Additional Details
Trojan:W32/Agent.DKJC identifies files involved in a recent spam run. On running the malicious file, a Zeus/Zbot variant is installed.
This malware is further discussed in our Labs Weblog:
DistributionThe spam run involves malicious ZIP files distributed using varying file names. Names seen so far include:
ActivityManually executing the malicious ZIP file causes a variant from the Trojan-Spy:W32/Zbot family to install on the machine. For more information on Zeus/Zbot capabilities, please see the
Trojan-Spy:W32/Zbot description.
The malware also downloads additional components from two Russian websites:
• jocudaidie.ru
• zephehooqu.ru
Note: Browsing Protection blocks access to these malicious sites.