Home Malware Programs Trojans Trojan-Spy.Win32.Zbot.apqa

Trojan-Spy.Win32.Zbot.apqa

Posted: March 7, 2011

Aptly named, Trojan-Spy.Win32.Zbot.apqa is a Trojan horse and a keylogger. The Trojan-Spy.Win32.Zbot.apqa infection can not only download even more infections onto your PC, Trojan-Spy.Win32.Zbot.apqa can also steal personal information from your keyboard's keystrokes while doing so! This causes Trojan-Spy.Win32.Zbot.apqa to be a terrible risk for computer users with vulnerable passwords and account logins, but this Trojan is bad news for anyone who wants a secure and safe PC. If this infection turns up on your system, don't rest until you've deleted Trojan-Spy.Win32.Zbot.apqa down to every last Registry entry and file.

Trojan-Spy.Win32.Zbot.apqa's One Part Trojan, One Part Spy

Trojan-Spy.Win32.Zbot.apqa will infect PCs without the awareness of the computer's users and then attempt to run itself just as furtively. By making changes to the Windows Registry, Trojan-Spy.Win32.Zbot.apqa can run with Windows without any outer display of Trojan-Spy.Win32.Zbot.apqa's functions. Be watchful for extra memory processes in your Task Manager, but not all malware will even leave meager evidence like that behind.

Common attacks used by Trojan-Spy.Win32.Zbot.apqa infections are as follows:

  • The installation of other malware, evident primarily in the sudden appearance of unusual files and programs. The types of malware a Trojan like Trojan-Spy.Win32.Zbot.apqa can install can extend nearly infinitely. Frequently-seen possibilities are spyware which steal information unobtrusively, remote administration tools that serve as assistants for remote attackers, browser hijackers and rogue anti-malware applications that create false positive infection alerts.
  • Keylogging and other spying-related activities. Trojan-Spy.Win32.Zbot.apqa can monitor everything typed on your keyboard, record this to a log and then send the log out to a remote criminal. This is one common method by which online bank accounts and game accounts are often lost, as the login details are easily compromised.
  • Crashing applications related to anti-malware security or to system maintenance (like the Registry Editor, Task Manager, et cetera). Most Trojans, including Trojan-Spy.Win32.Zbot.apqa, will routinely disable these programs to some extent; after all, if these programs weren't disabled, the infection would be caught and removed pretty quickly!
Taking Your PC Back from Trojan-Spy.Win32.Zbot.apqa

Computers that are suffering under a Trojan-Spy.Win32.Zbot.apqa infection should be rebooted into Safe Mode to prevent any malware from running in the background. Afterwards, you can use an appropriate anti-malware application to scan for and delete Trojan-Spy.Win32.Zbot.apqa and any other viruses, worms or other malware.

To increase your chances of a complete deletion of Trojan-Spy.Win32.Zbot.apqa, be sure your security programs are totally up to date and use multiple brands of scanners. Never assume that the Trojan-Spy.Win32.Zbot.apqa infection is truly gone until you've rebooted and a full scan comes up empty; keyloggers like Trojan-Spy.Win32.Zbot.apqa can do great damage while being nearly invisible if you underestimate their tenacity.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %AppData%\Otuk\addec.tmp
    2 %AppData%\Otuk\addec.uhp
    3 %AppData%\Yzhuvi\fyiqm.exe
    4 %PROGRAM_FILES%\Trojan-Spy.Win32.Zbot.apqa
    5 %Temp%\tmp28c9c259.bat
    6 c:\Documents and Settings\All Users\Start Menu\Trojan-Spy.Win32.Zbot.apqa \
    7 c:\Documents and Settings\All Users\Trojan-Spy.Win32.Zbot.apqa \

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\PrivacyHKEY_CURRENT_USER\Software\Microsoft\WeeraHKEY_LOCAL_MACHINE\Software\Trojan-Spy.Win32.Zbot.apqa[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run]
Loading...