Malware

PWS:Win32/Zbot.LY (file analysis)

Malware Removal

The PWS:Win32/Zbot.LY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Zbot.LY virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PWS:Win32/Zbot.LY?


File Info:

crc32: FAA56F93
md5: fccedf50d294758d2eca783c933b924f
name: FCCEDF50D294758D2ECA783C933B924F.mlw
sha1: 7225d3415d131260960f3954906132c433f062f1
sha256: a0129d7bd3827259d46eb99ab9d15f1f0b9f53ef3b22660fbdce865864468b0d
sha512: 9e85a747d1b122728fcdf6a11f21725d000491747665d758fde4729ecdc7dd84cc0b556d74cfe2b1611f46fa70ec8eccc2cc3e1e177c374b1b533d1c4ad03e02
ssdeep: 6144:3kykNZziZkMgChx432nBVh/gddKCA3t+aHyCRHNYFLBNaEY+Aj+6PBL:3XkT+x432b6eCuPLYpBsEY+W+mBL
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/Zbot.LY also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055dd191 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.46698
CynetMalicious (score: 100)
ALYacWin32.Worm.Socks.A
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.785
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.0d2947
CyrenW32/S-2b475323!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ATA
APEXMalicious
AvastWin32:Socks-AL [Wrm]
ClamAVWin.Trojan.Zbot-6853
KasperskyTrojan-Spy.Win32.Zbot.wmra
BitDefenderWin32.Worm.Socks.A
NANO-AntivirusTrojan.Win32.Zbot.iixec
ViRobotTrojan.Win32.A.Zbot.77312.G
MicroWorld-eScanWin32.Worm.Socks.A
TencentMalware.Win32.Gencirc.10b67943
Ad-AwareWin32.Worm.Socks.A
SophosMal/Generic-S
BitDefenderThetaAI:Packer.E6EE0F631D
TrendMicroTROJ_GEN.R067C0DKB21
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.fccedf50d294758d
EmsisoftWin32.Worm.Socks.A (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.eet
AviraTR/Crypt.XDR.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.F2940
MicrosoftPWS:Win32/Zbot.LY
GDataWin32.Worm.Socks.A
AhnLab-V3Trojan/Win32.Zbot.R56304
Acronissuspicious
McAfeeGenericRXCM-EK!FCCEDF50D294
MAXmalware (ai score=85)
VBA32Malware-Cryptor.General.3
MalwarebytesMalware.AI.1234967078
PandaTrj/Sinowal.VKV
TrendMicro-HouseCallTROJ_GEN.R067C0DKB21
RisingMalware.Heuristic!ET#100% (RDMK:cmRtazpfvXAJK6kciWdo2cxAr35F)
YandexTrojan.GenAsa!L9BVovTrmlI
IkarusTrojan-Spy.Win32.Zbot.dki
FortinetW32/Generic.AC.354923
AVGWin32:Socks-AL [Wrm]

How to remove PWS:Win32/Zbot.LY?

PWS:Win32/Zbot.LY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment