Home Malware Programs Trojans TSPY_ZBOT.AZL

TSPY_ZBOT.AZL

Posted: February 15, 2010

TSPY_ZBOT.AZL is an information stealing banking Trojan. Once installed on your computer, TSPY_ZBOT.AZL represents a serious security threat. TSPY_ZBOT.AZL scans your PC for passwords, particularly for online banking sites, and will steal these passwords and send them to malicious hackers. TSPY_ZBOT.AZL will also attempt to intercept and transmit your sign-in information, other cached Windows passwords and email account passwords. TSPY_ZBOT.AZL is extremely dangerous and should be removed immediately once detected.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System Root%\Documents and Settings\All Users\Application Data\Microsoft\Windows\Network

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HKEY..\..\..\..{RegistryKeys}LoadAppInit_DLLs = "1"RequireSignedAppInit_DLLs = "0"Windows NT\CurrentVersion\Windows
Loading...