Trojan-Spy.Win32.Zbot.gtvm Description

Trojan-Spy.Win32.Zbot.gtvm is a Trojan that proliferates via fake emails allegedly coming from Air Canada. The spam Air Canada email that is used to spread Trojan-Spy.Win32.Zbot.gtvm displays a fictitious sender's id 'Air Canada' together with a subject line 'Your Order#74267102 - PROCESSED'. The unsolicited email addressing the computer user as a customer, announces that there has been a perfect processing of the order. Respectively, the details are: Flight Number: TB739 highlight.2CA, Electronic 74267102; Date and Time: 6th December 2012 at 10.30am; Leaving Toronto; and Ticket rate: Canadian Dollars 375.12. Then, the bogus email asks the recipient to download and print out the ticket by visiting the website To find out more about the order, the email message asks the PC user to contact Air Canada at In the end, to express thanks in the name of the Air Canada airlines, the false email signs off. However, the provided URL rather than directing onto the actual website takes the recipient onto a zipped file called 'hxxp://', which when unzipped, creates a huge 175KB file called 'ticketTB7392CA.scr', which encompasses Trojan-Spy.Win32.Zbot.gtvm.

Aliases: Trojan.GenericKDZ.26333 [MicroWorld-eScan], Win32/CInject.RJCCaM [TotalDefense], Trojan.Win32.Zbot.didlmo [NANO-Antivirus], Trojan.Agent [Malwarebytes], PWSZbot-FAFM!94347DEEA558 [McAfee], Win32/Trojan.20f [Qihoo-360], W32.ATVC_OnsurotLTL.Trojan [Bkav], Trojan-Spy.Win32.Zbot.uniq [Kaspersky], Trojan.MalPack [Malwarebytes], Trojan.Win32.Obuvka.Afi [Baidu-International], W32/Rovnix.N!tr [Fortinet], Win32:Agent-AUNJ [Trj] [Avast], Trojan-Spy.Win32.Zbot.uncv [Kaspersky], Troj/HkMain-BM [Sophos] and TR/Crypt.ZPACK.103430 [Avira].

Infected with Trojan-Spy.Win32.Zbot.gtvm? Scan Your PC for Free

Download SpyHunter's Spyware Scanner
to Detect Trojan-Spy.Win32.Zbot.gtvm
* SpyHunter's free version is only for malware detection. If SpyHunter detects malware on your PC, you will need to purchase SpyHunter's malware removal tool to remove the malware threats. Read more on SpyHunter. If you no longer wish to have SpyHunter installed on your computer, follow these steps to uninstall SpyHunter.

Security Doesn't Let You Download SpyHunter or Access the Internet?

Solutions: Your computer may have malware hiding in memory that prevents any program, including SpyHunter, from executing on your computer. Follow to download SpyHunter and gain access to the Internet:
  • Use an alternative browser. Malware may disable your browser. If you're using IE, for example, and having problems downloading SpyHunter, you should open Firefox, Chrome or Safari browser instead.
  • Use a removable media. Download SpyHunter on another clean computer, burn it to a USB flash drive, DVD/CD, or any preferred removable media, then install it on your infected computer and run SpyHunter's malware scanner.
  • Start Windows in Safe Mode. If you can not access your Window's desktop, reboot your computer in "Safe Mode with Networking" and install SpyHunter in Safe Mode.
  • IE Users: Disable proxy server for Internet Explorer to browse the web with Internet Explorer or update your anti-spyware program. Malware modifies your Windows settings to use a proxy server to prevent you from browsing the web with IE.

If you still can't install SpyHunter? View other possible causes of installation issues.

Technical Information

File System Details

Trojan-Spy.Win32.Zbot.gtvm creates the following file(s):
# File Name Size MD5 Detection Count
1 %LOCALAPPDATA%kwlltreh.exe 178,688 81ab0e089471649247d2633e8e7df064 8
2 %LOCALAPPDATA%hkmktvlw.exe 91,648 8f049b422895c0a7435d194cf40e6d5d 6
3 %LOCALAPPDATA%alpodqgx.exe 345,646 437b112abf0dddd41bfcd3809265ab88 3
4 %LOCALAPPDATA%bierdxcm.exe 178,688 3bbc7c0bc5d9fe7de916e0011d977143 3
5 %LOCALAPPDATA%ckolimlx.exe 178,688 651a3ee7b5591c39ebc0f1aa2feb26cb 3
6 %LOCALAPPDATA%epbqbjgu.exe 178,688 513dfa60139ddb57d1463f369001d2d3 3
7 %LOCALAPPDATA%faxrasjm.exe 178,688 5aca5894cf0dcbe7ff4317bc0a86f80b 3
8 %LOCALAPPDATA%fiietoud.exe 178,688 f94f62299eec6f4cbc28f4168c8acfa0 3
9 %LOCALAPPDATA%ihrpwtbq.exe 178,688 911e973a8b4a09332e42c605055cc82a 3
10 %LOCALAPPDATA%jsxwtpie.exe 178,688 94dba098e1f5ffd22edcd962abd113dc 3
11 %LOCALAPPDATA%pgxoomfe.exe 178,688 05f7de4a5cc7085094c934f21c493f4b 3
12 %LOCALAPPDATA%qqshgcps.exe 178,688 dbf3bc78f2be817d023ea357298369d7 3
13 %LOCALAPPDATA%qtvcvnbf.exe 178,688 58f7890100a35993a595d2a87d0fce5b 3
14 %LOCALAPPDATA%ucwfmdlo.exe 345,646 94347deea558def5540476d21369fbb8 3
15 %LOCALAPPDATA%uvlccgsx.exe 345,646 5761e6afba2d7fc9677b87ba314e998d 3
16 hxxp:// N/A
More files

Site Disclaimer

Leave a Reply

Please DO NOT use this comment system for support or billing questions. For SpyHunter technical support requests, please contact our technical support team directly by opening a customer support ticket via your SpyHunter. For billing issues, please refer to our "Billing Questions or Problems?" page. For general inquiries (complaints, legal, press, marketing, copyright), visit our "Inquiries and Feedback" page.

IMPORTANT! To be able to proceed, you need to solve the following simple math.
Please leave these two fields as is:
What is 9 + 5 ?