Home Malware Programs Trojans Trojan.Downloader.Bilakip.A

Trojan.Downloader.Bilakip.A

Posted: January 7, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 393
First Seen: January 7, 2013
Last Seen: June 12, 2019
OS(es) Affected: Windows

Aliases

W32/Zbot.DHN!tr [Fortinet]Troj/Zbot-DPJ [Sophos]Backdoor.Win32.Androm.peq [Kaspersky]Bck/Qbot.AO [Panda]Ransomer.BJP [AVG]W32/LockScreen.AMJ [Fortinet]Trojan-Ransom.Win32.Blocker.aidl [Kaspersky]Artemis!CD5F098E37C4 [McAfee]PSW.Generic10.AYPE [AVG]W32/ZBOT.HL!tr [Fortinet]Artemis!301728C3B296 [McAfee-GW-Edition]Generic PWS.y!1wp [McAfee]Suspicion: unknown virus [AVG]Heuristic.BehavesLike.Win32.Suspicious-BAY.K [McAfee-GW-Edition]PAK_Generic.008 [TrendMicro]
More aliases (174)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\System32\drivers\atapi.sys File name: atapi.sys
Size: 95.36 KB (95360 bytes)
MD5: e9abadcb314b197c6bbb04d10da18b88
Detection count: 159
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\drivers
Group: Malware file
Last Updated: January 14, 2013
%SystemDrive%\Documents and Settings\Den\Local Settings\Application Data\wmiapsvr.exe File name: wmiapsvr.exe
Size: 39.88 KB (39880 bytes)
MD5: cd5f098e37c4f0fcb4c953f5e3941bd4
Detection count: 56
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\Den\Local Settings\Application Data
Group: Malware file
Last Updated: January 14, 2013
%ALLUSERSPROFILE%\Application Data\l.exe File name: l.exe
Size: 71.54 KB (71544 bytes)
MD5: f16b17706dc9030879bf98d88c5ace99
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: January 14, 2013
%APPDATA%\Microsoft\Windows\Templates\CertPolEng.exe File name: CertPolEng.exe
Size: 6.65 KB (6656 bytes)
MD5: 928c5919d1148abb141d702b7d008e30
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Microsoft\Windows\Templates
Group: Malware file
Last Updated: January 14, 2013
%WINDIR%\System32\wdrwzsvc.exe File name: wdrwzsvc.exe
Size: 86.01 KB (86016 bytes)
MD5: 907efa5a6c54699fef4d3d307b541f07
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\System32
Group: Malware file
Last Updated: January 14, 2013
%APPDATA%\9719.exe File name: 9719.exe
Size: 233.47 KB (233472 bytes)
MD5: 8661b5de187a853fc9283bec52c76cc7
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 14, 2013
%WINDIR%\System32\DRIVERS\atapi.sys File name: atapi.sys
Size: 95.36 KB (95360 bytes)
MD5: cd8995e6027c2448eff678adb9185578
Detection count: 9
File type: System file
Mime Type: unknown/sys
Path: %WINDIR%\System32\DRIVERS
Group: Malware file
Last Updated: January 14, 2013
%ALLUSERSPROFILE%\pcdfdata\1jfuweif.exe File name: 1jfuweif.exe
Size: 80.32 KB (80320 bytes)
MD5: 011f8e82a758f0e841a9dc9f7feabb97
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\pcdfdata
Group: Malware file
Last Updated: January 8, 2013
%USERPROFILE%\Lokale Einstellungen\Anwendungsdaten\zomjZbX9ezy2vM\zomjZbX9ezy2vM.dll File name: zomjZbX9ezy2vM.dll
Size: 145.56 KB (145568 bytes)
MD5: 301728c3b296f6a042ec70558ba972e4
Detection count: 9
File type: Dynamic link library
Mime Type: unknown/dll
Path: %USERPROFILE%\Lokale Einstellungen\Anwendungsdaten\zomjZbX9ezy2vM
Group: Malware file
Last Updated: January 14, 2013
%APPDATA%\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#mymembervault.com\odbcconf.exe File name: odbcconf.exe
Size: 307.2 KB (307200 bytes)
MD5: dd5098a4813483f7068c2c72a5deacbf
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#mymembervault.com
Group: Malware file
Last Updated: January 14, 2013
%USERPROFILE%\Local Settings\Temp\msxfauara.exe File name: msxfauara.exe
Size: 49.14 KB (49144 bytes)
MD5: 47d2d1cb12fe30e583b51d42443ade80
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: January 21, 2013
Loading...