TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
TSPY_ZBOT.MCS
Overview

QUICK LINKS  

Download the latest scan engine


TypeSpyware

In the wild: Yes

Destructive: No

Language: English

Systems affected: Windows NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:

Low

Reported detections:

Low

System  impact:

High

Information exposure:

High

 

Description:

This spyware arrives as a file downloaded from a remote URL.

It drops a copy of itself in the Windows system folder and appends garbage code to the dropped copy to avoid easy detection. It creates a folder with attributes set to System and Hidden to prevent users from discovering and removing its components. It then creates non-malicious files. It modifies a registry entry to enable its automatic execution at system startup. It also injects itself into processes as part of its memory residency routine.

It attempts to access a Web site to download a file which contains information where the spyware can download an updated copy of itself, and where to send its stolen data. This configuration file also contains a list of targeted bank-related Web sites from which it steals information. Note that the contents of the file, hence the list of Web sites to monitor, may change any time.

It attempts to steal sensitive online banking information, such as user names and passwords. This routine risks the exposure of the user’s account information, which may then lead to the unauthorized use of the stolen data.

It saves the stolen information in a file. It sends the gathered information via HTTP POST to a remote URL.

It accesses a remote site to download its configuration file. The downloaded file contains information where it can download an updated copy of itself, and where to send its stolen data.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jul 13, 2009




Tell us how we did. Take our quick survey.