Ha bisogno di assistenza? Chieda alla community oppure consulti un esperto.
Vai ad Avira Answers
Virus:TR.Spy.ZBot.cba
Date discovered:20/07/2010
Type:Trojan
In the wild:Yes
Reported Infections:Low
Distribution Potential:Low to medium
Damage Potential:Low to medium
Static file:Yes
File size:221.696 Bytes
MD5 checksum:088971b318b4e048c46175e9004d940D
IVDF version:7.10.09.146 - Wednesday, July 21, 2010

 General Method of propagation:
   • No own spreading routine


Aliases:
   •  Mcafee: Spam-Mailbot.m
   •  Kaspersky: Email-Worm.Win32.Iksmas.htj
   •  Avast: Win32:Bredolab-DL
   •  Microsoft: Trojan:Win32/Malagent
   •  Panda: Bck/Bredolab.AZ
   •  Eset: Bck/Bredolab.AZ
   •  GData: Win32:Bredolab-DL
   •  AhnLab: Worm/Win32.Iksmas
   •  DrWeb: Win32.HLLW.Autoruner.22584
   •  Ikarus: Trojan-Spy.Win32.Fitmu


Platforms / OS:
   • Windows 98
   • Windows NT
   • Windows ME
   • Windows 2000
   • Windows XP
   • Windows 2003
   • Windows Server 2008
   • Windows 7


Side effects:
   • Registry modification

 Files It copies itself to the following location:
   • %APPDATA%\%random character string%.exe

 Registry The following registry key is changed:

– [HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]
   New value:
   • Taskman="%APPDATA%\%random character string%.exe"

 File details Runtime packer:
In order to aggravate detection and reduce size of the file it is packed with a runtime packer.

Descrizione inserita da Carlos Valero Llabata su mercoledì 21 luglio 2010
Descrizione aggiornata da Carlos Valero Llabata su mercoledì 21 luglio 2010

Indietro . . . .
https:// Questa finestra è criptata per tua sicurezza.