Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | April 2008 (4.28) |
| Protection available since | 14 February 2008 21:56:16 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Zbot-E is a Trojan for the Windows platform.
When Troj/Troj/Zbot-E is installed it copies itself to <System>\ntos.exe but with varying amounts of appended data.
The following registry entry is changed to run ntos.exe on startup:
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\ntos.exe,
Troj/Zbot-E also attempts to download files to the folder <System>\wsnpoem\.
When first installed, Troj/Zbot-E attempts to launch Microsoft Internet Explorer to the site americangreetings.com to try to hide the fact that it has been downloaded by Troj/Flamgo-A.
