Zeus 1.0.2.11
(Trojan-Spy.Win32.Bancos.aam)
(Trojan-Spy.Win32.Bancos.avj)

by ?

Written in

Released in May 2007

Made in Russia

  
More Information                                                                              

Server Dropped Files: c:\WINDOWS\system32\ntos.exe Size: 413,696 bytes c:\WINDOWS\system32\wsnpoem\audio.dll Size: 133 bytes Added to Registry: HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run "userinit" Data: C:\WINDOWS\system32\ntos.exe HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run "userinit" Data: C:\WINDOWS\system32\ntos.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon "Userinit" Old data: C:\WINDOWS\system32\userinit.exe, New data: C:\WINDOWS\system32\userinit.exe,C:\WINDOWS\system32\ntos.exe, Tested on Windows XP August 03, 2008

MegaSecurity