HOME / CONTACT
 
  Home > Malware Cyclopedia > Malware Info.
 Malware Info.
FAQ
Download

 Trojan@W32.FraudPa...
 Trojan@W32.Obfusca...
 Trojan@W32.Zbot.34
 Virus@W32.Sality
 Trojan@W32.Zbot.26
Malware Info. Malware Cyclopedia
Trojan@W32.Dybalom
Dybalom trojan spread by 'GGreat USB Antibody' crack version.

'GGreat USB Antibody' crack version in the internet, it's malware.
Dybalom trojan in the malware, will disable 'security center' and 'UAC' function.

If you want download or order, please to offical website, don't to any unclear website.

Offical download website:
http://www.cuoday.com.tw/GGreat_USB_Antibody.exe

http://download.cnet.com/GGreat-USB-AntiBody/3000-2239_4-10964357.html?tag=mncol


Offical order website:
http://search.buy.yahoo.com.tw/gdsearch.php?hpp=gdsearch&kw=ggreat+usb+antibody&catsel=&btn_srch=&z=0&subno=0

http://shopping.pchome.com.tw/?m=search&f=doSearch&STYPE=&c=I00&target=GGreat+USB+AntiBody&searchType=
ST_0A&priceRange=

http://www.ggreat.com.tw/po-usbabgg.asp


Newest activity:
http://www.ggreat.com.tw/usbabs/apply.htm
Aliases : Trojan-PSW.Win32.Dybalom.qv [Kaspersky Lab]
Type : Trojan
Date Discovered : 2009/10/13
System Affected : Windows 95/98/ME, Windows NT/2000/XP/2003/Vista
 Risk Assessment
Distribution : High
Damage : Medium
 Character

None

  Description

  ●Modify the following registry file, disable 'security center' and 'UAC' function:
   HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\
   UACDisableNotify: 0x00000001
   HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\
   system\EnableLUA: 0x00000000


  ●Modify the following registry file, it will execute when service start:
   HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\kmixer\Enum\
   0: "SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-
   A195-0020AFD156E4}"
   HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\kmixer\Enum\
   0: "SW\{b7eafdc0-a680-11d0-96d8-00aa0051e51d}\{9B365890-165F-11D0-
   A195-0020AFD156E4}"


 solution None
<Back