkd        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      38466      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   18         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Exploit.JS.Agent.awd       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      35024      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   19         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Pegel.k       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      34665      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   20         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-288"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Krap.an       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      33538      </td>
</tr>
</table>
</div>
<p>
<p>The state of affairs regarding malware on the Internet in February was quite remarkable, which is reflected in our second rating.</p>
<p>First of all, there was a dramatic surge in Gumblar.x, which has once again regained top spot after virtually disappearing completely in January. Last month, we suggested there might be another Gumblar attack and it didn’t take long to materialize. However, this time the black hats haven’t changed their approach in any significant way; they’ve simply been gathering new data that can be used to access websites prior to infecting them en masse. We’ll be keeping track of any further developments.  </p>
<p align="center"><img class="colorbox-288"  src="images/vlill/aseev_top20_0310_pic01.png" border="0" width="400" height="350" alt=""><br /><strong></strong></p>
<p>Secondly, the Pegel epidemic that started in January grew almost six-fold – there are four representatives of this family among the new entries, one of which made it straight to third place.  This is a downloader program and in some ways it’s not unlike Gumblar, in that it also infects perfectly legitimate websites. A user that visits an infected site is redirected by the malicious script to a cybercriminal resource. To ensure users don’t suspect anything, the names of popular websites are used in the addresses of malicious pages, for example:   </p>
<div class="pre">http://friendster-com.youjizz.com.jeuxvideo-com.**********.ru:8080/sify.com/sify.com/pdfdatabase.com/google.com/allegro.pl.php</p>
<p>http://avast-com.deviantart.com.dangdang-com.**********.ru:8080/wsj.com/wsj.com/google.com/nokia.com/aweber.com.php</p></div>
<p>These links lead to pages containing another script which uses a number of different methods to download the main executable file. The methods used are mostly traditional – exploiting vulnerabilities in major software products such as Internet Explorer (CVE-2006-0003) and Adobe Reader (CVE-2007-5659, CVE-2009-0927 as well as downloading via a special Java applet. The main executable file is the now familiar Backdoor.Win32.Bredolab, packed using various malicious packers (several of which are detected as Packed.Win32.Krap.ar and Packed.Win32.Krap.ao). We have already written in some detail about this malware but it’s worth mentioning again that in addition to its main payload – remote management of infected machines &#8211; it can also download other malicious files. </p>
<p>And now back to Exploit.JS.Aurora.a, which was mentioned above. At number nine in the second rating, Aurora.a is the exploit targeting the CVE-2010-0249 vulnerability. It was identified after a massive targeted attack on several versions of Internet Explorer in January. </p>
<p>The attack, which received wide coverage in the IT media, targeted major organizations (including Google and Adobe) and was named Aurora after part of the file path name used in one of the main executable files. The attack was designed to gain access to personal data and corporate intellectual property such as project source code. The attack was carried out using emails with links to malicious sites; these sites contained exploits which resulted in the main executable file being stealthily downloaded to victim machines. </p>
<p align="center"><img class="colorbox-288"  src="images/vlill/aseev_top20_0310_pic02.png" border="0" width="402" height="259" alt=""><br /><strong></strong></p>
<p>Remarkably, the programmers at Microsoft had been aware of this loophole for a number of months, but it was only patched  a month after it began being exploited. It’s worth pointing out that in that time the source code of the exploit became publicly available and only the laziest cybercriminals failed to use it in their attacks: our collection already has more than a hundred malware variants that exploit this vulnerability.</p>
<p>The facts speak for themselves. Vulnerabilities in popular software continue to pose the main threat to users and their data. The fact that cybercriminals are still attempting to exploit vulnerabilities which were detected several years ago is evidence that these vulnerabilities still pose a security threat. Unfortunately, even updating software from major vendors on a regular basis does not guarantee security, as vendors may not always release patches promptly. It’s therefore important to exercise caution – particularly when surfing the Internet – and of course an up-to-date antivirus solution is a must! </p>


