Home Malware Programs Worms Mal/Zbot-U

Mal/Zbot-U

Posted: May 25, 2010

Mal/Zbot-U is a network-aware computer worm which attempts to replicate across existing networks. Mal/Zbot-U requests malicious files from the Internet and has the ability to send out email messages with a built-in SMTP client engine which can send private emails directly to a recipient mail server for malicious purposes. Mal/Zbot-U contains characteristics of an identified security risk and should be removed from the system.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\qtplugin.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Setup]HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...