Aliases: TR/PSW.Zbot.130560.Y (Avira) Gen:Variant.Zbot.13 (BitDefender) Win32/Spy.Zbot.YW (ESET) Trojan-Spy.Win32.Zbot (Ikarus) Packed.Win32.Krap.hm (Kaspersky) Troj/Zbot-UW (Sophos) TrojanSpy.Zbot.AGZW (VirusBuster) Zeus (other) Zbot (other)
They are part of the Win32/Zbot family.
Use the following free Microsoft software to detect and remove this threat:
- Windows Defender Antivirus for Windows 10 and Windows 8.1, or Microsoft Security Essentials for Windows 7 and Windows Vista
- Microsoft Safety Scanner
- Microsoft Windows Malicious Software Removal Tool
You should also run a full scan. A full scan might find other, hidden malware.
Additional recovery steps
This threat tries to steal your sensitive and confidential information. If you think your information has been stolen, see:
You should change your passwords after you've removed this threat:
This threat might make lasting changes to your PC's settings that won't be restored when it's cleaned. The following steps can help change these settings back to what you want:
- Configuring Security Zone settings for Internet Explorer:
- For Internet Explorer 7 and 8 in Windows Vista
- Enabling the Phishing Filter in Internet Explorer 7, 8 and 9
- For other support and help related articles, go to:
- Microsoft Security TechNet Center
Get more help
If you’re using Windows XP, see our Windows XP end of support page.