Trojan.Zbot Description

Trojan.Zbot is a fairly generic backdoor Trojan infection that is closely linked to Mal/VB-AER and the Zeus Trojan, one of the most infamous malware infections. Since 2007, Trojan.Zbot has made headlines when Trojan.Zbot was used to infiltrate and steal information from the Transportation Department of the United States. Since March of 2009, Trojan.Zbot and the Zeus Trojan became widespread, infecting millions of computer from all around the world. ESG security researchers detected thousands of FTP servers of some of the most popular websites that were infected with the Zeus Trojan and Trojan.Zbot. Malware analysts estimate that the botnets associated with Trojan.Zbot cost billions of dollars every year and that a large percentage of phishing messages on Facebook and in spam emails are sent in order to spread malware associated with Trojan.Zbot. In the fall of 2010, the FBI cracked down on the criminal network thought to be responsible for an attack using Trojan.Zbot and the Zeus Trojan that resulted in the theft of more than seventy million dollars from American banks. About ninety people were arrested in relation to these criminal acts in the United States, the Russian Federation, the United Kingdom and Ukraine. In 2011, PC security researchers are facing a serious challenge since the source code of Zeus Trojan and Trojan.Zbot were leaked to the public, enabling practically anyone to use Trojan.Zbot to perform their own attacks.

Is Your Computer System in Danger from Trojan.Zbot?

While malware associated with Trojan.Zbot is not confined to a single area, the five countries with the highest incidence of infection are Mexico, Egypt, Saudi Arabia, the United States and Turkey. As of today, this malware infection is linked to the largest botnets known to PC security researchers. If your operating system is not Windows, then you are safe from Trojan.Zbot. This malware infection can only attack computer system with the Windows Operating system. Users of Windows Vista and Windows Vista SP1 operating systems are particularly vulnerable and form the majority of computer systems integrating this network of infected computers. Each criminal can fine tune their infection in order to steal different data, although Trojan.Zbot is mostly linked to credit card and online banking account information theft. However, these can also be used to steal login information for email or social media accounts.
Aliases: Trojan.Generic.8877826 [nProtect], Generic7_c.BULS [AVG], Artemis!1C946EE5948C [McAfee], TROJ_GEN.RCBCOCU [TrendMicro-HouseCall], AutoIt:MalOb-J [Trj] [Avast], Trojan.Win32.Bublik.akiq [Kaspersky], Trojan.Generic.8877826 (B) [Emsisoft], Trojan.PWS.Stealer.1932 [DrWeb], TR/Rogue.8877826.1 [AntiVir], W32/Bublik.AKIQ!tr [Fortinet], Backdoor.Win32.DarkKomet [Ikarus], a variant of Win32/Injector.Autoit.HN [ESET-NOD32], Trojan/Win32.Jorik [AhnLab-V3], Win32.Troj.Bublik.ak.(kcloud) [Kingsoft] and Heuristic.BehavesLike.Win32.Suspicious-BAY.S [McAfee-GW-Edition].

Infected with Trojan.Zbot? Scan Your PC for Free

Download SpyHunter’s Spyware Scanner
to Detect Trojan.Zbot

Security Doesn't Let You Download SpyHunter or Access the Internet?

Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in 'Safe Mode with Networking' and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

Infection Statistics

Our MalwareTracker shows malware activity across the world. Explore real-time data of Trojan.Zbot outbreaks and other threats from global to local level.

File System Details

Trojan.Zbot creates the following file(s):
# File Name Size MD5 Detection Count
1 %APPDATA%\ohydy.exe 77,824 004010a43054d66bf1d6d32e710ec59e 333
2 %APPDATA%\juzjf.exe 102,400 dfda2db5ed7c417c9fececd8f5f48653 85
3 %USERPROFILE%\userinit.exe 41,472 f01443167573144e3cf25b079a73226d 81
4 C:\bbotxxxxxx.exe\bbotxxxxxx.exe 140,800 02d7b03f126ced200af04cafffbf4f66 18
5 %TEMP%\dc_tmp_path\svchost77.exe 431,104 4063dc3346591414467dea192e4de47d 17
6 C:\sdfjaidhuw.exe\sdfjaidhuw.exe 274,944 a6a2e40b6bfaf60a5f096117a53a5ddb 14
7 %WINDIR%\System32\WinUpdate\server.exe 1,543,665 1c946ee5948c6d23847688c7d5fb8ebd 14
8 %USERPROFILE%\Documents\crss.exe 492,503 733032ca6f13e38740fc4416eee0a0d4 9
9 %SystemDrive%\Users\andrew\AppData\Local\Temp\wgsdgsdgdsgsd.exe 239,040 d4c60f32496ae92c5a53bda45d28937d 8
10 %WINDIR%\Temp\_ex-08.exe 420,864 5e65019a053e88ac9cdd31203d80bbe5 7
11 %LOCALAPPDATA%\DayZCommander\CrashRpt\oshdo.dll 753,152 267433320dc37f9369aef2aeaae68499 4
12 %TEMP%\0.0863059484879578.exe 94,249 b3f35490864b39475bd5d8e9a12a0f08 3
13 C:\Recycle.Bin\Recycle.Bin.exe 350,208 5ed168874559f43720d9a79b20c89d9f 3
14 %TEMP%\0.2778958902928622.exe 94,251 f4f2bd07bfaf360b2ba596d134df76e3 2
15 %COMMONPROGRAMFILES%\rmload.{2227A280-3AEA-1069-A2DE-08002B30309D}\auaucdlve.exe 933,937 cab45be12136d15f2958b1ca575131b4 2

More files

Registry Details

Trojan.Zbot creates the following registry entry or registry entries:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"userinit" = "%UserProfile%\Application Data\sdra64.exe"
The following CLSID's were found:
HKEY..\..\{CLSID Path}
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\"Userinit" = "%System%\userinit.exe, %System%\sdra64.exe"

More Details on Trojan.Zbot

The following URL's were found:
Tip: We recommend blocking the domain names as well as the IP addresses associated with them.

Site Disclaimer

Leave a Reply

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as-is:
What is 6 + 12 ?