Home Malware Programs Trojans Trojan.Win32.VB.zbt

Trojan.Win32.VB.zbt

Posted: December 17, 2009

Trojan.Win32.VB.zbt is a malicious Trojan horse or bot that may exhibit a security risk for the compromised system and/or its network environment. Trojan.Win32.VB.zbt is commonly installed without user's cooperation through security exploits, and can seriously compromise a computer system's security. Such dangers may open forbidden network connection, use polymorphic tricks to self-mutate, disable security software, change system files, and install additional malware.

Aliases

Troj/Zbot-GC [Sophos]
Trojan.Win32.VB.zbt [Kaspersky Lab]
Trojan.Generic [PCTools]
VirTool:Win32/VBInject.gen!BP [Microsoft]
Trojan Horse [Symantec]

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %Windir%\rgs.reg

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]HKEY..\..\..\..{RegistryKeys}SetUp = "%Windir%\winlogonn.exe"
Loading...