Home Malware Programs Viruses Virus.Dzan.A

Virus.Dzan.A

Posted: January 30, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 59
First Seen: January 30, 2012
OS(es) Affected: Windows

Virus.Dzan.A is a polymorphic virus, which can steal your personal information. Virus.Dzan.A affects Windows computers and destroys personal data. Virus.Dzan.A may use rootkit techniques to hide itself from security applications and, thus, might be difficult to detect and remove from infected computers. Malicious components of Virus.Dzan.A can disable file security, add unknown Start Menu links, compromised processes, and assure that all illegitimate processes are launched with your PC's startup. Virus.Dzan.A can also use cloaked executables such as kasperskytools.exe, server.exe, services.exe, svchost.exe, and explorer.exe in order to establish unauthorized links to remote servers, steal confidential information, use personal accounts for its spreading to other PCs, download other malware threats, delete system's components, remove administrative privileges, cause Internet connection dysfunctions, or even cause complete system damage.

Aliases

Generic Trojan [Panda]SHeur4.NCH [AVG]Trojan-Downloader.Win32.Dapato [Ikarus]Win-Trojan/Dapato.354816 [AhnLab-V3]Trojan/Win32.Dapato.gen [Antiy-AVL]Win32/Ransom.AEP [eTrust-Vet]TR/Crypt.ULPM.Gen [AntiVir]Trojan.Packed.22322 [DrWeb]Heur.Suspicious [Comodo]Trojan.Winlock.N [BitDefender]Trojan-Downloader.Win32.Dapato.brw [Kaspersky]Win32.Yakes.D [eSafe]Win32:Kryptik-GKQ [Trj] [Avast]W32/SuspPack.EC.gen!Eldorado [F-Prot]a variant of Win32/Kryptik.YUO [NOD32]
More aliases (66)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\Policies.exe File name: Policies.exe
Size: 75.26 KB (75264 bytes)
MD5: a7cfe8ee03456d142d9e9c6288df0682
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%
Group: Malware file
Last Updated: February 7, 2012
%WINDIR%\system32\controller.exe File name: controller.exe
Size: 172.03 KB (172032 bytes)
MD5: 573ea3ce67000dbc37a4ab28145092d1
Detection count: 33
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: March 2, 2012
%WINDIR%\system32\wnh.exe File name: wnh.exe
Size: 55.29 KB (55296 bytes)
MD5: 26cf73c57aa7a6d4cbd8a9923ca81ad0
Detection count: 7
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: January 30, 2012
%APPDATA%\ActiveX32_64lo.exe File name: ActiveX32_64lo.exe
Size: 354.81 KB (354816 bytes)
MD5: 1e13c528617c340b226d769ba34d7ca1
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%
Group: Malware file
Last Updated: May 13, 2013
%WINDIR%\SysWOW64\wnh.exe File name: wnh.exe
Size: 55.8 KB (55808 bytes)
MD5: 06a7adea832b63bd3a11a299ea696eb9
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\SysWOW64
Group: Malware file
Last Updated: February 6, 2012
Loading...