BZub.DO, a variant of BZub, is a Trojan. BZub.DO creates files in the Windows directory and steals logins, passwords, PINs, check words and other info related to logging to bank websites.
Based on the settings of your F-Secure security product, it will either move the file to the quarantine where it cannot spread or cause harm, or remove it.
The BZub.DO trojan was spammed to a large number of people as an attachment to an email message. The attachment name was rakningen.exe, the same file name that was recently used for a spammed variant of Haxdoor backdoor. The trojan drops a keylogger and spies against users of several banks.After being run by the user, the trojan drops three files to the Window System folder. The dropped files represent the main spying component (ipv6monl.dll) and a keylogger (msn.exe and hook.dll). Both spying components are registered to start with every Windows session and remain active in memory at all times. The main spying component steals information related to various on-line banking accounts. Customers of the following banks and on-line payment systems may be affected:
The trojan also steals the following info and sends it to a hacker:
The keylogger records all keystrokes on an infected computer and sends the stolen info to the hacker.
Date Created: -
Date Last Modified: -