Home page logo
/

fulldisclosure logo Full Disclosure mailing list archives

Re: Re: Online Script Decoder
From: Willem Koenings <infsec () gmail com>
Date: Mon, 13 Dec 2004 15:08:32 +0200

It's a trojan-dropper called VBS.Zerolin and it tries to
download an executable file also belonging to the
trojan-downloader family. It is called malware 
Win32.Zdesnado.Y

What that exe file tries to download, I don't know.

hi,

It's a trojan-dropper called VBS.Zerolin and it tries to
download an executable file also belonging to the
trojan-downloader family. It is called malware Win32.Zdesnado.Y

What that exe file tries to download, I don't know.

it's also known as W32/Lowzones.J and Troj/Crabton-B

http://www.sophos.com/virusinfo/analyses/trojcrabtonb.html
http://vi.db.kingsoft.com/virus.php?fid=1597

latter is in simplified chinese, use babelfish to read.

W.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


  By Date           By Thread  

Current thread:
[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]
AlienVault