Threat Database Trojans TR/BHO.Zwangi.728.trojan

TR/BHO.Zwangi.728.trojan

By SpideyMan in Trojans

TR/BHO.Zwangi.728.trojan is a mischievous trojan infection that will stealthily install on a targeted user's computers without their knowledge. TR/BHO.Zwangi.728.trojan is created to attach and damage the data and files on the computer system, which leads to the improper running of the computer, or failure to access the system. Once the computer is corrupted by TR/BHO.Zwangi.728.trojan, it is possible for attackers to access it remotely and do whatever they want, leaving your files, applications, accounts, and passwords unsafe.

File System Details

TR/BHO.Zwangi.728.trojan may create the following file(s):
# File Name Detections
1. %Temp%\mswinsck.exe
2. %Documents and Settings%\[UserName]\Application Data\av.exe
3. C:\Documents and Settings\\Application Data\
4. C:\Documents and Settings\\

Registry Details

TR/BHO.Zwangi.728.trojan may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run
HKEY_CLASSES_ROOT\secfile
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce 'SelfdelNT'
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion Explorer\ShellFolders Startup="C:\windows\start menu\programs\startup C:\Windows\win.ini
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run '[random string]'
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download 'RunInvalidSignatures' ='1'
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_CLASSES_ROOT\Folder\shellex\ContextMenuHandlers\SimpleShlExt

Trending

Most Viewed

Loading...