<h3>Related Posts</h3>
<p>No related posts.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-february-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monthly Malware Statistics: January 2010</title>
		<link>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-january-2010/</link>
		<comments>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-january-2010/#comments</comments>
		<pubDate>Fri, 05 Feb 2010 14:32:19 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[top twenty lists]]></category>
		<category><![CDATA[trojan downloader win32]]></category>

		<guid isPermaLink="false">http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-january-2010/</guid>
		<description><![CDATA[Malicious programs detected on users&#8217; computers The first Top Twenty lists malicious programs, adware and potentially unwanted programs that were detected and neutralized when accessed for the first time, i.e. by the on-access scanner. Position Change in position Name Number of infected computers 1   0 Net-Worm.Win32.Kido.ir   276021   2   0 Net-Worm.Win32.Kido.iq  <br /><span class="excerpt_more"><a href="http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-january-2010/">[continue reading...]</a></span>

<h3>Related Posts</h3>

No related posts.
]]></description>
			<content:encoded><![CDATA[<h3>Malicious programs detected on users&#8217; computers</h3>
<p>The first Top Twenty lists malicious programs, adware and potentially unwanted programs that were detected and neutralized when accessed for the first time, i.e. by the on-access scanner.</p>
<p>
<div align="center">
<table width="75%" cellpadding="4px" cellspacing="0" border="0">
<tr align="center" valign="center" style="font-weight:bold;">
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Position </td>
<td width="17%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Change in position       </td>
<td width="50%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Name   </td>
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Number of infected computers      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   1          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.ir     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      276021     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   2          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.iq     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      197376     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   3          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Sality.aa      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      169101     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   4          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_down.gif">     -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.ih     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      164421     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   5          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.FlyStudio.cu    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      109898     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   6          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       21      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Zapchast.m    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      65476      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   7          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       21      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Small.oj      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      64767      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   8          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.WMA.GetCodec.s           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      63266      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   9          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_down.gif">     -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.Win32.VB.eql     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      61852      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   10         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       2       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Virut.ce       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      51944      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   11         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_down.gif">     -4      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.Boran.z           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      51868      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   12         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Induc.a        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      44432      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   13         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.Win32.AutoRun.sj    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      39530      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   14         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Krap.l        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      38944      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   15         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.Win32.AutoRun.sl    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      38742      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   16         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.Mabezat.b       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      37365      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   17         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.AutoIt.tc       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      36162      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   18         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.Win32.AutoRun.ws    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      36149      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   19         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_down.gif">     -5      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Dropper.Win32.Flystud.yo    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      35883      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   20         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_down.gif">     -4      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Black.a       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      35462      </td>
</tr>
</table>
</div>
<p>
<p>For the third month in a row the top five programs have led the rest of the rating by some distance.</p>
<p>January, however, did see seven new entries, which is unusual for the first Top Twenty. The two script downloaders that entered right behind the leading pack have already made an appearance in our second rating for web-borne malware, but this is the first time they have made it into this rating.</p>
<p>Among the newcomers are three modifications of Trojan.Win32.Autorun that help spread the notorious P2P-Worm.Win32.Palevo and Trojan-GameThief.Win32.Magania via removable devices.  </p>
