Home Malware Programs Trojans TR/Spy.ZBot.RU

TR/Spy.ZBot.RU

Posted: March 6, 2012

Threat Metric

Threat Level: 8/10
Infected PCs: 30
First Seen: March 6, 2012
OS(es) Affected: Windows

TR/Spy.ZBot.RU is a malicious Zbot Trojan that is involved in a spam campaign related to DHL. The spam DHL email includes a DHL Shipment Express tracking report and has an archive attached, which contains TR/Spy.ZBot.RU. The only file in the zip archive is an executable and carries the same name as the archive, which is 'DHL-Worldwide-Delivery_Notification_Feb_032012_7902366.zip'. If you receive a fake DHL email, do not open its malicious attachment.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



DHL-Worldwide-Delivery_Notification_Feb032012__7902366.zip File name: DHL-Worldwide-Delivery_Notification_Feb032012__7902366.zip
Size: 133.81 KB (133818 bytes)
MD5: 8c3a62d62b958274d24fe0e20599cba1
Detection count: 53
Mime Type: unknown/zip
Group: Malware file
Last Updated: March 12, 2012
DHL-Worldwide-Delivery_Notification.exe File name: DHL-Worldwide-Delivery_Notification.exe
Size: 164.86 KB (164864 bytes)
MD5: 071d766e3df86006e15db2dc2d91b6c5
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: March 12, 2012
Loading...