Home Malware Programs Trojans Trojan-Spy.Win32.Zbot.biwp

Trojan-Spy.Win32.Zbot.biwp

Posted: September 21, 2011

Threat Metric

Threat Level: 9/10
Infected PCs: 73
First Seen: September 21, 2011
OS(es) Affected: Windows

Trojan-Spy.Win32.Zbot.biwp is a seditious Trojan which spreads via security flaws and targets badly protected computers. Trojan-Spy.Win32.Zbot.biwp records the affected PC user's keystrokes and gathers personal details. Trojan-Spy.Win32.Zbot.biwp usually comes to infected PC system as a self-extracting archive and can download other malicious files. Trojan-Spy.Win32.Zbot.biwp allows cybercriminals to gain remote access to the corrupted machine. Trojan-Spy.Win32.Zbot.biwp can block legitimate anti-virus software and corrupt your web browser through a proxy server. Delete Trojan-Spy.Win32.Zbot.biwp before it damages your computer system.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%Temp%\tmp06b23466.bat File name: %Temp%\tmp06b23466.bat
File type: Batch file
Mime Type: unknown/bat
Group: Malware file
%AppData%\Nahaa\nuysc.tmp File name: %AppData%\Nahaa\nuysc.tmp
File type: Temporary File
Mime Type: unknown/tmp
Group: Malware file
%AppData%\Evhapy\toikf.exe File name: %AppData%\Evhapy\toikf.exe
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
%AppData%\Nahaa\nuysc.bee File name: %AppData%\Nahaa\nuysc.bee
Mime Type: unknown/bee
Group: Malware file

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\{CLSID Path}HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run {0A6EE16D-0E10-C541-5CA9-A1917432F3BA} = ""%AppData%\Evhapy\toikf.exe""HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Privacy CleanCookies = 0x00000000HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PrivacyHKEY_CURRENT_USER\Software\Microsoft\EdiqHKEY_CURRENT_USER\Identities Identity Login = 0x00098053
Loading...