<p>AutoIt, which we have already discussed on a number of occasions, is gaining in popularity with two new malicious programs – Packed.Win32.Krap.l and Worm.Win32.AutoIt.tc – created using this script language.</p>
<h3>Malicious programs on the Internet</h3>
<p>The second Top Twenty presents data generated by the web antivirus component, and reflects the online threat landscape. This ranking includes malicious programs detected on web pages and malware downloaded to victim machines from web pages.</p>
<p>
<div align="center">
<table width="75%" cellpadding="4px" cellspacing="0" border="0">
<tr align="center" valign="center" style="font-weight:bold;">
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Position </td>
<td width="17%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Change in position</td>
<td width="50%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Name</td>
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Number of attempted downloads       </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   1          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Redirector.l     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      615521     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   2          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       3       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Clicker.JS.Iframe.db        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      299222     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   3          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_ret.gif">      Return  </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Zapchast.m    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      208056     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   4          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Iframe.hw        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      166755     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   5          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_down.gif">     -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.HTML.IFrame.sz           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      138843     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   6          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       21      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Agent.ewo     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      116110     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   7          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_down.gif">     -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.Boran.z           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      99567      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   8          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Agent.exc     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      82147      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   9          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_ret.gif">      Return  </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Small.oj      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      77659      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   10         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Exploit.Win32.Pidief.cvl           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      75687      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   11         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Popupper.t       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      73028      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   12         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_up.gif">       2       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Shadraem.a    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      43592      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   13         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Clicker.JS.Iframe.dh        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      39441      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   14         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">New   </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.JS.Agent.bp         </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      39420      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   15         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Fraud.s          </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      38088      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   16         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_down.gif">     -9      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Iframe.ez        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      36156      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   17         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Pegel.c       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      35977      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   18         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Iframe.ef        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      34700      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   19         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_down.gif">     -2      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Twetti.a      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      32544      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   20         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-225"  src="http://www.kaspersky.com/images/vldesign/top20_down.gif">     -9      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Krap.ag       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      31148      </td>
</tr>
</table>
</div>
<p>
<p>The second rating remains a kaleidoscope of the latest cybercriminal creations.</p>
<p>New entries include Trojan.JS.Iframe.hw (4th place), Trojan-Downloader.JS.Agent.ewo (6th), and Trojan-Downloader.JS.Pegel.c (17th) – all of them similar script downloaders that redirect users to other malicious scripts which in turn exploit vulnerabilities in popular software products.</p>
<p>Trojan.JS.Fraud.s in 15th place detects web pages which are cloned from a template and used to spread rogue antivirus applications.</p>
<p>All the other new entries are various script downloaders that infect users&#8217; computers with malicious programs.</p>
<p>It&#8217;s worth pointing out that the  second Gumblar epidemic fizzled out fairly quickly. We&#8217;ll have to wait and see if there is to be a third.</p>
<p>Overall, there has been no major change to recent trends. Malware is actively spreading via removable media with the help of script downloaders, and for the most part exploiting vulnerabilities in popular software products.</p>
<p>Countries where most attempts to infect via the web originated:</p>
<p align="center"><img class="colorbox-225"  src="http://www.kaspersky.com/images/vlill/aseev_top20_1001_en_s.png" border="0" width="400" height="240" alt=""> <img class="colorbox-225"  src="http://www.kaspersky.com/images/draft/enlarge.gif" border="0" width="9" height="9" alt=""></p>


