Home Malware Programs Trojans Trojan.Picebot

Trojan.Picebot

Posted: February 5, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 54
First Seen: February 5, 2013
OS(es) Affected: Windows

Trojan.Picebot is a Trojan that downloads other PC threats onto the affected computer system. Once executed, Trojan.Picebot copies itself to the particular location of the infected computer system and adds the run key. Trojan.Picebot disables the User Account Control (UAC) and Task Manager. Trojan.Picebot collects OS information and transmits it to the particular domains. Trojan.Picebot downloads and runs potentially malicious files from the particular web addresses.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



file.exe File name: file.exe
Size: 102.4 KB (102400 bytes)
MD5: bb89a045060b19db744381dda26f103a
Detection count: 29
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: February 11, 2013
%Windir%\iexplorer.exe File name: %Windir%\iexplorer.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"iexplorer" = "C:\WINDOWS\iexplorer.exe"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System\"DisableTaskmgr" = 1HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system\"EnableLUA" = 0
Loading...