1. /
  2. Security Response/
  3. Trojan.LowZones

Trojan.LowZones

Risk Level 1: Very Low

Discovered:
March 27, 2005
Updated:
April 6, 2005 8:16:31 PM
Type:
Trojan
Systems Affected:
Windows 2000, Windows 7, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Server 2008, Windows Vista, Windows XP
Trojan.LowZones is a detection name used by Symantec to identify malicious programs that share the primary functionality of lowering Internet Explorer security settings.

Internet Explorer has a security model that can be configured by assigning websites and accompanying rules to the following zones:
  • Internet
  • Local intranet
  • Trusted sites
  • Restricted sites




The security policy for each zone can be altered to allow, restrict, or prevent access to certain websites, to control user interface and behavioral features, and to allow, restrict, or prevent the use of technologies such as ActiveX and .NET. Programs detected as Trojan.LowZones alter the Internet Explorer zone settings and therefore lower security settings on the compromised computer.

When Internet Explorer security settings have been lowered, a program may be able to perform the following actions:
  • Run malicious or exploit code
  • Display advertisements
  • Download files
  • Steal information
  • Alter user authentication settings

Programs detected as Trojan.LowZones often arrive bundled with other malware. They may also be used in the early stages of a multi-stage attack.

Users should be aware that changes to security settings made by Trojan.LowZones may also affect other programs that use components of Internet Explorer.

If a Symantec antivirus product displays a detection alert for this threat, it means the computer is already protected and the Symantec product will effectively remove this threat from the computer.

Antivirus Protection Dates

  • Initial Rapid Release version March 27, 2005
  • Latest Rapid Release version May 20, 2013 revision 039
  • Initial Daily Certified version March 27, 2005
  • Latest Daily Certified version May 21, 2013 revision 002
  • Initial Weekly Certified release date March 30, 2005
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 0 - 49
  • Number of Sites: 0 - 2
  • Geographical Distribution: Low
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Low
  • Compromises Security Settings: Lowers Internet Explorer security settings.

Distribution

  • Distribution Level: Low
Writeup By: Henry Bell

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
Internet Security Threat Report, Volume 17
Symantec DeepSight Screensaver