<h3>Related Posts</h3>
<p>No related posts.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-january-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monthly Malware Statistics: November 2009</title>
		<link>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-november-2009/</link>
		<comments>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-november-2009/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 15:46:53 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[top twenty lists]]></category>
		<category><![CDATA[trojan downloader win32]]></category>
		<category><![CDATA[virus win32]]></category>

		<guid isPermaLink="false">http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-november-2009/</guid>
		<description><![CDATA[Malicious programs detected on users’ computers The first Top Twenty lists malicious programs, adware and potentially unwanted programs that were detected and neutralized when accessed for the first time, i.e. by the on-access scanner. Position Change in position Name Number of infected computers 1   0 Net-Worm.Win32.Kido.ir   330305   2   New Net-Worm.Win32.Kido.iq  <br /><span class="excerpt_more"><a href="http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-november-2009/">[continue reading...]</a></span>

<h3>Related Posts</h3>

No related posts.
]]></description>
			<content:encoded><![CDATA[<p> Malicious programs detected on users’ computers</p>
<p>The first Top Twenty lists malicious programs, adware and potentially unwanted programs that were detected and neutralized when accessed for the first time, i.e. by the on-access scanner.</p>
<div align="center">
<table width="75%" cellpadding="4px" cellspacing="0" border="0">
<tr align="center" valign="center" style="font-weight:bold;">
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Position        </td>
<td width="17%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Change in position      </td>
<td width="50%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Name    </td>
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Number of infected computers    </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   1          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_noch.gif">       0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.ir     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      330305     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   2          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">     New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.iq     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      174351     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   3          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">     -1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.ih           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      145332     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   4          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_noch.gif">     0      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Sality.aa      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      128737      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   5          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_noch.gif">       0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.FlyStudio.cu    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      93848      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   6          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">     -3      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.Boran.z     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      84825      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   7          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">     -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.Win32.VB.eql        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      63287      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   8          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_up.gif">      9      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.WMA.GetCodec.s       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      48426      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   9          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_up.gif">      1     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Virut.ce     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      47812      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   10         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">     -3      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Induc.a       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      46252      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   11         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">      -2      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.AutoRun.awkp       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      36453      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   12         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">     -4      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Black.d     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      36422      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   13         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">       -2       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Black.a    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      35094      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   14         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">      -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Dropper.Win32.Flystud.yo    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      34638      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   15         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">      -3      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.AutoRun.dui      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      32493      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   16         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">      -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Klone.bj     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      31963      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   17         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_up.gif">      1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.Mabezat.b          </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      29804      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   18         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">     New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Krap.ag       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      26041      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   19         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-GameThief.Win32.Magania.ckqi        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      25529      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   20         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.Win32.Genome.bjgu    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      24730      </td>
</tr>
</table>
</div>
<p>Overall, there was little change to the first rating, although there are a few points worth highlighting.</p>
<p>First of all, there is the new entry of Kido.iq that came straight in at 2nd place. This malicious program has very similar functionality to the leader, Kido.ir, which entered the ratings back in September.</p>
<p>Secondly, GetCodec.s rose 9 places overall, with the number of computers on which GetCodec was detected more than doubling in November. To recap, GetCodec.s spreads together with P2P-Worm.Win32.Nugg, just like GetCodec.r which we wrote about last December. It looks as though cybercriminals are making another attempt to spread P2P-Worm.Win32.Nugg via the Gnutella file sharing network Gnutella (and in this case, using the popular LimeWire application). This worm downloads other malicious programs, which act as an additional threat to users’ computers.</p>
<p>Another newcomer of note is Packed.Win32.Krap.ag. Just as other representatives of the Packed family do, Krap.ag detects a special packing program used to pack malicious programs. In this particular case, the malicious programs, which are concealed by a standard, but modified, packing program, are fake antivirus programs such as those we wrote about recently. In other words, 18th place in the rankings is effectively occupied by a rogue antivirus solution.</p>
