Mal/Zbot-JF

Category: Viruses and Spyware Protection available since:18 Nov 2012 05:32:34 (GMT)
Type: Malicious behavior Last Updated:21 Jun 2013 01:21:06 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Mal/Zbot-JF include:

Example 1

File Information

Size
224K
SHA-1
001392364300c45e3afabef0f90180cf6af08190
MD5
4b5dcd705b1e63990fa410c4eb9c1830
CRC-32
6c49ff4a
File type
Windows executable
First seen
2007-07-27

Runtime Analysis

Registry Keys Created
  • HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    NoAutoUpdate
    0x00000001
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    mpsoup
    c:\Documents and Settings\test user\mpsoup.exe /k
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Advanced
    ShowSuperHidden
    0x00000000
DNS Requests
  • ns1.helpchecks.com

Example 2

File Information

Size
227K
SHA-1
01ad766f051826f67a5491ce0165c3e4071819e6
MD5
7efd8cbd23aacc1138d52d63edc32665
CRC-32
145c3b1d
File type
Windows executable
First seen
2012-09-20

Runtime Analysis

Copies Itself To
  • c:\Documents and Settings\test user\Application Data\uAlwp.exe
Registry Keys Created
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    KmRXW
    c:\Documents and Settings\test user\Application Data\uAlwp.exe

Example 3

File Information

Size
268K
SHA-1
01d3dba4985b08ab482a0aaa7ca328ddd1fe0e18
MD5
5d74139091b91bbcb08c91e4d90e0452
CRC-32
78954340
File type
Windows executable
First seen
2012-05-29

download Try Sophos products for free
Download now