Home Malware Programs Trojans PWS.Win32/Zbot.gen!W

PWS.Win32/Zbot.gen!W

Posted: April 13, 2011

PWS.Win32/Zbot.gen!W is a password stealer trojan infection that exploits security vulnerabilities to control your activities and gather stolen usernames, passwords and other personal details from your infected computer. PWS.Win32/Zbot.gen!W may enable a criminal remote access to an affected computer system, and execute various operations. Once PWS.Win32/Zbot.gen!W invades your PC system, it can record your confidential data, such as credit card information, login numbers, etc. PWS.Win32/Zbot.gen!W is a privacy threat that should not be trusted but terminated immediately upon detection with a reputable anti-spyware program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\lowsec\local.ds
    2 %System%\lowsec\user.ds
    3 %System%\lowsec\user.ds.lll
    4 %System%\sdra64.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon]Userinit =[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders] Cookies = History =
Loading...