TROJ_ZBOT.PG |
|
| BugsAlert Home > TROJ_ZBOT.PG | |
|
This Trojan arrives as a downloaded file from a certain URL. It downloads a configuration file from a certain Web site. The said file contains information where the Trojan can download an updated copy of itself, and where to send its stolen data. This configuration file also contains targeted bank-related Web sites to monitor from which it steals information. Once users access any of the monitored sites, this Trojan starts logging keystrokes. It saves gathered information in a file then sends it to a remote site through HTTP post. It creates a mutex to ensure that only one instance of itself is running in memory. It modifies the windows HOST file to restrict user to access certain domains. It checks for the presence of processes which are related to Outpost Personal Firewall and ZoneLabs Firewall Client. It then terminates the said processes. It has rootkit capabilities, which enables it to hide its processes and files from the user. Original Source: http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=TROJ_ZBOT.PG Learn more about TROJ_ZBOT.PG |
|
| Tags: troj zbot.pg | |
Related Items |
|
|
CVE-2008-1923 (Open Source, Asterisk Business Edition, AsteriskNOW, Asterisk Appliance Developer...)
|
|
|
Vuln: Apache Tomcat SSL Anonymous Cipher Configuration Information Disclosure Vulnerability
|
|
|
Microsoft Security Bulletin Summary for September 2008
|
|
|
CVE-2008-0785 (Cacti)
|
|
|
CVE-2008-0681 (phpShop)
|
|
|
CVE-2008-0318 (ClamAV)
|
|
|
TROJ_WIGON.J
|
|