The Content you are about to see is only for educational purpose,please do not use this tricks for illegal activities,We are not taking any responsibility for any illegal offence.Thank You .

Search Here

The father of all Trojans found it's name : ZeuS Trojan

The newly discovered ZeuS trojan is a blackmailer, robber and spy—all in one. ZeuS has become widespread only recently though. Investigations by antivirus specialists at Kaspersky Labs have revealed it to the public. It was detected as “gpcode.ai”, a trojan which encodes files on affected
computers and releases them again only after a ransom is paid.
Some details struck the experts, who discovered more to this trojan than first met the eye: gpcode.ai marks its presence with the “_SYSTEM_ 64AD0625_” string in the RAM. This string is suspected to be in many of the latest malware programs. The experts thus tracked down a universal code for pests in gpcode.ai. The code, for instance, can be found in the Bancos.aam trojan through which data of bank accounts can be stolen. It can also be found in the Zhelatin worm, which spreads through email attachments.
A quick glance at the methods used by all these pests identified the name ZeuS. The trojan gets installed in the system as ntos.exe and downloads the files zeus.exe and zupa.exe and connects to the network of infected “bots” already in existence. Zeus.exe is an aggressive snooper. Zupa.exe communicates with the botnet center and receives instructions. According to Kaspersky, one of the ZeuS networks that got shut down comprised of more than 100,000 zombie PCs before it was detected. The fact that ZeuS is established as a commercial tool in the virus scene is no wonder considering the various functions it can carry out: accessing data, and stealing certificates and passwords. It also lures users to phishing sites or adds infected input fields to websites. However, its discovery might also mean its end. The group that developed ZeuS has proclaimed in a forum: “ZeuS is not sold anymore; support for old customers however is still available. Good luck to all." Stumble Delicious Technorati Twitter Facebook

0 comments:

Please Leave a Comment