Threat Search: 

ThreatExpert's Statistics for Trojan-Spy.Zbot.YETH [PC Tools]:

Trojan-Spy.Zbot.YETH [PC Tools] is also known as:
Threat AliasNumber of Incidents
Trojan Horse [Symantec]11
Trojan-Spy.Win32.Zbot [Ikarus]11
Trojan-Ransom.Win32.BlueScreen.gc [Kaspersky Lab]10
VirTool:Win32/VBInject.gen!CE [Microsoft]10
Trojan-Dropper [Ikarus]9
Infostealer.Banker.C [Symantec]4
Mal/EncPk-LE [Sophos]4
Spy-Agent.bw [McAfee]4
Trojan.Zbot!gen3 [Symantec]4
Trojan-Spy.Win32.Zbot.gen [Kaspersky Lab]4
Trojan-Spy.Win32.Zbot.kdc [Kaspersky Lab]4
W32/Sdbot.worm.gen.ax [McAfee]4
Infostealer [Symantec]3
PWS:Win32/Zbot.gen!R [Microsoft]3
Trojan.Zbot [PC Tools]3
TrojanSpy:Win32/Zbot.gen!C [Microsoft]3
PWS:Win32/Zbot.J [Microsoft]2
Troj/Zbot-BV [Sophos]2
Troj/ZbotPP-Fam, Troj/Zbot-BV [Sophos]2
Trojan.Win32.Agent [Ikarus]2
Win32/Zbot.worm.139776 [AhnLab]2
Downloader [Symantec]1
Generic PWS.y [McAfee]1
Generic.dx [McAfee]1
Generic.dx!mlr [McAfee]1
Generic.dx!noa [McAfee]1
Mal/EncPk-CZ [Sophos]1
Mal/EncPk-FW [Sophos]1
Mal/FakeAV-BT, Mal/EncPk-NP [Sophos]1
Mal/Resdro-A [Sophos]1
Mal/WaledPak-A [Sophos]1
Mal/Zbot-O [Sophos]1
Packed.Generic.232 [Symantec]1
PWS.Win32 [Ikarus]1
PWS:Win32/Zbot.VM [Microsoft]1
PWS:Win32/Zbot.WJ [Microsoft]1
PWS-Zbot [McAfee]1
PWS-Zbot.gen.c [McAfee]1
Ransom!bm [McAfee]1
Spam-Mailbot.m [McAfee]1
Troj/Agent-IGN [Sophos]1
Troj/Agent-IHX [Sophos]1
Troj/Agent-ILE [Sophos]1
Troj/Agent-IOA [Sophos]1
Troj/Agent-JJP [Sophos]1
Troj/Zbot-JQ [Sophos]1
Trojan.Win32.Agent.bepu [Kaspersky Lab]1
Trojan.Win32.Agent.bxlf [Kaspersky Lab]1
Trojan.Win32.Agent.dgid [Kaspersky Lab]1
Trojan.Win32.FraudPack.gle [Kaspersky Lab]1
Trojan.Win32.Malex [Ikarus]1
Trojan.Win32.Zbot [Ikarus]1
Trojan:Win32/Malex.gen [Microsoft]1
Trojan:Win32/Zbot.CA [Microsoft]1
Trojan-Spy.Win32.Zbot.aecp [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.C [Ikarus]1
Trojan-Spy.Win32.Zbot.giv [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.gsv [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.gwi [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.hkp [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.tem [Kaspersky Lab]1
W32.SillyFDC [Symantec]1
Win32.Outbreak [Ikarus]1
Win32/IRCBot.worm.variant [AhnLab]1
Win-Trojan/Agent.84480.CM [AhnLab]1
Win-Trojan/Obfuscator.85504 [AhnLab]1
Win-Trojan/Zbot.79360 [AhnLab]1

Trojan-Spy.Zbot.YETH [PC Tools] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation5

Trojan-Spy.Zbot.YETH [PC Tools] is known to be created as:
%System%\sdra64.exe
%Temp%\0.14196438816008727.exe
%Windir%\system\svchost.exe
%Windir%\win7.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.