Home Malware Programs Trojans Trojan.Zbot!gen2

Trojan.Zbot!gen2

Posted: November 10, 2009

Trojan.Zbot!gen2 is a nasty Trojan horse that gains access to a computer through vulnerabilities that have been created by other malicious Trojans and backdoor computer viruses. Once inside your system, Trojan.Zbot!gen2 will open up a backdoor through which a hacker can access your PC and perform various malicious tasks. Trojan.Zbot!gen2 includes a keyboard monitor that records all keystrokes into a file, which can later on be taken by a remote attacker. Trojan.Zbot!gen2 poses a serious risk to the security and privacy of your personal and financial data, and it is recommended that Trojan.Zbot!gen2 be eliminated immediately.

Aliases

Mal/EncPk-LE, Mal/Behav-353 (Sophos)
PWS:Win32/Zbot.gen!R (Microsoft)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %System%\lowsec\local.ds
    2 %System%\lowsec\user.ds
    3 %System%\sdra64.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon][HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders]
Loading...