Skip to main content

BZub.DN

Classification

Category:

Malware

Type:

Trojan-spy

Aliases:

  • BZub.DN

Summary

BZub.DN, a variant of BZub, is a Trojan. BZub.DN creates files in the Windows directory and steals logins, passwords, PINs, check words and other info related to logging to bank websites.

Removal

Technical Details

The BZub.DN trojan was spammed to a large number of people as an attachment to an email message. The attachment name was rechnung.exe, the same file name that was recently used for a spammed variant of Haxdoor backdoor. The trojan drops a keylogger and spies against users of several banks.After being run by the user, the trojan drops three files to the Window System folder. The dropped files represent the main spying component (ipv6monl.dll) and a keylogger (msn.exe and hook.dll). Both spying components are registered to start with every Windows session and remain active in memory at all times. The main spying component steals information related to various on-line banking accounts. Customers of the following banks and on-line payment systems may be affected:

  • Barklays
  • E-Gold
  • Intelligent Finance
  • Nationwide's Internet Bank
  • Postbank

The trojan also steals the following info and sends it to a hacker:

  • HTTP mail password
  • HTTP mail user name
  • IE autocomplete fields data
  • IE protected storage data
  • MSN Explorer signup data
  • Outlook account passwords
  • POP server name
  • POP server password
  • POP server user name
  • SMTP email address

The keylogger records all keystrokes on an infected computer and sends the stolen info to the hacker.

Protect your devices from malware with F‑Secure Total

Protecting your devices from malicious software is essential for maintaining online security. F‑Secure Total makes this easy, helping you to secure your devices in a brilliantly simple way.

  • Award‑winning antivirus and malware protection

  • Online browsing, banking, and shopping protection

  • 24/7 online identity and data breach monitoring

  • Unlimited VPN service to safe­guard your privacy

  • Password manager with private data protection

Choose how many devices you want to protect to get started.

  • Free customer support

  • Cancel anytime

  • The trial does not obligate you to buy the product

After 30 days your subscription will renew automatically for one year at €69.99.

More Support

Community

Ask questions in our Community.

User guides

Check the user guide for instructions.

Contact Support

Chat with with or call an agent.

Submit a Sample

Submit a file or URL for analysis.