Threat Database Trojans PWS:Win32/Zbot.gen!AJ

PWS:Win32/Zbot.gen!AJ

By GoldSparrow in Trojans

PWS:Win32/Zbot.gen!AJ is a Trojan that steals passwords from affected PC users. PWS:Win32/Zbot.gen!AJ also opens a back door on the affected computer system and, thus, enables cybercriminals to obtain remote access and control over the infected PC. PWS:Win32/Zbot.gen!AJ can decrease the compromised Internet browser's security, steal computer data and personal information such as online banking, email, shopping, and network credentials and information when he/she visits certain websites from affected computer users. PWS:Win32/Zbot.gen!AJ usually propagates via spam emails or through compromised websites. PWS:Win32/Zbot.gen!AJ uses a configuration file to find out the websites that it will steal from when you enter them. PWS:Win32/Zbot.gen!AJ also records keystrokes and takes screenshots of the targeted computer. PWS:Win32/Zbot.gen!AJ transmits gathered information to a predefined FTP or email server, indicated in the configuration file, for remote cybercriminals.

File System Details

PWS:Win32/Zbot.gen!AJ may create the following file(s):
# File Name Detections
1. C:\Documents and Settings\\Application Data\iciz\uxqug.exe
2. %APPDATA%\[RANDOM CHARACTERS]\[RANDOM CHARACTERS]exe

Registry Details

PWS:Win32/Zbot.gen!AJ may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\1 = "1406" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\4 = "1406" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0 = "1609" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 = "1406" = "0"
HKEY_CURRENT_USER\Software\Microsoft\Windows\Currentversion\Run = "", for example "Ryatper" = "%APPDATA%\\.exe", for example "C:\Documents and Settings\Administrator\Application Data\iciz\uxqug.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 = "1609" = "0"

Trending

Most Viewed

Loading...