Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

TROJANSPY.ZBOT.CSGR

 

 

Name:

TrojanSpy.Zbot.csgr

Added:

December 9, 2011

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Malware problems?   We can help.  Free Removal Tools.

 

 

Description:

 

When TrojanSpy.Zbot.csgr is executed, it performs the following activities:

After execution, it drops the folowing files:

%Appdata%\Ulkofa\puarp.exe
%Appdata%\Yjxe\aheph.ezk.0
%Appdata%\Yjxe\aheph.ezk
%Temp%\tmp9bde7a2c.bat
%Appdata%\Microsoft\Address Book\Administrator.wab

It creates/modifies the following registry entries:

{A8329313-8B25-AD40-99BA-555283C07640}= "%Appdata%\Ulkofa\puarp.exe"
HKU\Software\Microsoft\Windows\CurrentVersion\Run

"puarp.exe" Runs every time Windows start.

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 - Industry Leading Endpoint Security Solution

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4