Troj/Zbot-DEG

Category: Viruses and Spyware Protection available since:05 Dec 2012 16:54:06 (GMT)
Type: Trojan Last Updated:05 Dec 2012 16:54:06 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Zbot-DEG exhibits the following characteristics:

File Information

Size
361K
SHA-1
cd905850f63b855b02ffc90b7a2d18bdfa6ba304
MD5
87c290f9f57e5daebad4bd2446ddc2f7
CRC-32
99ab5121
File type
Windows executable
First seen
2012-12-05

Runtime Analysis

Modified Files
  • %PROFILE%\Local Settings\Application Data\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Microsoft\Outlook Express\Inbox.dbx
  • %PROFILE%\Local Settings\Application Data\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Microsoft\Outlook Express\Offline.dbx
  • %PROFILE%\Local Settings\Application Data\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Microsoft\Outlook Express\Folders.dbx
Registry Keys Created
  • HKCU\Software\Microsoft\Internet Explorer\Privacy
    CleanCookies
    0x00000000
  • HKCU\Software\Microsoft\Evyp
    Nuduypyh
    □'□□□□`□□□□□ □□□□□□□□□□□□□□□□□□□□□Y□ N□□□□□□□0□□p□□□/□pm□□@□□'□□□□□□□□□□PL□ □□Pt□□□□`□□□J□□□□□h□□D□□q□□□□□\□□□□□j□`□□□□□□□□□□□p□□□{□P□□□□□p□□pQ□ □□@7□0q□□□□□r□□i□□□□□□□□□□@I□
  • HKCU\Identities
    Identity Login
    0x00098053
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Run
    {92228FA9-4936-93A3-50E9-0C292876A1F1}
    "c:\Documents and Settings\test user\Application Data\Detipe\ywlet.exe"
Registry Keys Modified
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0
    1609
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2
    1609
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4
    1609
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1
    1609
    0x00000000
  • HKCU\Software\Microsoft\Windows\CurrentVersion\UnreadMail\user@example.com
    TimeStamp
    3e 62 83 2b c3 d2 cd 01
  • HKCU\Identities\{E2564744-A8ED-497D-924B-A548B20CA034}\Software\Microsoft\Outlook Express\5.0
    Compact Check Count
    0x00000007
Processes Created
  • c:\Documents and Settings\test user\application data\detipe\ywlet.exe
  • c:\windows\system32\cmd.exe
  • c:\windows\system32\ipconfig.exe
HTTP Requests
  • http://208.98.15.15/indexes/setns.bin
  • http://www.google.bg/webhp
  • http://www.google.com/webhp
IP Connections
  • 208.98.15.15:80
DNS Requests
  • www.google.bg
  • www.google.com

download Try Sophos products for free
Download now