Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

TROJANSPY.ZAPCHAST.BP

 

 

 

Name:

TrojanSpy.Zapchast.bp

Added:

July 25, 2011

Type:

Trojan

Risk:

Low

Payload:

N/A

At risk systems:

Windows 95/98/ME/XP/NT/2003

 

 

Description:

 

When TrojanSpy.Zapchast.bp is executed, it performs the following activities:

After execution, it drops the following files:

%Windir%\system32\gbvgbv01.exe
%Windir%\system32\dbr0002.ocx
%Windir%\system32\ddr016.ocx
%Temp%wow01.bat
%Temp%10785e7wow.dat
%Windir%\system32\dsound.dll
%Windir%\system32\New.dll
%Windir%\system32\ddraw.dll
%Windir%\system32\comres.dll
%Windir%\system32\ksuser.dll
%Windir%\system32\olepro32.dll
%Windir%\system32\1001.ocx

It creates/modifies the following registry entries:

Layout File = "kbdus.dll"
HKLM\SYSTEM\ControlSet001\Control\Keyboard Layouts\E0200804

Layout File = "kbdus.dll"
HKLM\SYSTEM\CurrentControlSet\Control\Keyboard Layouts\E0200804

It creates processes with explorer.exe,iexplore.exe and gbvgbv01.exe


 

 

 

 

 

 

 

 
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Malware problems?
We can help.

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

Evaluate Thirtyseven4 Antivirus Now

Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware
Thirtyseven4 Antivirus | AntiMalware | AntiRootkit | AntiSpyware

“Delight yourself in the Lord and he will give you the desires of your heart.” Psalm 37:4