4/29/2005. As with every month, Panda Software has published a list of the ten viruses most frequently detected during the month of April by the online anti-malware solution, Panda ActiveScan. A new version of this tool, which also detects spyware, has recently been made available to users. Based on data collected from this application, Panda Software has also published the Top Ten of the most frequently detected spyware last month.
Malware activity during April was largely split between Trojans and worms, although interestingly enough, the most widespread example of malware was neither of these two, but the detection of a vulnerability for a family of Trojans -the Mhtredir.gen exploit-, which tries to exploit an Outlook Express vulnerability reported by Microsoft in its security bulletin MS04-013. This exploit has regularly appeared in the ranking since it first emerged in August last year.
The rest of the classification is made up of four Trojans, four worms and a backdoor Trojan. In particular, Netsky.P is worth mentioning. This is an email worm that also spreads through P2P programs and exploits a vulnerability in Internet Explorer called Exploit/Iframe. The notable prevalence of Trojans over the last few months has continued this month, in line with the recent trend of attacks motivated by financial returns reported repeatedly by Panda Software of late.
The complete list of viruses and worms and Trojans is as follows:
Name % frequency
Exploit/Mhtredir.gen 3.06
W32/Netsky.P.worm 2.44
Trj/Qhost.AF 2.18
Trj/Shinwow.E 2.02
W32/Sdbot.ftp 1.82
W32/Gaobot.gen.worm 1.11
Trj/Downloader.BSU 1.05
W32/Bagle.CA.worm 1.05
Trj/Citifraud.A 1.02
Bck/Small.HI 0.99
In addition to the ranking, above there is also a classification of infections by spyware, which is without doubt the threat that has flourished most over recent months. Spyware is a type of malware designed to gather data regarding users Internet habits, which is then sent to the creators of the malware or sold on to third-parties, normally spammers.
In many cases, spyware is associated to forms of adware, which modify the browser settings to redirect users to certain websites or cause pop-up adverts to appear.
“Very often the full magnitude of the threat of spyware is not appreciated”, explains Luis Corrons, director of PandaLabs. “The real problem with this type of malware is that in addition to the damage it can cause, which is significant, it steals information, examines users Internet habits and can be an entry point for other types of annoying malware such as adware and dialers, as many types of spyware can download other threats from the Internet.”
The classification of the most widespread spyware over the last month is as follows:
Name % frequency
Spyware/ISTbar 3.97
Spyware/New.net 3.71
Spyware/Cydoor 3.46
Spyware/BetterInet 3.37
Spyware/Altnet 2.52
Spyware/Dyfuca 1.14
Spyware/Petro-Line 0.9
Spyware/MarketScore 0.8
Spyware/Aveo-Attune 0.38
Spyware/YourSiteBar 0.35
ISTbar, like others in the ranking, displays the typical behavior of this kind of malware: the spyware is installed on victims’ computers without their consent (camouflaged as an ActiveX control) and, in turn, installs other similar types of malware: spyware, adware and dialers. Additional functions include displaying pornographic pop-ups, installing a toolbar, and changing the browser home page.
To help as many users as possible scan and/or disinfect their computers when necessary, Panda Software offers Panda ActiveScan, which now also detects spyware, free of charge at http://www.pandasoftware.com. Webmasters who would like to include ActiveScan on their websites can get the HTML code, free of charge, at http://www.pandasoftware.com/partners/webmasters.
Panda Software also offers users Virus Alerts, an e-bulletin in English and Spanish that gives immediate warning of the emergence of potentially dangerous malicious code. To receive Virus Alerts just visit Panda Software´s website (http://www.pandasoftware.com) and complete the corresponding form in the Virus Alerts section.
For more information about these and other malicious code, visit Panda Software´s Virus Encyclopedia.
About PandaLabs
On receiving a possibly infected file, Panda Software´s technical staff get straight down to work. The file is analyzed and depending on the type, the action taken may include: disassembly, macro scanning, code analysis etc. If the file does in fact contain a new virus, the disinfection and detection routines are prepared and quickly distributed to users.
For more information: http://www.pandasoftware.com/virus_info/
Oxygen3 24h-365d, by Panda Software
© Panda Software 2003
Back
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel