Spy Trojan

How to remove “MemScan:Trojan.Spy.ZBot.EPA”?

Malware Removal

The MemScan:Trojan.Spy.ZBot.EPA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Spy.ZBot.EPA virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time

How to determine MemScan:Trojan.Spy.ZBot.EPA?


File Info:

crc32: 03B985F5
md5: 66044d9d35d6da7521d5bd4d3d0f3c09
name: upload_file
sha1: 82e252d6d90f6f9b3380f339823e6cfdf9e9a4a3
sha256: e0f986f757f76ddb07e207943416c63ea8d26149fbf06c6d76eb892439d15346
sha512: 71655a4959dfab4d9238a7eb4ceee04306dd5c47f6c074bc5dd619706bcb95a45936e8e6ab9af3b583d3346296bba0277221847ab97c5176647c9218821d3596
ssdeep: 3072:AGqgqPdJHZVjNE2R8g7sPKsarKS034NR+8+JAaPONspGsqKCCoQ/ywE:Xqg+JHfTGh2I8+J+Nr/K5K
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Pygoga
InternalName: Uhip
CompanyName: Bientyawahnyav
LegalTrademarks: Maudysisurneoms
ProductName: Dyvoedsoefa
FileDescription: Cebo
OriginalFilename: Uklaric
Translation: 0x0409 0x04b0

MemScan:Trojan.Spy.ZBot.EPA also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanMemScan:Trojan.Spy.ZBot.EPA
CAT-QuickHealTrojanPWS.Zbot.Y
McAfeePWS-Zbot.gen.be
CylanceUnsafe
VIPRETrojan-PWS.Win32.Zbot.gen.y (v)
AegisLabTrojan.Win32.Generic.l8T4
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderMemScan:Trojan.Spy.ZBot.EPA
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.d35d6d
ArcabitTrojan.Spy.ZBot.EPA
TrendMicroTROJ_KRAP.SMDA
CyrenW32/Zbot.AE.gen!Eldorado
SymantecTrojan.Zbot
APEXMalicious
KasperskyTrojan-Spy.Win32.Zbot.gen
AlibabaTrojanSpy:Win32/ATRAPS.ca58036a
NANO-AntivirusTrojan.Win32.Zbot.cmyck
SUPERAntiSpywareTrojan.Agent/Gen-Cryptor
TencentWin32.Trojan-spy.Zbot.Wlyy
Ad-AwareMemScan:Trojan.Spy.ZBot.EPA
EmsisoftMemScan:Trojan.Spy.ZBot.EPA (B)
ComodoTrojWare.Win32.Spy.Zbot.ABV@1qlk7c
F-SecureTrojan.TR/ATRAPS.Gen2
DrWebBackDoor.Siggen.16668
ZillyaTrojan.Zbot.Win32.23654
InvinceaML/PE-A + Mal/FakeAV-CX
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
MaxSecureTrojan.Malware.7175482.susgen
FireEyeGeneric.mg.66044d9d35d6da75
SophosMal/FakeAV-CX
IkarusPacker.Win32.Krap
JiangminTrojanSpy.Zbot.adnk
WebrootW32.Malware.Gen
AviraTR/ATRAPS.Gen2
GridinsoftSpy.Win32.Keylogger.oa
MicrosoftPWS:Win32/Zbot.gen!Y
ViRobotTrojan.Win32.Z.Zbot.169984
ZoneAlarmTrojan-Spy.Win32.Zbot.gen
GDataMemScan:Trojan.Spy.ZBot.EPA
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R1982
Acronissuspicious
VBA32SScope.Trojan.FakeAV.01110
ALYacMemScan:Trojan.Spy.ZBot.EPA
MAXmalware (ai score=100)
PandaTrj/Sinowal.XCJ
ESET-NOD32Win32/Spy.Zbot.QT.Gen
TrendMicro-HouseCallTROJ_KRAP.SMDA
RisingTrojan.Generic@ML.98 (RDML:SS/ryQQql/9iWYUDJ50h/A)
YandexTrojanSpy.Zbot.Gen!Pac.25
SentinelOneDFI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Zbot.TES!tr
BitDefenderThetaAI:Packer.0558268516
AVGWin32:Zbot-MSU [Trj]
AvastWin32:Zbot-MSU [Trj]
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.Spy.056

How to remove MemScan:Trojan.Spy.ZBot.EPA?

MemScan:Trojan.Spy.ZBot.EPA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment