Spy Trojan

MemScan:Trojan.Spy.Zeus.C malicious file

Malware Removal

The MemScan:Trojan.Spy.Zeus.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Spy.Zeus.C virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MemScan:Trojan.Spy.Zeus.C?


File Info:

name: 330E760BFF4AF8A9AB43.mlw
path: /opt/CAPEv2/storage/binaries/7ac5173645280b8980259cf59ad2d1159d5b140752825e8588350f0174884e22
crc32: 2FE2C10D
md5: 330e760bff4af8a9ab43f298d14ab578
sha1: a49d10b3d0510a8aad80ff141d6a8a922991e959
sha256: 7ac5173645280b8980259cf59ad2d1159d5b140752825e8588350f0174884e22
sha512: 1f0646ba222dd9f473dd6b95ed9c305edd17425635c68bab227e446832ad47f20aa61bb6792a76cf3d24ef99b6f79a4aade8c630714b9e48c3783904643d1b03
ssdeep: 1536:Awrx+zVeysGnNhKZpTnKFRNo0xijgoqwyeNqmZr0r1eIZjeVthH0:VYVeSNErKFb2kmZArAsiVtK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18853F1DA7B1C7485C0C9743418E09EB14458EBB4BA42F3995D822DDB046BAA0FFA36C7
sha3_384: 1bec396f08bd0b569dbff6a279ee800295f0a8ed741631c86dcc89efab8a8f97b352c226534cdd6f430b5393a0f995bc
ep_bytes: 31c0e801000000c389ff89e583ec148d
timestamp: 2008-03-04 23:12:34

Version Info:

0: [No Data]

MemScan:Trojan.Spy.Zeus.C also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.kYXg
Elasticmalicious (high confidence)
DrWebTrojan.Packed.443
MicroWorld-eScanMemScan:Trojan.Spy.Zeus.C
FireEyeGeneric.mg.330e760bff4af8a9
McAfeeSpy-Agent.ke.gen.c
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.3316
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0054c19a1 )
AlibabaTrojanSpy:Win32/EncPk.3b88dad5
K7GWSpyware ( 0054c19a1 )
Cybereasonmalicious.bff4af
BitDefenderThetaAI:Packer.40EE36EC1E
VirITTrojan.Win32.Zbot.B
CyrenW32/Trojan.NVAN-2602
SymantecInfostealer.Banker.C
ESET-NOD32a variant of Win32/Spy.Zbot.UR
TrendMicro-HouseCallTSPY_ZBOT.CAR
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-9388
KasperskyTrojan-Spy.Win32.Zbot.gen
BitDefenderMemScan:Trojan.Spy.Zeus.C
NANO-AntivirusTrojan.Win32.Zbot.updn
AvastWin32:Zbot-AXP [Trj]
TencentWin32.Trojan-spy.Zbot.Lfzy
Ad-AwareMemScan:Trojan.Spy.Zeus.C
EmsisoftMemScan:Trojan.Spy.Zeus.C (B)
ComodoTrojWare.Win32.Spy.Zbot.GEN@1fmlmy
VIPRETrojan-Spy.Win32.Zbot.gen (v)
TrendMicroTSPY_ZBOT.CAR
McAfee-GW-EditionBehavesLike.Win32.VirRansom.kc
SophosMal/Generic-S + Mal/EncPk-CZ
IkarusTrojan-Spy.Zeus
GDataWin32.Trojan-Spy.Zbot.DT
JiangminTrojanSpy.Zbot.hhy
AviraTR/Crypt.ZPACK.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.6435A7
KingsoftWin32.Troj.Zbot.g.(kcloud)
ViRobotTrojan.Win32.Zbot.63488.P
MicrosoftTrojan:Win32/Zbot.UR!MTB
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Zbot.60416
Acronissuspicious
VBA32BScope.Malware-Cryptor.Hlux
ALYacSpyware.Zbot.vx
TACHYONTrojan-Spy/W32.ZBot.63488.M
APEXMalicious
RisingTrojan.Spy.Win32.Zbot.fak (CLOUD)
YandexTrojanSpy.ZBot.Gen!Pac.7
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.13640.susgen
FortinetW32/Zbot.gen!tr
AVGWin32:Zbot-AXP [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove MemScan:Trojan.Spy.Zeus.C?

MemScan:Trojan.Spy.Zeus.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment