Mal/Zbot-EZ

Category: Viruses and Spyware Protection available since:05 Dec 2011 22:44:02 (GMT)
Type: Malicious behavior Last Updated:20 Jun 2012 18:55:14 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Mal/Zbot-EZ include:

Example 1

File Information

Size
191K
SHA-1
0064fdaa88fbd0cf47fade2618620175dd4aa48d
MD5
2fe2fd683dd07d860fe9162b1aaf5be4
CRC-32
286df85a
File type
application/x-ms-dos-executable
First seen
2012-01-22

Example 2

File Information

Size
100K
SHA-1
006a6ba08d3d4f1c08bbb359545793867b2d1aec
MD5
c2712c8d3701bdcdff7c3b0f6c3bb88f
CRC-32
cb42d643
File type
application/x-ms-dos-executable
First seen
2012-01-18

Runtime Analysis

Dropped Files
  • C:\Documents and Settings\All Users\Application Data\common.data
    Size
    544
    SHA-1
    c2a4c455ba407bc72b45b87816b273051965c4e2
    MD5
    202e60a0c6a151aa075a00b1833fd148
    CRC-32
    592a507a
    File type
    Unspecified binary - probably data
    First seen
    2011-08-09
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
    AutoStart
    c:\test_item.exe
DNS Requests
  • a.mx.mail.yahoo.com

Example 3

File Information

Size
224K
SHA-1
00829f61d401551ef60390b6ea1649f9d1ba5d3e
MD5
313910627cc9eceeaf6c1af73a952e58
CRC-32
6c9d4a6f
File type
application/x-ms-dos-executable
First seen
2012-01-22

download Try Sophos products for free
Download now