Home Malware Programs Trojans PWSteal.Zbot.gen!AJ

PWSteal.Zbot.gen!AJ

Posted: January 2, 2013

Threat Metric

Threat Level: 8/10
Infected PCs: 37
First Seen: January 2, 2013
OS(es) Affected: Windows

Aliases

Trj/CI.A [Panda]W32/Zbot.LKA!tr [Fortinet]Trojan-PWS.Win32.Zbot [Ikarus]TR/PSW.Zbot.AJ.3078 [AntiVir]Trojan.PWS.Panda.2977 [DrWeb]UnclassifiedMalware [Comodo]Trojan-Spy.Win32.Zbot.lkqx [Kaspersky]WS.Reputation.1 [Symantec]PWS-Zbot.gen.ary [McAfee]Trojan.PWS.Panda.3115 [DrWeb]Trojan-Dropper.Win32.Dapato.bups [Kaspersky]Artemis!EC7B9AC27C1D [McAfee]Suspicious file [Panda]Generic30.IPT [AVG]Win32:Agent-AQIW [GData]
More aliases (44)

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%TEMP%\RarSFX0\input.exe File name: input.exe
Size: 138.24 KB (138240 bytes)
MD5: ba5bad286c978230ed279d58c50450a3
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %TEMP%\RarSFX0
Group: Malware file
Last Updated: January 8, 2013
%APPDATA%\Iwfov\ilwa.exe File name: ilwa.exe
Size: 274.94 KB (274944 bytes)
MD5: 3462b335100f7eda4e17a61143878f60
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\Iwfov
Group: Malware file
Last Updated: January 5, 2013
%SystemDrive%\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Windows\1620\wmcodecdspps.exe File name: wmcodecdspps.exe
Size: 75.77 KB (75776 bytes)
MD5: ec7b9ac27c1d45d6de20aa80551a2d65
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Documents and Settings\utilisateur\Local Settings\Application Data\Microsoft\Windows\1620
Group: Malware file
Last Updated: January 21, 2013
%SystemDrive%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\mihexa.exe File name: mihexa.exe
Size: 207.36 KB (207360 bytes)
MD5: da5cfc2d67dece1326d7d09e459a8831
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\Users\<username>\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
Group: Malware file
Last Updated: May 13, 2013
Loading...