Malware

PWS:Win32/Zbot.dam (file analysis)

Malware Removal

The PWS:Win32/Zbot.dam is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Zbot.dam virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PWS:Win32/Zbot.dam?


File Info:

crc32: 48E36332
md5: 285c71451e1d43a1170c74ec0bc21e50
name: infected.exe
sha1: ea1ab387bf93661c2a91b359675e45d416cbccd8
sha256: 5a702af4d660b82dafb75fc2aa00f827d96e138fe450823ecf4e1650e881887e
sha512: 23d8e4e28f6eeaee624a89da3bacc128814fd4e521b8189589953fbd4ad314e279c4d0d42ed8480c5580969b785107cf52f900dc096ae78421796a15c74b55ba
ssdeep: 3072:jPuS+VFMastf0lR8OJnMzwsWPGQOw5GAUVhIVCXGH9fiyqGMM3NYbg1qGI9LgZQJ:LGfVsdgekDlUVhIUXg9V6/bAqEZQBD
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/Zbot.dam also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.Agent.BWCX
FireEyeGeneric.mg.285c71451e1d43a1
CAT-QuickHealTrojan.Bamital.EC
McAfeeBredolab.gen.t
CylanceUnsafe
ZillyaTrojan.Agent2.Win32.12460
SangforMalware
K7AntiVirusSpyware ( 0054c6471 )
BitDefenderTrojan.Agent.BWCX
K7GWSpyware ( 0054c6471 )
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Agent.BWCX
TrendMicroTROJ_DLOADR.SMJU
F-ProtW32/MalwareF.BMEC
TotalDefenseWin32/Zbot.BUX
APEXMalicious
AvastWin32:Zbot-MTZ [Drp]
KasperskyTrojan.Win32.Agent2.csln
AlibabaTrojanPSW:Win32/Agent2.2ce944eb
ViRobotTrojan.Win32.A.Agent.128487
AegisLabTrojan.Win32.Agent2.4!c
RisingSpyware.Zbot!8.16B (CLOUD)
Endgamemalicious (high confidence)
EmsisoftTrojan.Agent.BWCX (B)
ComodoTrojWare.Win32.Trojan.Agent2.~csl@1y3agr
F-SecureTrojan.TR/Spy.Zbot.acsb
DrWebTrojan.Packed.20511
VIPRETrojan-Downloader.Win32.Reipym.b (v)
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Upatre.cc
CMCGeneric.Win32.285c71451e!CMCRadar
SophosTroj/Agent-NOB
IkarusTrojan.Win32.Agent2
CyrenW32/Risk.CQKM-9397
JiangminTrojan/Agent.dtyx
WebrootW32.Infostealer.Zeus
AviraTR/Spy.Zbot.acsb
eGambitUnsafe.AI_Score_87%
FortinetW32/Agent.NOB!tr
Antiy-AVLTrojan/Win32.Agent2
MicrosoftPWS:Win32/Zbot.dam
SUPERAntiSpywareTrojan.Agent/Gen
ZoneAlarmTrojan.Win32.Agent2.csln
TACHYONTrojan/W32.Agent2.177152.D
AhnLab-V3Trojan/Win32.FakeAV.C35767
Acronissuspicious
ALYacTrojan.Agent.BWCX
MAXmalware (ai score=100)
VBA32Trojan.Agent.SB.0493
PandaTrj/Sinowal.WXO
ESET-NOD32Win32/Spy.Zbot.QT
TrendMicro-HouseCallTROJ_DLOADR.SMJU
TencentWin32.Trojan.Zbot.Kush
YandexTrojan.Agent2!a7c8QJUtmEw
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.1354597.susgen
GDataTrojan.Agent.BWCX
Ad-AwareTrojan.Agent.BWCX
AVGWin32:Zbot-MTZ [Drp]
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.b56

How to remove PWS:Win32/Zbot.dam?

PWS:Win32/Zbot.dam removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment