Home Malware Programs Trojans Trojan.Win32.Lebag.dcz

Trojan.Win32.Lebag.dcz

Posted: July 22, 2011

Trojan.Win32.Lebag.dcz is a hazardous computer Trojan which invades the PC system secretly and stealthily executes its malicious actions in the background, avoiding detection from the user or any installed security programs. Trojan.Win32.Lebag.dcz can gather and forward your email address book to an email spammer and send unexpected email messages from your computer without your knowledge.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\conime32.exe
    2 [file and pathname of the sample #1]

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\BIFITHKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run[HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Winlogon][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings]
Loading...