Skip to main content
Skip to main content
Microsoft Security Intelligence
Published Jan 25, 2013 | Updated Sep 15, 2017

PWS:Win32/Zbot.AHD

Detected by Microsoft Defender Antivirus

Aliases: Backdoor.Win32.Androm (Ikarus) Mal/EncPk-AIC (Sophos) PWS-Zbot.gen.ati (McAfee) TR/Spy.ZBot.imgrua (Avira) Trojan-Spy.Win32.Zbot.ikoy (Kaspersky) Win32/Spy.Zbot.ZR (ESET) Worm/Win32.Stekct (AhnLab)

Summary

PWS:Win32/Zbot.AHD is trojan that allows unauthorized access and control of your computer, and steals your valuable information, such as passwords.  PWS:Win32/Zbot.AHD is created by kits known as "Zeus" which are bought and sold on the Internet black market.

PWS:Win32/Zbot.AHD is widespread. It has been distributed and installed on user's computers in several different ways, including:

Visit the Win32/Zbot family description for more details about how this malware is distributed.

To detect and remove this threat and other malicious software that may be installed on your computer, run a full-system scan with an appropriate, up-to-date, security solution. The following Microsoft products detect and remove this threat: 

This malware may attempt to steal sensitive and confidential information from affected you to perpetrate fraud. If you believe that your personal financial information may have been compromised, please refer to the following advisory for additional advice:

Additional remediation instructions for Win32/Zbot

This threat may make lasting changes to a computer's configuration that are NOT restored by detecting and removing this threat. For more information on returning an infected computer to its pre-infected state, please see the following article/s:

System Restore recommendation to revert registry data modifications
 
This malware changes registry data that will not be restored by detecting and removing this threat. To return registry data on an affected computer to its pre-infected state, run System Restore:

This malware may attempt to steal your Microsoft account credentials to spread itself or other malware. If you believe that your account may have been compromised, please refer to the following advisory for additional advice:

Follow us