Home Malware Programs Trojans Trojan-Spy.Win32.Zbot.gen

Trojan-Spy.Win32.Zbot.gen

Posted: October 20, 2009

Trojan-Spy.Win32.Zbot.gen is a privacy-stealing nasty trojan users might grab when surfing the Web. Trojan-Spy.Win32.Zbot.gen exploits system vulnerabilities to enter users' computer systems to compromise their privacy. Trojan-Spy.Win32.Zbot.gen is able to get on board absolutely unidentified. After entering a user's computer system, this hazardous Trojan would collect user's confidential data which includes user's passwords and banking information and sends it to remote attackers.

Trojan-Spy.Win32.Zbot.gen could also identify backdoors in the system's authentication tools to promote more malware inside a user's PC. While remaining resident in user's cyber environment, Trojan-Spy.Win32.Zbot.gen would track user's keystrokes which results in the tracking of a user's logins, passwords, credit card details, and other personal information. In spite of its primary structure, Trojan-Spy.Win32.Zbot.gen is a critical trojan that could indirectly result in theft of user's money and identity.

Aliases

Spy-Agent.bw.gen.e (McAfee)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\alg.exe
    2 %System%\lowsec\local.ds
    3 %System%\lowsec\user.ds
    4 %System%\lsass.exe
    5 %System%\sdra64.exe
    6 %System%\services.exe
    7 %System%\svchost.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_USERS\.DEFAULT\Software\Microsoft\Protected Storage System ProviderHKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{19127AD2-394B-70F5-C650-B97867BAA1F7}HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\{43BF8CD1-C5D5-2230-7BB2-98F22C2B7DC6}
Loading...