<p>After returning to the ratings the Magania family of gaming Trojans has held on to 19th place, albeit with the new version Magania.ckqi replacing last month’s entry Magania.cbrt.</p>
<p>Malicious programs on the Internet</p>
<p>The second Top Twenty presents data generated by the web antivirus component, and reflects the online threat landscape. This ranking includes malicious programs detected on web pages and malware downloaded to victim machines from web pages.</p>
<div align="center">
<table width="75%" cellpadding="4px" cellspacing="0" border="0">
<tr align="center" valign="center" style="font-weight:bold;">
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Position        </td>
<td width="17%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Change in position      </td>
<td width="50%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Name    </td>
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Number of attempted downloads    </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   1          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_noch.gif">       0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Gumblar.x     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      1714509     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   2          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_up.gif">     1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.HTML.IFrame.sz     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      189881     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   3          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">     New       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Clicker.JS.Iframe.be           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      170319     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   4          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_noch.gif">     0      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.Boran.z      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      136748      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   5          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_noch.gif">       0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Redirector.l    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      130271      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   6          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">     New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Ramif.a     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      115163      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   7          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_up.gif">     1       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Agent.aat        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      55291      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   8          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">      -2      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Clicker.HTML.Agent.aq       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      47873      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   9          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.HTML.Fraud.r     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      47473      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   10         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">     -8      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Gumblar.w       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      41977      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   11         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Iframe.dy       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      35152      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   12         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">     -5      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Zapchast.m     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      31161      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   13         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">       New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.IstBar.cy    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      30806      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   14         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Clicker.JS.Iframe.u    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      30553      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   15         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_ret.gif">      Return      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Psyme.gh      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      30078      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   16         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.HTML.FraudLoad.b     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      29466      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   17         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Clicker.HTML.IFrame.ajn           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      29455      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   18         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">     New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.PrygSkok.a       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      27804      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   19         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_new.gif">      New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Krap.ag        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      26770      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   20         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-45"  src="images/vldesign/top20_down.gif">      -5      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.LuckySploit.q    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      26175      </td>
</tr>
</table>
</div>
<p>Gumblar continues to dominate this rating with a huge gap separating it from the program in 2nd place. The number of unique attempts to download this malicious program increased nearly four times in November.</p>
<p>The latest Gumblar attack, which we described last month, continued unabated in November. Unlike the attack six months earlier this time all the components – the downloader, the exploits and the main executable file – were replaced or modified with alarming regularity.</p>
<p>Rogue antivirus programs also made it into the second rating. One method of spreading these programs is by downloading them to users’ machines from websites that are created using the same template and which are part of cybercriminal affiliate, or partner, programs.  The web pages most commonly used to download fake antivirus solutions in November are detected by us as Trojan.HTML.Fraud.r and Trojan-Downloader.HTML.FraudLoad.b. Packed.Win32.Krap.ag, mentioned above, was also downloaded from these pages and this explains why it makes an appearance in the second Top 20 as well.</p>
<p>The other new entries (script downloaders which vary in sophistication and the degree of obfuscation used) follow recent trends.</p>
<p>November trends</p>
<p>The overall picture remained unchanged in November. At the moment, the most common strategy for spreading malware is to use a malicious script + exploit + executable file. More often than not, this is how malware designed to steal confidential data or extort money from users is spread. Such malware includes programs such as Trojan-PSW.Win32.Kates (the Gumblar attacks are primarily designed to download this malware); Trojan-Spy.Win32.Zbot, an extremely widespread Trojan that actively spreads using script downloaders and varied spam mass mailings; and numerous fake antivirus programs.</p>
<p>Another marked trend of recent months that continued in November was the use of websites created using standardized templates to spread rogue antivirus solutions.</p>
<p>Cybercriminals are also aggressively using packers (usually polymorphic) in the hope that this will help the packed malicious programs avoid detection, so they won&#8217;t have to make significant modifications to the malicious programs themselves.</p>
<p>This month malware was also distributed via P2P networks using multimedia downloader programs, a method that the cybercriminals made use of last December.</p>
<p>Countries where most attempts to infect via the web originated.</p>
<p align="center"><img class="colorbox-45"  src="images/vlill/top20_09nov_en_s.png" border="0" width="400" height="200" alt=""> <img class="colorbox-45"  src="images/draft/enlarge.gif" border="0" alt=""></p>


