Threat Search: 

ThreatExpert's Statistics for Virus.Win32.Zbot [Ikarus]:

Virus.Win32.Zbot [Ikarus] is also known as:
Threat AliasNumber of Incidents
Infostealer.Banker.C [Symantec]12
PWS:Win32/Zbot.G [Microsoft]7
Trojan.Dropper [Symantec]7
Generic PWS.y [McAfee]5
Mal/EncPk-CZ [Sophos]5
Mal/Generic-A [Sophos]5
PWS-Zbot.gen.c [McAfee]5
Mal/EncPk-GS [Sophos]4
Packed.Generic.196 [Symantec]4
PWS:Win32/Zbot.UB [Microsoft]4
Spy-Agent.bw.gen.e [McAfee]4
Troj/Zbot-T [Sophos]4
Trojan-Spy.Win32.Zbot.btz [Kaspersky Lab]4
TrojanSpy.ZBot.Gen!Pac.4 [PC Tools]4
TrojanSpy:Win32/Zbot.gen!C [Microsoft]4
TSPY_ZBOT.AI [Trend Micro]4
PWS:Win32/Zbot.gen!R [Microsoft]3
VirTool:Win32/CeeInject.gen!Q [Microsoft]3
Win32/IRCBot.worm.variant [AhnLab]3
Backdoor.Win32.SdBot.mur [Kaspersky Lab]2
Backdoor:Win32/Sdbot [Microsoft]2
Troj/ZbotPP-Fam [Sophos]2
Trojan.Win32.Agent2.iwe [Kaspersky Lab]2
Trojan-Spy.Zbot!sd6 [PC Tools]2
W32/Sdbot.worm!g [McAfee]2
W32/Sdbot-DOQ [Sophos]2
Backdoor.Graybird [Symantec]1
Backdoor.Graybird!sd6 [PC Tools]1
Backdoor.IRC.Bot [Symantec]1
Backdoor.Trojan [PC Tools]1
Backdoor.Trojan [Symantec]1
Generic.dx [McAfee]1
Spy-Agent.bw.gen.i [McAfee]1
Troj/ZbotPP-Fam, Mal/EncPk-CZ [Sophos]1
Trojan.Win32.Agent.behr [Kaspersky Lab]1
Trojan.Win32.Agent2.ema [Kaspersky Lab]1
Trojan:Win32/Meredrop [Microsoft]1
Trojan:Win32/Zbot.AQ [Microsoft]1
Trojan-PSW.Win32.LdPinch.adyt [Kaspersky Lab]1
Trojan-Spy.Banker!sd6 [PC Tools]1
Trojan-Spy.Win32.Zbot.gen [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.gsh [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.mms [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.mte [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.mtu [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.mvf [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.njz [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.nps [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.npw [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.oiq [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.ojb [Kaspersky Lab]1
Trojan-Spy.Win32.Zbot.ojx [Kaspersky Lab]1
VirTool:Win32/Injector.gen!N [Microsoft]1
W32/Sdbot.worm!be [McAfee]1
Win-Trojan/Agent.68608.CM [AhnLab]1
Win-Trojan/Agent2.37938 [AhnLab]1
Win-Trojan/Graybird.43355 [AhnLab]1
Win-Trojan/SdBot.99328.B [AhnLab]1
Win-Trojan/Zbot.66048 [AhnLab]1
Worm:Win32/Rimecud.G [Microsoft]1

Virus.Win32.Zbot [Ikarus] has the following possible countries of origin:
OriginNumber of Incidents
Slovakia4
Sweden4

Virus.Win32.Zbot [Ikarus] is known to be created as:
%System%\ntos.exe
%Temp%\ixp000.tmp\reptile.exe
%Temp%\ixp000.tmp\wetwyt.exe
%Windir%\fxstaller.exe
%Windir%\msnmsgrss.exe
%Windir%\msnsmsgrs.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.