Threat description




BZub.DO, a variant of BZub, is a Trojan. BZub.DO creates files in the Windows directory and steals logins, passwords, PINs, check words and other info related to logging to bank websites.


Automatic action

Depending on the settings of your F-Secure security product, it will either automatically delete, quarantine or rename the suspect file, or ask you for a desired action.

More scanning & removal options

More information on the scanning and removal options available in your F-Secure product can be found in the Help Center.

You may also refer to the Knowledge Base on the F-Secure Community site for more information.

Contact Support

F-Secure customers can request support online via the Request support or the Chat forms on our Home - Global site.

Technical Details

The BZub.DO trojan was spammed to a large number of people as an attachment to an e-mail message. The attachment name was rakningen.exe, the same file name that was recently used for a spammed variant of Haxdoor backdoor. The trojan drops a keylogger and spies against users of several banks.After being run by the user, the trojan drops three files to the Window System folder. The dropped files represent the main spying component (ipv6monl.dll) and a keylogger (msn.exe and hook.dll). Both spying components are registered to start with every Windows session and remain active in memory at all times. The main spying component steals information related to various on-line banking accounts. Customers of the following banks and on-line payment systems may be affected:

  • Barklays
  • E-Gold
  • Intelligent Finance
  • Nationwide's Internet Bank
  • Postbank

The trojan also steals the following info and sends it to a hacker:

  • HTTP mail password
  • HTTP mail user name
  • IE autocomplete fields data
  • IE protected storage data
  • MSN Explorer signup data
  • Outlook account passwords
  • POP server name
  • POP server password
  • POP server user name
  • SMTP e-mail address

The keylogger records all keystrokes on an infected computer and sends the stolen info to the hacker.


Detection Type: PC

Database: 2006-09-12_09

Submit a Sample

Suspect a file or URL was wrongly detected? Send it to our Labs for further analysis

Submit a Sample

Give And Get Advice

Give advice. Get advice. Share the knowledge on our free discussion forum.

More Info