<h3>Related Posts</h3>
<p>No related posts.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-november-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Monthly Malware Statistics: December 2009</title>
		<link>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-december-2009/</link>
		<comments>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-december-2009/#comments</comments>
		<pubDate>Fri, 08 Jan 2010 15:44:21 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Kaspersky]]></category>
		<category><![CDATA[top twenty lists]]></category>
		<category><![CDATA[trojan downloader win32]]></category>
		<category><![CDATA[win32 swizzor]]></category>

		<guid isPermaLink="false">http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-december-2009/</guid>
		<description><![CDATA[Malicious programs detected on users’ computers The first Top Twenty lists malicious programs, adware and potentially unwanted programs that were detected and neutralized when accessed for the first time, i.e. by the on-access scanner. Position Change in position Name Number of infected computers 1   0 Net-Worm.Win32.Kido.ir   265622   2   0 Net-Worm.Win32.Kido.iq  <br /><span class="excerpt_more"><a href="http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-december-2009/">[continue reading...]</a></span>

<h3>Related Posts</h3>

No related posts.
]]></description>
			<content:encoded><![CDATA[<p> Malicious programs detected on users’ computers</p>
<p>The first Top Twenty lists malicious programs, adware and potentially unwanted programs that were detected and neutralized when accessed for the first time, i.e. by the on-access scanner.</p>
<div align="center">
<table width="75%" cellpadding="4px" cellspacing="0" border="0">
<tr align="center" valign="center" style="font-weight:bold;">
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Position        </td>
<td width="17%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Change in position      </td>
<td width="50%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Name    </td>
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Number of infected computers    </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   1          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.ir     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      265622     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   2          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.iq     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      211101     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   3          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Net-Worm.Win32.Kido.ih     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      145364     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   4          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Sality.aa      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      143166     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   5          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">  Worm.Win32.FlyStudio.cu    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      101743     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   6          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">       New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.GamezTar.a        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      63898      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   7          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.Boran.z           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      61156      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   8          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.Win32.VB.eql     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      61022      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   9          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -1      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.WMA.GetCodec.s           </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      56364      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   10         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">     New      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.Win32.Swizzor.c     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      54811      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   11         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-GameThief.Win32.Magania.cpct        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      42676      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   12         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -3      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Virut.ce       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      45127      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   13         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -3      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Virus.Win32.Induc.a        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      37132      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   14         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Dropper.Win32.Flystud.yo    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      33614      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   15         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_up.gif">       3       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Krap.ag       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      31544      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   16         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -3      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Black.a       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      31340      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   17         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.Mabezat.b       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      31020      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   18         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -2      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Klone.bj      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      28814      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   19         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -7      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Black.d       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      28560      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   20         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -5      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Worm.Win32.AutoRun.dui     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      28551      </td>
</tr>
</table>
</div>
<p>Traditionally, the first Top Twenty is relatively stable and December was no exception.<br />
The appearance of three newcomers in sixth, tenth and eleventh places pushed a few other programs down the rankings. The exception was Packed.Win32.Krap.ag, which first entered the rankings last month, and which rose three places this month. Krap.ag, like other representatives of the Packed family, detects a packing program used to pack malicious programs – in this case, rogue antivirus programs. The figures for this malicious program increased slightly, which suggests that cybercriminals are continuing to actively use these programs to turn a profit.   </p>
<p>GamezTar.a, which entered in sixth place, is a noteworthy December newcomer. This program is presented as being a toolbar for popular browsers which provides quick access to online games. Of course, it also displays irritating adverts. Additionally, it installs a number of applications that run independently of the toolbar and interfere in online activity, whether it’s searching or displaying content. The EULA (www.gameztar.com/terms.do) does cover all these functions, but the user&#8217;s attention is usually focused on the large flashing “click here, get free games” button rather than the almost invisible “terms of service” at the bottom of the screen. It&#8217;s highly recommended to read the EULA (if it exists) before downloading any software.   </p>
<p>Tenth place is taken by Trojan.Win32.Swizzor.c, a relative of Swizzor.b, which made an appearance in the rankings in  August , and Swizzor.a, which dates back to May. The people behind this deftly obfuscated code are not resting on their laurels and regularly create new variants.  The actual function of this Trojan is very simple – it downloads other malicious files from the Internet. </p>
<p>Malicious programs on the Internet</p>
<p>The second Top Twenty presents data generated by the web antivirus component, and reflects the online threat landscape. This ranking includes malicious programs detected on web pages and malware downloaded to victim machines from web pages.</p>
<div align="center">
<table width="75%" cellpadding="4px" cellspacing="0" border="0">
