Malware

How to remove “Mal/ZAccess-CH”?

Malware Removal

The Mal/ZAccess-CH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/ZAccess-CH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/ZAccess-CH?


File Info:

name: 8B4F64F441B6D1C6A3B8.mlw
path: /opt/CAPEv2/storage/binaries/901e394bc93522f4d4ac0153143238899e5ad3bf758a04d9f9a783c00aa8087b
crc32: 5F88452C
md5: 8b4f64f441b6d1c6a3b83324c537b250
sha1: a94210e783e3d44636c323b751206b14ba176958
sha256: 901e394bc93522f4d4ac0153143238899e5ad3bf758a04d9f9a783c00aa8087b
sha512: 8d26cb0c0d5b2af4815826de0e9dfe2805de3a2b818251152cfdb305386655ed05b608fec3a4cf3b49b397bbe86b45fa05f0fccfc9abc7e3eb7cfd9c9fb1815c
ssdeep: 6144:x5QCCk6OeEIpjtWSHTuylOsV4SzFv++z3g8m0CiZrSy:xmxqeEhYVXzFbDg8TCiZ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16584CFAE2D0C0944D06D3DB74AAB1E72991C5C181B7003677472FAE9BB73F43A856CDA
sha3_384: cd8c07dcc44b0b61ffbc675fc43f2c225ce3964923e3fb8e205904a9f14c16a08dd94e0fcc0ce18bf4338d47135a133f
ep_bytes: 558bec83ec48c745e000000000c745e8
timestamp: 2013-04-29 17:13:47

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Mal/ZAccess-CH also known as:

LionicTrojan.Win32.Generic.lIDA
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Cafiko.1
FireEyeGeneric.mg.8b4f64f441b6d1c6
SkyhighBehavesLike.Win32.PWSZbot.fh
ALYacGen:Variant.Cafiko.1
Cylanceunsafe
ZillyaTrojan.Zbot.Win32.163838
CynetMalicious (score: 100)
K7AntiVirusSpyware ( 0029a43a1 )
BitDefenderGen:Variant.Cafiko.1
K7GWSpyware ( 0029a43a1 )
Cybereasonmalicious.783e3d
BaiduWin32.Trojan.Kryptik.as
VirITTrojan.Win32.Generic.JKK
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanPSW:Win32/ZAccess.56e8f12e
NANO-AntivirusTrojan.Win32.Luder.ddbrpc
RisingStealer.Zbot!8.109D7 (TFE:1:tkfKDReoBOV)
EmsisoftGen:Variant.Cafiko.1 (B)
F-SecureTrojan.TR/Agent.4019201
DrWebTrojan.PWS.Panda.2401
VIPREGen:Variant.Cafiko.1
TrendMicroTROJ_KRYPTK.SML3
Trapminemalicious.high.ml.score
SophosMal/ZAccess-CH
IkarusTrojan-PWS.Win32.Zbot
GDataGen:Variant.Cafiko.1
JiangminWorm.Luder.g
WebrootW32.InfoStealer.Zeus
AviraTR/Agent.4019201
MAXmalware (ai score=100)
Antiy-AVLWorm/Win32.Luder
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.ZBO@4x0xrx
ArcabitTrojan.Cafiko.1
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot!CI
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R64039
McAfeePWS-Zbot-FATG!8B4F64F441B6
DeepInstinctMALICIOUS
VBA32BScope.Malware-Cryptor.SB.01798
MalwarebytesTrojan.Dropper
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SML3
TencentTrojan.Win32.Kryptik.16000652
YandexWorm.Luder!HZS+FdBrRhE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Lockscreen.LOA!tr
BitDefenderThetaGen:NN.ZexaF.36792.yy0@aGAqjxhc
AVGWin32:Karagany
AvastWin32:Karagany
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Mal/ZAccess-CH?

Mal/ZAccess-CH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment