Home Malware Programs Trojans PWS-Zbot.gen.v

PWS-Zbot.gen.v

Posted: December 15, 2009

PWS-Zbot.gen.v is a Trojan that injects itself into a system process to remain undetected. PWS-Zbot.gen.v can steal sensitive information from infected PCs, including online banking details and other financial data. PWS-Zbot.gen.v may be downloaded from a malicious site or obtained via an infected email. PWS-Zbot.gen.v will then send all the gathered information to a remote attacker. If PWS-Zbot.gen.v is detected on your system, it is advisable to change your online banking details and remove PWS-Zbot.gen.v immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %SysDir%\lowsec\local.ds
    2 %SysDir%\lowsec\user.ds
    3 %SysDir%\lowsec\user.ds.lll
    4 %SysDir%\sdra64.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsNT\CurrentVersion\Winlogon]HKEY..\..\..\..{RegistryKeys}"Userinit" = "C:\WINDOWS\system32\userinit.exe"C:\WINDOWS\system32\sdra64.exe
Loading...