Troj/ZBot-EBJ

Category: Viruses and Spyware Protection available since:28 Feb 2013 10:15:35 (GMT)
Type: Trojan Last Updated:28 Feb 2013 10:15:35 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Examples of Troj/ZBot-EBJ include:

Example 1

File Information

Size
355K
SHA-1
5d3ec00fd32900229af4cf34f2d0745e01ad85ed
MD5
0a2bc96c6cb22f5c4548d09a2509dd67
CRC-32
2881a5c4
File type
Windows executable
First seen
2013-02-28

Runtime Analysis

Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\SpecialAccounts\UserList
    DHCP
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings
    GlobalUserOffline
    0x00000000
Registry Keys Modified
  • HKLM\SYSTEM\CurrentControlSet\Services\SAVAdminService
    Start
    0x00000004
  • HKLM\SYSTEM\CurrentControlSet\Services\SAVService
    Start
    0x00000004
Processes Created
  • c:\windows\system32\net.exe
  • c:\windows\system32\net1.exe

Example 2

File Information

Size
238K
SHA-1
e203a927b2458ee04f5816e3efd09bc79f16bee4
MD5
98fb8d4aa544a328a4dda9ff427fa572
CRC-32
e666fb76
File type
Windows executable
First seen
2013-02-27

download Try Sophos products for free
Download now