Home Malware Programs Trojans Troj/Zbot-BUS

Troj/Zbot-BUS

Posted: May 4, 2012

Threat Metric

Threat Level: 9/10
Infected PCs: 37
First Seen: May 4, 2012
OS(es) Affected: Windows

Troj/Zbot-BUS is a Trojan that is a part of a spam email attack associated with the Better Business Bureau (BBB). The spam email claims to come from the Better Business Bureau (BBB) with the aim of infecting Windows computers with Troj/Zbot-BUS. The fake email includes a malicious attachment, the 'BBB Report.zip' file, that contains Troj/Zbot-BUS. The emails differ in their words, but all declare that a consumer has complained about the company receiving the email. The details of the complaint, of course, are included into the attached malicious file. If a PC users opens the attached malicious file, his/her computer is corrupted by Troj/Zbot-BUS. You should remove Troj/Zbot-BUS immediately after detection with a genuine anti-malware tool.

Technical Details

Registry Modifications

The following newly produced Registry Values are:

HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run SunJavaUpdateSched = C:\Documents and Settings\All Users\svchost.exe
Loading...