10/31/2005. - Panda Software has published its ranking of the top ten threats and top ten spyware most frequently detected in October by its online anti-malware solution, Panda ActiveScan, (www.activescan.com).
During this month, the threat that was most frequently detected was the same as the previous month, Sdbot.ftp. This is actually a detection routine for the script used by the SDBot family of worms to download themselves to computers via FTP. In general, the top places are taken by threats that are now regulars in this ranking, such as Netsky.P, a highly damaging worm that first emerged in March 2004 or the genetic detection routine for the very wide-spread family of worms Gaobot. Similarly, Mhtredir.gen, the detection routine for the exploit that uses the vulnerability reported by Microsoft in the bulletin MS04-013 and used by many malware specimens to spread, continues to appear in the ranking.
Alcan.A, a mass-mailing worm, and Cimuz.X, a Trojan that has backdoor functions to allow the affected computer to be used an HTTP proxy, also consolidate their positions in the ranking. One of the main characteristics of this Trojan is that it goes unnoticed by many firewalls, as it injects itself into other processes, usually with full permissions from the firewall to use the network.
The ranking includes both Qhost.CG, which has backdoor functions that allow attacks against the affected computer, and the generic detection routine for the Qhost family of Trojans, a regular in this ranking due to its high rate of propagation. The ranking is completed with Parite.B, a polymorphic virus that infects .EXE (executable) and .SCR (screensavers) files and Smitfraud.D, another virus that injects its code in PE (portable executable) files using different 32-bit operating systems.
Malware % frequency
W32/Sdbot.ftp 3.33
W32/Netsky.P.worm 1.84
W32/Gaobot.gen.worm 1.37
Trj/Qhost.gen 1.19
Exploit/Mhtredir.gen 1.04
W32/Alcan.A.worm 0.84
Trj/Qhost.CG 0.70
W32/Parite.B 0.67
Trj/Cimuz.X 0.63
W32/Smitfraud.D 0.58
In addition to this list, a separate ranking of infections by spyware has been generated. Spyware is a type of malware designed to gather data regarding users’ Internet habits and preferences, which is then sent to the creators of the malware or sold on to third-parties, normally spammers.
The classification of the most widespread spyware over the last month is as follows:
Spyware % frequency
Spyware/New.net 2,14
Spyware/Cydoor 1,63
Spyware/Virtumonde 0,73
Spyware/Dyfuca 0,57
Spyware/BetterInet 0,57
Spyware/Altnet 0,49
Spyware/MarketScore 0,38
Spyware/RXToolbar 0,33
Spyware/Petro-Line 0,24
Spyware/media-motor 0,23
This ranking of the most widely-spread spyware includes New.net. Similarly, two new entries in last month’s list also consolidate their presence: Media-motor and Virtumonde. The new entry this month is RXToolbar, a spyware application that collects information about the affected user’s Internet browsing habits and about the applications installed on the computer. It sends this information to Internet advertising companies, who use this information for their own gain.
To prevent these malware or any other malicious code from affecting your computer, Panda Software recommends keeping antivirus software up-to-date. Panda Software clients can already access the updates to detect and disinfect these malicious code.
For further information about these and other computer threats, visit Panda Software´s Encyclopedia.
About PandaLabs
Since 1990, PandaLabs’ mission has been to analyze new threats as soon as possible to ensure that our clients are safe. Several teams specialized in each specific type of malware (viruses, worms, Trojans, spyware, phishing, spam, etc.) work 24x7 to offer global coverage. To do this they are supported by TruPrevent™ Technologies, a truly global early warning system made up of sensors that are strategically distributed and neutralize new threats and send them to PandaLabs for in-depth analysis. According to AV-Test.org, PandaLabs is the fastest in the industry to offer complete updates (more information at www.pandasoftware.com/pandalabs.asp).
Oxygen3 24h-365d
by Panda Software
Back
Member of IVSZ

Member of SZEK

Acer Affinity Gold partner

Dell Registered Partner
![]()
OKI System Shinrai Partner

XEROX Viszonteladó

APC megbízható szállító

EATON Authorized Partner

Cisco partner

Symantec Software Partner

ESET Partner
![]()
FUJITSU partner

LENOVO Premium Partner

IBM Business Partner

PARTNERS: Computerworld.hu | GameStar.hu | PCWorld.hu | SG.hu | PC Guru | Hitel