Home Malware Programs Trojans DDoS:Win32/Abot.A

DDoS:Win32/Abot.A

Posted: July 24, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 2,862
First Seen: July 24, 2012
Last Seen: January 4, 2023
OS(es) Affected: Windows

Aliases

Generic28.BJPK [AVG]W32/Gimemo.UJX!tr [Fortinet]Spyware/Win32.Zbot [AhnLab-V3]DDOS/Abot.A.22 [AntiVir]Mal/EncPk-AEM [Sophos]Trojan.Generic.KDV.639602 [BitDefender]Trojan-Ransom.Win32.Foreign.oyq [Kaspersky]W32/Trojan2.NSII [F-Prot]Generic.lg [McAfee]Trojan.Abot.a.cw3 [CAT-QuickHeal]Trojan/Win32.Agent [AhnLab-V3]TR/Dldr.Delphi.Gen [AntiVir]Win32.HLLW.Autoruner1.34021 [DrWeb]TrojWare.Win32.TrojanDownloader.Delf.gen [Comodo]Mal/Generic-S [Sophos]
More aliases (338)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



The Frozen Throne\support\config.exe File name: config.exe
Size: 23.44 MB (23444992 bytes)
MD5: e0f09885de40b79f2d1d0048831b705c
Detection count: 426
File type: Executable File
Mime Type: unknown/exe
Path: The Frozen Throne\support
Group: Malware file
Last Updated: January 4, 2023
%PROGRAMFILES(x86)%\NetNucleous\ActiveCollector\ACRecover.exe File name: ACRecover.exe
Size: 65.53 KB (65536 bytes)
MD5: cec983679b5fab7ed888d6a67c6a2b03
Detection count: 119
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\NetNucleous\ActiveCollector
Group: Malware file
Last Updated: July 26, 2012
%ALLUSERSPROFILE%\rltwlcofax.exe File name: rltwlcofax.exe
Size: 340.99 KB (340992 bytes)
MD5: 2f5a0f64c5ea8fae5432374e7e47dc8a
Detection count: 83
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%
Group: Malware file
Last Updated: July 26, 2012
%PUBLIC%\R-344233-5553-2-32\update32.exe File name: update32.exe
Size: 339.96 KB (339968 bytes)
MD5: 09f784075f84323c622b8f38024fde44
Detection count: 73
File type: Executable File
Mime Type: unknown/exe
Path: %PUBLIC%\R-344233-5553-2-32
Group: Malware file
Last Updated: July 26, 2012
%APPDATA%\Apple_Store.exe File name: Apple_Store.exe
Size: 288.25 KB (288256 bytes)
MD5: f28f9cb1ff043c109797454bde26e269
Detection count: 51
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 8, 2013
%APPDATA%\syncservicex86.exe File name: syncservicex86.exe
Size: 182.78 KB (182784 bytes)
MD5: 783f7468c4ad210a1adf7b6ac93d4297
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: October 15, 2012
%SystemDrive%\Users\<username>\AppData\Roaming\WinArchiver.exe File name: WinArchiver.exe
Size: 243.2 KB (243200 bytes)
MD5: 372de6bda8a083dd65898c3ace61af8f
Detection count: 35
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming
Group: Malware file
Last Updated: October 5, 2012
%TEMP%\8879686.dll File name: 8879686.dll
Size: 57.34 KB (57344 bytes)
MD5: b59151d6015a6ba2f74edeb03064f929
Detection count: 32
File type: Dynamic link library
Mime Type: unknown/dll
Path: %TEMP%
Group: Malware file
Last Updated: July 26, 2012
%APPDATA%\FSnapshot_x86.exe File name: FSnapshot_x86.exe
Size: 230.91 KB (230912 bytes)
MD5: 884b42cf729e59240f6438c9f4108eee
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: October 5, 2012
%APPDATA%\Apple_Store.exe File name: Apple_Store.exe
Size: 235 KB (235008 bytes)
MD5: 2ae166c2abc5e380c35dea3ab7a8d7f1
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: August 27, 2012
%WINDIR%\SysWOW64\config\systemprofile\AppData\Roaming\ram_reserver64.exe File name: ram_reserver64.exe
Size: 182.78 KB (182784 bytes)
MD5: f8eeecb3c9ea0ace4e485fd1611fa1ab
Detection count: 23
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64\config\systemprofile\AppData\Roaming
Group: Malware file
Last Updated: November 12, 2012
%PROGRAMFILES(x86)%\WinSoft\WinSecure.exe File name: WinSecure.exe
Size: 109.05 KB (109056 bytes)
MD5: e8e7bf41bc0b3bd9491d169533d0547b
Detection count: 14
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\WinSoft
Group: Malware file
Last Updated: March 29, 2013
%APPDATA%\WASHINGTONPC\wx2.cpl File name: wx2.cpl
Size: 839.68 KB (839680 bytes)
MD5: e8c1cb48ca7c5753f3fef5bcabfe2fe3
Detection count: 7
Mime Type: unknown/cpl
Path: %APPDATA%\WASHINGTONPC
Group: Malware file
Last Updated: July 26, 2012
%PUBLIC%\svhost.exe File name: svhost.exe
Size: 164.07 KB (164079 bytes)
MD5: e4fdc6e8d33d276b64c20780fecab86e
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PUBLIC%
Group: Malware file
Last Updated: July 26, 2012
%WINDIR%\tasks\SA.bat File name: SA.bat
Size: 12 KB (12001 bytes)
MD5: 3079238ed23f7d8f90067f14c816c4b4
Detection count: 5
File type: Batch file
Mime Type: unknown/bat
Path: %WINDIR%\tasks
Group: Malware file
Last Updated: July 26, 2012
%APPDATA%\itunes_service01.exe File name: itunes_service01.exe
Size: 268.8 KB (268800 bytes)
MD5: fd3f7aaef6b290ac4c1d6ebcb36209c9
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: January 5, 2013
Loading...