live casino online

TSPY_QBOT.N

October 08, 2012
 Analysis by: Roland Marco Dela Paz

 ALIASES:

Microsoft : Backdoor:Win32/Qakbot.gen!A; Kaspersky : Trojan-PSW.Win32.Qbot.pk

 PLATFORM:

Windows 2000, XP, Server 2003

 OVERALL RISK RATING:
 REPORTED INFECTION:
 SYSTEM IMPACT RATING:
 INFORMATION EXPOSURE:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: Yes

  • In the wild: Yes

  OVERVIEW

This Trojan arrives as a file that exports the functions of other malware/grayware. It may be dropped by other malware.

It requires its main component to successfully perform its intended routine.

  TECHNICAL DETAILS

File Size:

Varies

Memory Resident:

Yes

Initial Samples Received Date:

12 Nov 2010

Arrival Details

This Trojan arrives as a file that exports the functions of other malware/grayware.

It may be dropped by the following malware:

Other Details

This Trojan requires its main component to successfully perform its intended routine.

  SOLUTION

Minimum Scan Engine:

8.900

VSAPI OPR PATTERN File:

7.617.00

VSAPI OPR PATTERN Date:

12 Nov 2010

Step 1

For Windows XP and Windows Server 2003 users, before doing any scans, please make sure you to allow full scanning of your computer.

Step 2

Remove malware files dropped/downloaded by TSPY_QBOT.N

Step 3

Scan your computer with your live casino online product and note files detected as TSPY_QBOT.N

Step 4

Restart in Safe Mode

[ Learn More ]

Step 5

Search and delete the file detected as TSPY_QBOT.N

[ Learn More ]
Please make sure you check the Search Hidden Files and Folders checkbox in the More advanced options option to include all hidden files in the search result.