Spy Trojan

About “MemScan:Trojan.Spy.Zeus.C (B)” infection

Malware Removal

The MemScan:Trojan.Spy.Zeus.C (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What MemScan:Trojan.Spy.Zeus.C (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine MemScan:Trojan.Spy.Zeus.C (B)?


File Info:

name: 9407CD62913BC02609E4.mlw
path: /opt/CAPEv2/storage/binaries/02d2a9b68209710430a5241006b36478f8b815b46ea261b3f4ea08f11d27b6e4
crc32: 8C1C81A5
md5: 9407cd62913bc02609e4afdb2b7a98d8
sha1: ed16824c2775406519a7a211fce4d0c648327aa0
sha256: 02d2a9b68209710430a5241006b36478f8b815b46ea261b3f4ea08f11d27b6e4
sha512: 30e6a19bc23f97b7278f87b64f692630be08f58dde6e6f2712d0f19928d8fdbc148d9deea1270b4e317b0652e9a30edb7cce2e372bdebd92625d4bbf52fa6cdd
ssdeep: 3072:mLtRC6pZXYjE4WpuC+3o6H8uYCREPdfLvTh6xLdLZSsU8aPffx/:mLtUPjE4WITYdQcfLV6DLksMPx/
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T186F302C72406112AE02C8E7481AC4D02EA238E14346CA7992F9FF56D2BF75E5BCE35CD
sha3_384: 02aad179f3101f8e4dbef7e64ca9312d6150c5af94cf853b5fd168824a82477429c722c44a71679150590d6212f50e6f
ep_bytes: eccc2c6c547400bb0077d2007f46d982
timestamp: 2007-12-04 15:45:20

Version Info:

0: [No Data]

MemScan:Trojan.Spy.Zeus.C (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.9407cd62913bc026
ALYacMemScan:Trojan.Spy.Zeus.C
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0000017b1 )
AlibabaTrojanPSW:Win32/Obfuscator.20c930ee
K7GWSpyware ( 0000017b1 )
Cybereasonmalicious.2913bc
VirITTrojan.Win32.Panda.EN
SymantecInfostealer.Banker.C
ESET-NOD32Win32/Spy.Zbot.JF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-5066
KasperskyUDS:DangerousObject.Multi.Generic
BitDefenderMemScan:Trojan.Spy.Zeus.C
NANO-AntivirusTrojan.Win32.Packed.cskhad
MicroWorld-eScanMemScan:Trojan.Spy.Zeus.C
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Hqbf
Ad-AwareMemScan:Trojan.Spy.Zeus.C
SophosMal/Generic-R + Mal/GrumPk-A
ComodoTrojWare.Win32.PSW.Ldpinch.ai020@1nbda0
DrWebTrojan.PWS.Panda.117
ZillyaTrojan.Zbot.Win32.1552
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
EmsisoftMemScan:Trojan.Spy.Zeus.C (B)
SentinelOneStatic AI – Malicious PE
GDataMemScan:Trojan.Spy.Zeus.C
JiangminTrojanSpy.Zbot.kts
AviraTR/Proxy.Agent.CL
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.A281BA
ZoneAlarmPacked.Multi.SuspiciousPacker.gen
MicrosoftTrojan:Win32/Zbot.UR!MTB
Acronissuspicious
McAfeeGeneric.axw
TACHYONTrojan-Spy/W32.ZBot.172544.B
VBA32BScope.Malware-Cryptor.Hlux
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!JIusJ7SggOI
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.2588.susgen
FortinetW32/PackZbot.C!tr
BitDefenderThetaAI:Packer.3FD05E2C1E
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove MemScan:Trojan.Spy.Zeus.C (B)?

MemScan:Trojan.Spy.Zeus.C (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment