Threat Search: 

ThreatExpert's Statistics for PWS:Win32/Zbot.M [Microsoft]:

PWS:Win32/Zbot.M [Microsoft] is also known as:
Threat AliasNumber of Incidents
Trojan-Spy.Win32.Zbot.gen [Kaspersky Lab]69
Mal/Zbot-O, Mal/EncPk-CZ [Sophos]49
Packed.Generic.232 [Symantec]31
Trojan-Spy.Win32.Zbot [Ikarus]23
Mal/EncPk-CZ [Sophos]20
Infostealer.Banker.C [Symantec]14
Trojan Horse [Symantec]12
HeurEngine.MaliciousPacker [PC Tools]11
Infostealer [Symantec]10
Mal/EncPk-HZ [Sophos]10
Troj/Zbot-FG [Sophos]6
PWS-Zbot [McAfee]5
Trojan.Win32.Pakes [Ikarus]4
Trojan.Win32.Pakes.njm [Kaspersky Lab]4
Trojan-Spy.Win32.Zbot.snb [Kaspersky Lab]4
Trojan-Spy.Win32.Zbot.sot [Kaspersky Lab]4
Win-Trojan/Agent.62976.DR [AhnLab]4
Win-Trojan/Downloader.72192.N [AhnLab]4
Win-Trojan/Zbot.66560.S [AhnLab]4
Mal/Generic-A [Sophos]3
Trojan-Spy.Zbot!sd6 [PC Tools]3
Win-Trojan/Pakes.75264.D [AhnLab]3
FakeAlert-DA [McAfee]2
Generic Dropper.kj [McAfee]2
Generic PWS.y!f [McAfee]2
Mal/EncPk-IF [Sophos]2
Mal/EncPk-IF, Mal/EncPk-HH [Sophos]2
Mal/EncPk-KH [Sophos]2
Packed.Generic.218 [Symantec]2
PWS-Zbot.gen.e [McAfee]2
Spy-Agent.du [McAfee]2
Troj/Agent-JUZ [Sophos]2
Trojan.Gpcoder.E [Symantec]2
Trojan.Win32.FakeXPA [Ikarus]2
Trojan.Win32.Winwebsec [Ikarus]2
Trojan-Banker.Win32.Bancos [Ikarus]2
Trojan-PSW.Generic [PC Tools]2
Trojan-Spy.Banker!sd6 [PC Tools]2
Trojan-Spy.Win32.Zbot.aafl [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.aamf [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.rxp [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.ryj [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.rzj [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.spv [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.tiu [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.wfh [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.yiq [Kaspersky Lab]2
W32.SillyFDC.BBK [Symantec]2
Win32/IRCBot.worm.variant [AhnLab]2
Win-Trojan/Xema.variant [AhnLab]2
Win-Trojan/Zbot.62464.F [AhnLab]2
Win-Trojan/Zbot.67584.C [AhnLab]2
Win-Trojan/Zbot.67584.D [AhnLab]2
Win-Trojan/Zbot.91136.F [AhnLab]2
Gen.Trojan [Ikarus]1
Generic PWS.y [McAfee]1
Generic PWS.y!a [McAfee]1
Generic PWS.y!g [McAfee]1
Generic PWS.y!xb [McAfee]1
Generic PWS.y!xu [McAfee]1
Mal/TibsPk-A, Mal/TibsPk-D [Sophos]1
Mal/TibsPk-D [Sophos]1
Troj/Agent-JNR [Sophos]1
Troj/Agent-JNZ [Sophos]1
Troj/Agent-JQF [Sophos]1
Troj/Zbot-FJ [Sophos]1
Trojan-Spy.Win32.Zbot.spo [Kaspersky Lab]1
Win-Trojan/Zbot.62464.AD [AhnLab]1
Win-Trojan/Zbot.62976.AI [AhnLab]1
Win-Trojan/Zbot.71680.E [AhnLab]1

PWS:Win32/Zbot.M [Microsoft] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation1

PWS:Win32/Zbot.M [Microsoft] is known to be created as:
%System%\sdra64.exe
%Temp%\dhl_id8612.exe
%Temp%\tmp.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).