Home Malware Programs Worms Slenfbot.ZC

Slenfbot.ZC

Posted: January 10, 2012

Threat Metric

Threat Level: 5/10
Infected PCs: 126
First Seen: January 10, 2012
OS(es) Affected: Windows

Aliases

Artemis!90E2C7A07B40 [McAfee-GW-Edition]Trojan.Win32.FakeAV.klaj [Kaspersky]W32/Kryptik.ACO!tr [Fortinet]Generic26.BQOE [AVG]Artemis!DA94C01662C6 [McAfee-GW-Edition]Trojan.Win32.FakeAV.kkzf [Kaspersky]a variant of Win32/Kryptik.YXY [NOD32]BackDoor.Gbot.1591 [DrWeb]Gen:Heur.Krypt.6 [BitDefender]a variant of Win32/Kryptik.YXP [NOD32]Trojan.StartPage.41075 [DrWeb]Troj/CycBot-R [Sophos]Gen:Variant.Kazy.50047 [BitDefender]HEUR:Trojan.Win32.Generic [Kaspersky]a variant of Win32/Kryptik.XXM [NOD32]
More aliases (94)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%USERPROFILE%\Local Settings\Application Data\wyq.exe File name: wyq.exe
Size: 347.64 KB (347648 bytes)
MD5: 12adc10bbc7e5b758e6ac9840170e5de
Detection count: 94
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: January 16, 2012
%SystemDrive%\Users\<username>\Local Settings\Application Data\fox.exe File name: fox.exe
Size: 353.28 KB (353280 bytes)
MD5: e2bc92f1023e89ec05b3e3e3b4cbcf43
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\Local Settings\Application Data
Group: Malware file
Last Updated: January 16, 2012
bootcli.exe File name: bootcli.exe
Size: 43.52 KB (43520 bytes)
MD5: 21711d0dfe76e3375b3638fbf4d34d0c
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: January 10, 2012
%APPDATA%\381C3\10029.exe File name: 10029.exe
Size: 200.19 KB (200192 bytes)
MD5: feae306a3d8db1074dc007d5a5300f89
Detection count: 47
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\381C3
Group: Malware file
Last Updated: January 13, 2012
%USERPROFILE%\Local Settings\Application Data\gsn.exe File name: gsn.exe
Size: 325.63 KB (325632 bytes)
MD5: 380839fa6f99583ec8ba12551072f4b9
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: January 16, 2012
%ALLUSERSPROFILE%\Application Data\fgks.exe File name: fgks.exe
Size: 316.41 KB (316416 bytes)
MD5: da94c01662c65665df8313c097d90c5b
Detection count: 36
File type: Executable File
Mime Type: unknown/exe
Path: %ALLUSERSPROFILE%\Application Data
Group: Malware file
Last Updated: January 16, 2012
%USERPROFILE%\Local Settings\Application Data\rtk.exe File name: rtk.exe
Size: 300.54 KB (300544 bytes)
MD5: 90e2c7a07b40b9b282fdcb4b6dfca344
Detection count: 26
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: January 16, 2012
%APPDATA%\14E2E\B50CD.exe File name: B50CD.exe
Size: 180.73 KB (180736 bytes)
MD5: 62e7990761c697e1bbd861487afeb498
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\14E2E
Group: Malware file
Last Updated: January 13, 2012
%PROGRAMFILES(x86)%\LP\D10B\29C.exe File name: 29C.exe
Size: 291.32 KB (291328 bytes)
MD5: 43cb5b2de64366ebc8a764b471134832
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\LP\D10B
Group: Malware file
Last Updated: January 16, 2012
%APPDATA%\0C834\4F3F7.exe File name: 4F3F7.exe
Size: 174.59 KB (174592 bytes)
MD5: 8f7762e38c7f590e28e7820e345d21ba
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\0C834
Group: Malware file
Last Updated: January 16, 2012
%PROGRAMFILES(x86)%\LP\E04C\F30.exe File name: F30.exe
Size: 285.69 KB (285696 bytes)
MD5: f2aa4f4581133ac2e28d3866dfa5664c
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %PROGRAMFILES(x86)%\LP\E04C
Group: Malware file
Last Updated: January 11, 2012
%USERPROFILE%\Local Settings\Application Data\aug.exe File name: aug.exe
Size: 337.92 KB (337920 bytes)
MD5: 889011596ec4031e8201769a6323ebb1
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: January 13, 2012
%APPDATA%\5CE00\A0DBD.exe File name: A0DBD.exe
Size: 174.59 KB (174592 bytes)
MD5: 703e0e059971737082b2130811e600c6
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\5CE00
Group: Malware file
Last Updated: January 16, 2012
%USERPROFILE%\Local Settings\Application Data\duy.exe File name: duy.exe
Size: 330.75 KB (330752 bytes)
MD5: 77b65274c83a3da3ad4debbb1763ca78
Detection count: 0
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\Local Settings\Application Data
Group: Malware file
Last Updated: January 16, 2012
Loading...