Summary

Summary
Action
More Information
| Affected operating systems | Windows |
|---|---|
| Characteristics |
|
| Included in our products from | May 2008 (4.29) |
| Protection available since | 7 April 2008 08:57:58 (GMT) |
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Please follow the instructions for removing Trojans.
More Information
Troj/Bckdr-ZLB is a backdoor Trojan for the Windows platform, which allows a remote intruder to gain access and control over the computer.
Troj/Bckdr-ZLB copies itself to "<system folder>\drivers\own\".
Troj/Bckdr-ZLB creates rdisk.dll and skeys.dll.
Troj/Bckdr-ZLB creates registry entries
HKLM\SYSTEM\CurrentControlSet\Services\wuauserv\Parameters
ServiceDll
<System Folder>\wauserv.dll
HKLM\SYSTEM\Controlset001\Services\wuauserv\Parameters
ServiceDll
<System Folder>\wauserv.dll
HKLM\SYSTEM\Controlset002\Services\wuauserv\Parameters
ServiceDll
<System Folder>\wauserv.dll
HKLM\SYSTEM\Controlset003\Services\wuauserv\Parameters
ServiceDll
<System Folder>\wauserv.dll
Troj/Bckdr-ZLB downloads and uploads code from internet.
Troj/Bckdr-ZLB sends keyboard record.
