Troj/Zbot-DRI

Category: Viruses and Spyware Protection available since:01 Feb 2013 07:06:53 (GMT)
Type: Trojan Last Updated:01 Feb 2013 07:06:53 (GMT)
Prevalence: Small Number of Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

Troj/Zbot-DRI exhibits the following characteristics:

File Information

Size
74K
SHA-1
7f7b4520565f090e79c32320a9482bd42694688e
MD5
30edf62eec7dcbc4688a7fe618077dad
CRC-32
6dfdb918
File type
Windows executable
First seen
2013-02-01

Runtime Analysis

Copies Itself To
  • F:/RECYCLER/R-1-5-21-1482476501-1644491937-682003330-1013/hostsv.exe
Dropped Files
  • F:/RECYCLER/R-1-5-21-1482476501-1644491937-682003330-1013/Desktop.ini
Modified Files
  • C:\RECYCLER
    • Set the readonly flag
Registry Keys Created
  • HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
    Taskman
    c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\hostsv.exe
DNS Requests
  • tv.zabetwo.com

download Try Sophos products for free
Download now