Home Malware Programs Trojans Trojan.Win32.Sasfis.apiz

Trojan.Win32.Sasfis.apiz

Posted: June 28, 2010

Trojan.Win32.Sasfis.apiz is a malicious Trojan that runs in the background and has threat characteristics of a ZBot banking Trojan. Trojan.Win32.Sasfis.apiz disables the firewall and attempts to steal sensitive financial data like credit card numbers, and online banking login details. Trojan.Win32.Sasfis.apiz creates a startup registry entries that load at boot of Windows. Trojan.Win32.Sasfis.apiz is a malicious trojan horse that may represent a severe security risk for the compromised system and/or its network environment and should be removed immediately.

Aliases

Mal/Emogen-Y
Mal/Behav-211
Mal/VB-Z

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\system\lsass.exe
    2 %Windir%\system\winlogon.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\..{RunKeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
Loading...