Home Malware Programs Trojans TROJ_ZBOT.BTM

TROJ_ZBOT.BTM

Posted: February 12, 2010

TROJ_ZBOT.BTM is a banking Trojan that steals confidential information from an infected computer and sends the stolen data to a malicious hacker. TROJ_ZBOT.BTM represents a security risk for any PC system or a network environment. TROJ_ZBOT.BTM will penetrate the system without the user's consent before easily contacting a remote server to download additional parasites onto the infected computer. Symptoms for TROJ_ZBOT.BTM include the computer screen flipping upside down or inverting and documents or messages printing by themselves. For the safety of your computer, TROJ_ZBOT.BTM should be removed immediately.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\lowsec
    2 sdra64.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HKEY..\..\..\..{RegistryKeys}EnableFirewall = "0"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Services\SharedAccess\Parameters\ FirewallPolicy\StandardProfileUID = "{Computer name}_{Random numbers}"Userinit = "%System%\userinit.exe, %System%\sdra64.exe"Windows NT\CurrentVersion\NetworkWindows NT\CurrentVersion\Winlogon
Loading...