Threat Database Spam DHL Express Notification with Trojan PWS-Zbot.gen.cc...

DHL Express Notification with Trojan PWS-Zbot.gen.cc attachment

By Sumo3000 in Spam

DHL Express Notification with the Trojan PWS-Zbot.gen.cc is a dangerous email ported by hackers to spread a Trojan horse known as PWS-Zbot.gen.cc. The DHL Express Notification with the Trojan PWS-Zbot.gen.cc message includes a zip file called DHL_EXPRESS_Notification_Message_NR-167436340.30585700 131966658120.zip and when opened reveals a large executable file named DHL-Delivery-Notification-Message-102611.exe. When executed, the file loads the Trojan horse PWS-Zbot.gen.cc which could ultimately make a system vulnerable to an outside attack. Computer users who may discover the DHL Express Notification with the Trojan PWS-Zbot.gen.cc message and download the attachment are recommended to take immediate action to delete the Trojan that may have installed.

File System Details

DHL Express Notification with Trojan PWS-Zbot.gen.cc attachment may create the following file(s):
# File Name Detections
1. %USERPROFILE%\ Start Menu\ Programs\ Startup\ deyto.exe
2. %USERPROFILE%\ Start Menu\ Programs\ Startup\ doeq.exe
3. %SystemDrive%\ Documents and Settings\ Administrator\ Start Menu\ Programs\ Startup\ gaqaf.exe
4. %USERPROFILE%\ Start Menu\ Programs\ Startup\ xywo.exe
5. %USERPROFILE%\ Start Menu\ Programs\ Startup\ yginm.exe
6. %USERPROFILE%\ Start Menu\ Programs\ Startup\ leny.exe
7. %USERPROFILE%\ Start Menu\ Programs\ Startup\ xavif.exe
8. %SystemDrive%\ Documents and Settings\ Administrator\ Start Menu\ Programs\ Startup\ efnimi.exe
9. %WINDIR%\ system32\ sdra64.exe
10. %WINDIR%\ apppatch\ blbhkda.dat

Trending

Most Viewed

Loading...