Sophos

Troj/Zbot-E

Aliases
  • Trojan-Spy.Win32.Zbot.agq
  • TR/Spy.ZBot.agq
  • TSPY_ZBOT.DF
  • Infostealer.Banker.C
Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Included in our products from April 2008 (4.28)
Protection available since 14 February 2008 21:56:16 (GMT)
Detected by All Sophos products

Action

More Information

Troj/Zbot-E is a Trojan for the Windows platform.

When Troj/Troj/Zbot-E is installed it copies itself to <System>\ntos.exe but with varying amounts of appended data.

The following registry entry is changed to run ntos.exe on startup:

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Userinit
<System>\userinit.exe,<System>\ntos.exe,

Troj/Zbot-E also attempts to download files to the folder <System>\wsnpoem\.

When first installed, Troj/Zbot-E attempts to launch Microsoft Internet Explorer to the site americangreetings.com to try to hide the fact that it has been downloaded by Troj/Flamgo-A.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer