Home Malware Programs Worms Zombaque.A

Zombaque.A

Posted: November 30, 2010

Threat Metric

Threat Level: 5/10
Infected PCs: 115
First Seen: November 30, 2010
Last Seen: May 9, 2019
OS(es) Affected: Windows

Zombaque.A (Worm:Win32/Zombaque.A) is a worm that circulates to other computers through the Radmin application. Zombaque.A attempts to spread to other PCs by guessing effective user names and passwords. Once Zombaque.A has proliferated, it makes the affected computer part of a botnet. Zombaque.A turns the targeted PC into a node in a botnet, which is composed of other computers also affected by Zombaque.A. Once installed, Zombaque.A makes system changes by downloading potentially malicious files and creating the registry entries so that it can runs automatically as a service.

Aliases

Trj/CI.A [Panda]BackDoor.Generic13.GFT [AVG]Win32/Zombaque.worm.318464 [AhnLab-V3]Worm/Zombaque.A.1 [AntiVir]TrojWare.Win32.Agent.~aja [Comodo]Trojan.Generic.KD.44843 [BitDefender]Win32:Malware-gen [Avast]EmailWorm [K7AntiVirus]W32/Autorun.worm.h [McAfee]BackDoor.Generic13.GRH [AVG]W32/Zombaque.A!worm [Fortinet]Worm.Win32.Zombaque [Ikarus]Worm/Win32.Zombaque [AhnLab-V3]Worm:Win32/Zombaque.A [Microsoft]Worm/Win32.Zombaque.gen [Antiy-AVL]
More aliases (44)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%WINDIR%\system32\ipz.exe File name: ipz.exe
Size: 318.46 KB (318464 bytes)
MD5: 4cabbdec75761fb44b1ad7de00cdd64e
Detection count: 91
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: November 30, 2010
%WINDIR%\system32\ipz.exe File name: ipz.exe
Size: 318.46 KB (318464 bytes)
MD5: 1160f4c2ccd5f86014c998886a7c1a7c
Detection count: 21
File type: Executable File
Mime Type: unknown/exe
Path: %WINDIR%\system32
Group: Malware file
Last Updated: December 6, 2010
Loading...