Worm

W32.Niuniu

W32.Niuniu can propagate via unsecured network shares and removable media storage devices by means of infected .html files. W32.Niuniu will copy itself on available removable media devices and also drops an autorun.inf file that points to a hidden .exe file. More

W32.Niuniu!inf

W32.Niuniu!inf is a detection for files that has been infected with W32.Niuniu. Files identified as W32.Niuniu!inf may propagate by creating a duplicate of itself on removable media devices and unsecured network drives. More

VBS.Stemclover

VBS.Stemclover can disable opening or running various software on the infected computer. It propagates by copying itself to removable media storage devices.  VBS.Stemclover also search for files that has .XLS extension and duplicate them into .VBS file  in order to mislead victims to execute the virus without their knowledge.
More

W32.Stemclover

W32.Stemclover can drop a copy of VBS.Stemclover onto the computer. It spreads by copying itself to network shares and removable media storage devices. W32.Stemclover is also capable of modifying registry entry to allow itself to run every time Windows is started. When executed, it may display the following text messages: More

W32.Badday.A

W32.Badday.A spreads through removable storage devices. This worm can reduce security settings on the infected computer that may disable any installed anti-virus and firewall applications. W32.Badday.A will search for files that are .doc, .mpg, .3pg, .wmv, .rar, .jpg, .txt and creates the same file with the executable extension. This worm can also shut down any opened windows that contains words such as kill, hijack, reg and process to prevent its removal. More

W32.Fleck.A

W32.Fleck.A spreads via unsecured file-sharing networks and is capable of downloading and executing additional threats onto the infected computer. W32.Fleck.A can create its own registry so that it runs every time Windows starts. When loaded, W32.Fleck.A will connect to a remote file-sharing networks to download more threats. More

W32.Yahack.A

W32.Yahack.A propagates via unsecured mapped drives on computer networks. W32.Yahack.A can steal sensitive information by logging keystrokes, gathers system information, and steals Yahoo! Messenger passwords. It will store the gathered data to LogBoy.log under Windows directory and send later to a predefined e-mail address. More