TrojanPWS.Zbot.y
Posted: November 30, 2011
Threat Metric
The following fields listed on the Threat Meter containing a specific value, are explained in detail below:
Threat Level: The threat level scale goes from 1 to 10 where 10 is the highest level of severity and 1 is the lowest level of severity. Each specific level is relative to the threat's consistent assessed behaviors collected from SpyHunter's risk assessment model.
Detection Count: The collective number of confirmed and suspected cases of a particular malware threat. The detection count is calculated from infected PCs retrieved from diagnostic and scan log reports generated by SpyHunter.
Volume Count: Similar to the detection count, the Volume Count is specifically based on the number of confirmed and suspected threats infecting systems on a daily basis. High volume counts usually represent a popular threat but may or may not have infected a large number of systems. High detection count threats could lay dormant and have a low volume count. Criteria for Volume Count is relative to a daily detection count.
Trend Path: The Trend Path, utilizing an up arrow, down arrow or equal symbol, represents the level of recent movement of a particular threat. Up arrows represent an increase, down arrows represent a decline and the equal symbol represent no change to a threat's recent movement.
% Impact (Last 7 Days): This demonstrates a 7-day period change in the frequency of a malware threat infecting PCs. The percentage impact correlates directly to the current Trend Path to determine a rise or decline in the percentage.
Threat Level: | 9/10 |
---|---|
Infected PCs: | 53 |
First Seen: | November 30, 2011 |
---|---|
OS(es) Affected: | Windows |
TrojanPWS.Zbot.y is a dangerous Trojan that is included in a United Parcel Service (UPS) spam email pretending that 'A new invoice is now available in the UPS Billing Centre. Please refer to attached file for more details'. The subject of the fake email message is 'Your UPS Invoice is Ready'. The bogus UPS email includes an attachment named 'UPS-Billing-Invoice-Notification-809288436661915.zip'. Each states to come from UPS Billing Center, that you can view, manage and pay your UPS invoices from a single online location. The zip file includes the 'UPS-Bailling_Notification-Details.exe', which is TrojanPWS.Zbot.y, a banking Trojan used to steal banking credentials that involve confidential data such user name, password and credit card number from the victim. By harvesting cookies and accessing other sensitive details, attackers can extract a lot of personal data which can be used to raise their chances to obtain access to the victim's online banking account. If you receive such UPS emails, do not open the attachment. Delete the unsolicited email messages from your inbox as soon as possible.
Technical Details
File System Modifications
Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.
The following files were created in the system:file.exe
File name: file.exeSize: 167.93 KB (167936 bytes)
MD5: 614404754b44bced9d69c8cef4c2b9bf
Detection count: 72
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 1, 2011
file.exe
File name: file.exeSize: 203.26 KB (203264 bytes)
MD5: 9f3f29376b395b1f93abb8a2104782e9
Detection count: 71
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 1, 2011
file.exe
File name: file.exeSize: 200.7 KB (200704 bytes)
MD5: 04351d851538410ab2697bd05852360a
Detection count: 70
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 1, 2011
file.exe
File name: file.exeSize: 193.02 KB (193024 bytes)
MD5: 5d96267e2bbd4c8df6a5849b54e3714b
Detection count: 69
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 1, 2011
file.exe
File name: file.exeSize: 63.48 KB (63488 bytes)
MD5: 987c775c8c2ed5ee3dc72ac5a61a18ce
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 1, 2011
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.