Home / malware TrojanDropper:JS/Zlader.B
First posted on 18 November 2015.
Source: MicrosoftAliases :
There are no other names known for TrojanDropper:JS/Zlader.B.
Explanation :
Threat behavior
Installation
This threat might arrive on your PC as an email attachment. We have seen it use the following names:
- ætÑGá-Sá¬Gpad_130-2_132-9_߫ú½Ã¡ÃŸ«Ã³Ã¡¡«_ß_¡Ã¡tá½8¡¿¬«¼_«Gñѽá_»a«Ã±Ã¡ª__Scanned_by_Dr.WÑ£_Çntivirus_163-10_13f850b43c8.tst_.js
- ǬG_ßóÑa¬¿_«G_10.11.2015_ú«Ã±Ã¡___«G»aáó½Ã‘¡«_¬«¡GaáúÑ¡Gp_-_æ«Ãº½Ã¡ÃŸ«Ã³Ã¡¡«_ñ¿aѬG«a«¼_-_ÄÃTÑßGó«_ß_«Ãºaá¡¿tÑ¡¡«¬_«GóÑGßGóÑ¡¡«ÃŸG8e_ÉÑÃpß___2bd55b51050.tst_.js
We have seen this threat create the following file your your PC:
%TEMP% \09093.exe - detected as Ransom:Win32/Zlader.A
Payload
Downloads malware or unwanted software
This threat can download other malware and unwanted software onto your PC. We have seen it install malware from the Trojan:Win32/Zlader family.
Analysis by Donna Sibangan
Symptoms
The following can indicate that you have this threat on your PC:
- You have these files
%TEMP%\09093.exe
ætÑGá-Sá¬Gpad_130-2_132-9_߫ú½Ã¡ÃŸ«Ã³Ã¡¡«_ß_¡Ã¡tá½8¡¿¬«¼_«Gñѽá_»a«Ã±Ã¡ª__Scanned_by_Dr.WÑ£_Çntivirus_163-10_13f850b43c8.tst_.js
ǬG_ßóÑa¬¿_«G_10.11.2015_ú«Ã±Ã¡___«G»aáó½Ã‘¡«_¬«¡GaáúÑ¡Gp_-_æ«Ãº½Ã¡ÃŸ«Ã³Ã¡¡«_ñ¿aѬG«a«¼_-_ÄÃTÑßGó«_ß_«Ãºaá¡¿tÑ¡¡«¬_«GóÑGßGóÑ¡¡«ÃŸG8e_ÉÑÃpß___2bd55b51050.tst_.jsLast update 18 November 2015