<tr align="center" valign="center" style="font-weight:bold;">
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Position        </td>
<td width="17%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Change in position      </td>
<td width="50%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Name    </td>
<td width="20%" style="border-top:1px solid #BCD9DD;border-bottom:2px solid #FF0000;font-weight:bold;">
Number of attempted downloads    </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   1          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_noch.gif">     0       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Gumblar.x     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      445881     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   2          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_up.gif">       3       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Redirector.l    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      178902     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   3          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.GamezTar.a        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      165678     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   4          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -2      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.HTML.IFrame.sz    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      134215     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   5          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Clicker.JS.Iframe.db        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      128093     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   6          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_down.gif">     -2      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">  not-a-virus:AdWare.Win32.Boran.z    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      109256     </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   7          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Iframe.ez        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      91737      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   8          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Zapchast.bn      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      64756      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   9          </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.JS.Agent.bn         </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      60361      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   10         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Krap.ai       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      43042      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   11         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_up.gif">       8       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Packed.Win32.Krap.ag       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      41731      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   12         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Exploit.JS.Pdfka.asd       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      36044      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   13         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Agent.axe        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      35309      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   14         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Shadraem.a    </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      35187      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   15         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_ret.gif">      Return  </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Popupper.f       </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      33745      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   16         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   not-a-virus:AdWare.Win32.GamezTar.b        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      33266      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   17         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Twetti.a      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      30368      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   18         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.Win32.Lipler.iml        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      28634      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   19         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan-Downloader.JS.Kazmet.d      </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      28374      </td>
</tr>
<tr align="center" valign="center">
<td style="border-bottom:1px solid #BCD9DD;">   20         </td>
<td style="border-bottom:1px solid #BCD9DD;">   <img class="colorbox-26"  src="images/vldesign/top20_new.gif">      New     </td>
<td align="center" style="border-bottom:1px solid #BCD9DD; padding-left:15px;">   Trojan.JS.Agent.axc        </td>
<td align="center" style="border-bottom:1px solid #BCD9DD;">      26198      </td>
</tr>
</table>
</div>
<p>The second Top Twenty has changed far more than the first, with only a quarter of the programs which featured last month remaining in the rankings. One malicious program re-entered the Top Twenty; however, the rest of the table underwent significant changes. </p>
<p>Gumblar.x remains the leader, but the sites infected with this malware are gradually being cleaned up by webmasters – the number of unique download attempts in December was around a quarter of those seen in November.  </p>
<p>Krap.ag, which also figures in the first Top Twenty, moved up 8 places in this ranking. Attempted downloads of this program were up 50% on last month. Just above Krap.ag is Krap.ai, which also detects a dedicated packing program used to pack rogue antivirus programs. </p>
<p>GamezTar.a also makes an appearance in the second Top Twenty. This is unsurprising given the program&#8217;s connection to online games. Moreover, another modification of this malicious program – GamezTar.b – entered the rankings in sixteenth place.</p>
<p>In fifth place is Trojan-Clicker.JS.Iframe.db, a typical iframe-downloader with simple obfuscation.</p>
<p>Trojan.JS.Iframe.ez, Trojan.JS.Zapchast.bn, Packed.JS.Agent.bn, Trojan.JS.Agent.axe, Trojan-Downloader.JS.Shadraem.a, and Trojan-Downloader.JS.Kazmet.d are all scripts designed to exploit vulnerabilities in Adobe and Microsoft products in order to download executable files. These programs vary in terms of sophistication and the complexity of obfuscation employed.</p>
<p>Trojan-Downloader.JS.Twetti.a, in 17th place, is a very interesting example of cybercrime creativity. Lots of legitimate sites have been infected with this malware and it&#8217;s worth taking a closer look at how it works. Once decrypted, there is no trace of a link to the main executable file and no exploits or links to them! Analysis shows that the script uses an API (application programming interface) popular with both cybercriminals and Twitter. </p>
<p>The Trojan works in the following way: it creates a request to the API which results in data on so-called &#8220;trends&#8221; – i.e. the topics most discussed on Twitter. The data returned is then used to create an apparently random domain name, which the cybercriminals have registered in advance having used a similar method, and a redirect to this domain is created. The main part of the malware (whether it&#8217;s a PDF exploit or an executable file) will be placed on the domain. In other words, the malicious link and the redirect are created on the fly via an intermediary, which in this case happens to be Twitter.</p>
<p>It should be noted that both Packed.JS.Agent.bn and Trojan-Downloader.JS.Twetti.a use a specially crafted PDF file to infect users&#8217; computers. This file is detected as Exploit.JS.Pdfka.asd and it also made it into the second Top Twenty, entering in twelfth place. We can therefore assume that at least three of December’s malicious programs were the handiwork of a single cybercriminal gang. Also a cause for concern is that fact that programs from the TDSS, Sinowal and Zbot families  &#8211; some of the most dangerous threats currently in existence &#8211; were detected among the executable files downloaded to victim machines during drive-by attacks.  </p>
<p>Overall, the trends remain the same. Attacks are becoming more sophisticated and more difficult to analyze. Their aim, in the vast majority of cases, is to make money in some way. Virtual threats are no longer purely virtual; they can cause real damage, and this is why is it vital to ensure that your computer and data are protected. </p>


<h3>Related Posts</h3>
<p>No related posts.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.antivirus-advice.com/kaspersky/monthly-malware-statistics-december-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

