Home Malware Programs Trojans PWS:Win32/Zbot.gen!AJ

PWS:Win32/Zbot.gen!AJ

Posted: September 13, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 6
First Seen: September 13, 2012
OS(es) Affected: Windows

PWS:Win32/Zbot.gen!AJ is a password-stealing Trojan that also opens a back door on the compromised PC and, thus, allows attackers to gain remote access and control over the affected computer. PWS:Win32/Zbot.gen!AJ can reduce the hijacked web browser's security, steal computer data and a victim's personal information such as online banking information, network credentials and browsing history. PWS:Win32/Zbot.gen!AJ is usually spread via spam emails or through hijacked websites. PWS:Win32/Zbot.gen!AJ uses a configuration file to determine the websites that it will steal from when you visit them. PWS:Win32/Zbot.gen!AJ also logs keystrokes and takes screenshots of the corrupted PC. PWS:Win32/Zbot.gen!AJ sends collected data to a predefined FTP or email server, indicated in the configuration file.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%APPDATA%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe File name: %APPDATA%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS].exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
C:\Documents and Settings\<username>\Application Data\iciz\uxqug.exe File name: C:\Documents and Settings\<username>\Application Data\iciz\uxqug.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{Value}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 = "1609" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 = "1406" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 = "1609" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 = "1406" = "0"HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 = "1406" = "0"HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run "C:\Documents and Settings\Administrator\Application Data\iciz\uxqug.exe"
Loading...