Home Malware Programs Trojans PWSteal.Zbot.AHY

PWSteal.Zbot.AHY

Posted: March 26, 2013

Threat Metric

Ranking: 16,303
Threat Level: 8/10
Infected PCs: 393
First Seen: March 26, 2013
Last Seen: March 4, 2025
OS(es) Affected: Windows

Aliases

Downloader.Generic13.AMUW [AVG]Troj/MSIL-BQ [Sophos]Trojan-Downloader.Win32.Andromeda.tvt [Kaspersky]Heuristic.LooksLike.Win32.Suspicious.J [McAfee-GW-Edition]Packed.Win32.MUPX.Gen [Comodo]Artemis!7A204E55AA9B [McAfee]Trj/CI.A [Panda]Generic7_c.BJNS [AVG]W32/Injector_Autoit.GI [Fortinet]Trojan.Win32.Scarsi [Ikarus]PWS:Win32/Zbot.AHY [Microsoft]Trojan/Win32.Chifrax.gen [Antiy-AVL]Heuristic.BehavesLike.Win32.Suspicious-BAY.K [McAfee-GW-Edition]TR/Agent.838335 [AntiVir]BackDoor.Comet.152 [DrWeb]
More aliases (30)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



D:\PROGRAMM WIN\TCPU59\Programm\DrWeb\DrWU\DrWU.exe File name: DrWU.exe
Size: 166.91 KB (166912 bytes)
MD5: 7a204e55aa9be2c249e1481c665ba203
Detection count: 187
File type: Executable File
Mime Type: unknown/exe
Path: D:\PROGRAMM WIN\TCPU59\Programm\DrWeb\DrWU\DrWU.exe
Group: Malware file
Last Updated: March 4, 2025
%ALLUSERSPROFILE%\Local Settings\Temp\msfmpg.cmd File name: msfmpg.cmd
Size: 100.86 KB (100864 bytes)
MD5: 87986222882a10e2d8357fa0f32df808
Detection count: 38
Mime Type: unknown/cmd
Path: %ALLUSERSPROFILE%\Local Settings\Temp
Group: Malware file
Last Updated: April 2, 2013
%USERPROFILE%\652386\svhost.exe File name: svhost.exe
Size: 838.33 KB (838335 bytes)
MD5: 6e1a83b6dad2dcd2b3b9321f7931f395
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: %USERPROFILE%\652386
Group: Malware file
Last Updated: March 29, 2013
Loading...