Threat Search: 

ThreatExpert's Statistics for Trojan.Zbot [Ikarus]:

Trojan.Zbot [Ikarus] is also known as:
Threat AliasNumber of Incidents
Infostealer.Banker.C [Symantec]4
Mal/Generic-A [Sophos]3
PWS:Win32/Zbot.gen!R [Microsoft]2
Troj/Agent-LCX [Sophos]2
Trojan Horse [Symantec]2
Trojan:Win32/Malat [Microsoft]2
Trojan-Dropper.Win32.Agent.bbkm [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.aahv [Kaspersky Lab]2
Win-Trojan/Agent.90112.PC [AhnLab]2
Win-Trojan/Zbot.91648.B [AhnLab]2
Backdoor.Win32.Bredolab.mr [Kaspersky Lab]1
Generic PWS.y!ti [McAfee]1
HeurEngine.MaliciousPacker [PC Tools]1
Mal/FakeAV-AX [Sophos]1
Packed.Generic.264 [Symantec]1
PWS:Win32/Dipwit.A [Microsoft]1
Trojan.Win32.FraudPack.vtk [Kaspersky Lab]1
Trojan-Banker.Win32.Bancos.glo [Kaspersky Lab]1
W32/Xirtem@MM [McAfee]1
Win-Trojan/Fraudpack.2082304.B [AhnLab]1

Trojan.Zbot [Ikarus] is known to be created as:
%CommonAppData%\fcc6\windowsedefender.exe
%System%\sdra64.exe
%Temp%\sdra64.exe
Notes:
  • %CommonAppData% is a variable that refers to the file system directory containing application data for all users. A typical path is C:\Documents and Settings\All Users\Application Data.
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).