Home Malware Programs Trojans Abwiz.e

Abwiz.e

Posted: March 28, 2006

Abwiz.e is a trojan that collects confidential computer information and sends it to a predefined web server. It also secretly downloads and runs arbitrary files. Abwiz.e can be used by the attacker to relay spam e-mail messages. It is able to update itself via the Internet. The trojan runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 sysvcs.exe
    2 zlbw.dll
    3 ~update.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunaupd
Loading...