Spy Trojan

About “MemScan:Trojan.Spy.ZBot.EQH” infection

Malware Removal

The MemScan:Trojan.Spy.ZBot.EQH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Spy.ZBot.EQH virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine MemScan:Trojan.Spy.ZBot.EQH?


File Info:

name: 7456403F402A21B88A61.mlw
path: /opt/CAPEv2/storage/binaries/692c2315a1a9b34d82a4550f371d8fdcaa9db24519917c9c30e1e352102abd97
crc32: CD7CE89A
md5: 7456403f402a21b88a615fe9a8914f7f
sha1: 768374c49b0b521cc1d4bb109c4e36896061fb63
sha256: 692c2315a1a9b34d82a4550f371d8fdcaa9db24519917c9c30e1e352102abd97
sha512: 3c0f8b72edfb394be293baed705181fe0d85fc7c51abc0e645420896fbcd24754bc7382059408cff2868fb13aff35c0d4c8d576132b714ededcfc49c1c751bb6
ssdeep: 3072:6aDtD6uXj39X7dSgdaL4uETexVkl3hhLjdpufZOMx7AYf4VH:ftDnZLdrSd2/j6bR8VH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1E934E0225580AB37C3F41732FE181DA7E66F349A4BB1861BC79319085CFF6ADE903964
sha3_384: 96a32f38c5b930dc076669c5fa973045729a820dfd77fcff87c95c468c0e773b9166a3b30ef6a3ae68be713cb35e7032
ep_bytes: 558bec83c4ccff75f08d45e45068714b
timestamp: 2004-01-18 15:30:17

Version Info:

0: [No Data]

MemScan:Trojan.Spy.ZBot.EQH also known as:

BkavW32.MosquitoQKB.Fam.Trojan
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.387
CynetMalicious (score: 100)
FireEyeGeneric.mg.7456403f402a21b8
ALYacMemScan:Trojan.Spy.ZBot.EQH
CylanceUnsafe
VIPREPacked.Win32.PWSZbot.gen (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanSpy:Win32/Kryptik.b43707cf
K7GWTrojan ( 004bcce41 )
Cybereasonmalicious.f402a2
BitDefenderThetaAI:Packer.C2B352EE1F
VirITTrojan.Win32.Small.HQP
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.JSA
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.Zbot.ayhd
BitDefenderMemScan:Trojan.Spy.ZBot.EQH
NANO-AntivirusTrojan.Win32.Zbot.cxzxb
SUPERAntiSpywareTrojan.Agent/Gen-DitherC
MicroWorld-eScanMemScan:Trojan.Spy.ZBot.EQH
AvastWin32:Trojan-gen
TencentWin32.Trojan.Zbot.Kush
Ad-AwareMemScan:Trojan.Spy.ZBot.EQH
EmsisoftMemScan:Trojan.Spy.ZBot.EQH (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
ZillyaTrojan.Zbot.Win32.36016
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionBehavesLike.Win32.Trojan.dm
SophosMal/Generic-S
IkarusTrojan.Win32.Spyeye
GDataMemScan:Trojan.Spy.ZBot.EQH
JiangminTrojanSpy.Zbot.aueh
eGambitUnsafe.AI_Score_62%
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.94287C
ViRobotTrojan.Win32.A.Zbot.248320.D
MicrosoftPWS:Win32/Zbot.gen!Y
SentinelOneStatic AI – Malicious PE
AhnLab-V3Trojan/Win32.Zbot.R2835
Acronissuspicious
McAfeeArtemis!7456403F402A
TACHYONTrojan-Spy/W32.ZBot.248320.BK
VBA32Trojan.Zeus.EA.0999
APEXMalicious
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojanSpy.Zbot!NdXcAtC5BnI
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.2255594.susgen
FortinetW32/Zbot.AYHD!tr
WebrootW32.Suspicious.Heur
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove MemScan:Trojan.Spy.ZBot.EQH?

MemScan:Trojan.Spy.ZBot.EQH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment