VIRUS \ SPYWARE ALERTS - April 8, 2010
by Marianna Schmudlach - 4/8/10 1:42 PM
Troj/Zbot-NV
Aliases
* VirTool:Win32/Obfuscator.GQ
* W32/Bancos.ANGT
* Generic PWS.ew trojan
* Backdoor.Trojan
* Trojan-Spy.Win32.Zbot.afhi
Category
* Viruses and Spyware
Type
* Trojan
Affected operating systems Windows
Protection available since 8 April 2010 18:22:07 (GMT)
roj/Zbot-NV is a Trojan for the Windows platform.
Troj/Zbot-NV includes functionality to:
- run automatically
- copy itself to the <System> folder
- create files in the <System> folder
- access the internet and communicate with a remote server via HTTP
Troj/Zbot-NV communicates via HTTP with the following locations:
windows-update . cn
When Troj/Zbot-NV is installed the following files are created:
<System>\lowsec\local.ds
<System>\lowsec\user.ds
<System>\lowsec\user.ds.lll
<System>\sdra64.exe
Registry entries are set as follows:
more: http://www.sophos.com/security/analyses/viruses-and-spyware/trojzbotnv.html?_log_from=rss

Moderator
CNET Staff
Samsung Staff
Dell Staff