Home Malware Programs Trojans Mal/ZbotTemp-A

Mal/ZbotTemp-A

Posted: January 11, 2010

Mal/ZbotTemp-A is a Trojan keylogger program that can steal confidential details like credit card numbers, etc. Mal/ZbotTemp-A is capable of modifying the host file and restricting access to security websites. Mal/ZbotTemp-A may be installed via fake or misleading means, without the user's full awareness or agreement. Have Mal/ZbotTemp-A removed from the system using a reliable anti-virus program.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\stu2.exe
    2 %System%\twex.exe
    3 %Temp%\ie2.tmp
    4 %Temp%\ie3.tmp
    5 %Temp%\in1.tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
Loading...