Malware

About “PWS:Win32/Zbot!atmnm” infection

Malware Removal

The PWS:Win32/Zbot!atmnm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Zbot!atmnm virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Creates Zeus (Banking Trojan) mutexes

How to determine PWS:Win32/Zbot!atmnm?


File Info:

name: 1B2CD52E5E8ACE391643.mlw
path: /opt/CAPEv2/storage/binaries/8985024cb147b7101d71be62e73e269473ff03d4f89e80171dce908d899edc36
crc32: 55AEEAF0
md5: 1b2cd52e5e8ace3916436050ec43b1b1
sha1: c37920f6a11b56e8a0c9a0097f94f79d92c0c538
sha256: 8985024cb147b7101d71be62e73e269473ff03d4f89e80171dce908d899edc36
sha512: 608d2d1a0dd615f3f5b316307533ac4ab3e8f9721e0d60e7ed522ff655f197efe7248183fa46fa39d3c538660e9c9c07a893e19ef850c4c094160349c26505f2
ssdeep: 1536:lBYL8mIvuYwmPt1opqIrYfLqT2VS41QgfpxtLpCzNHyWZIZaMj5WzmuKbS:lBk8mIvuEPGb02TaQgtLp5WyhWzJqS
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19EB3AE22E3E1817CF4B35A3246710767DFB67D21193A822EE6D24B590F326B1D536393
sha3_384: 84acc446d2bcbee01884dfd27ee64a2a03a6bb54f2066d1ede0c545e32dfdeb8a3e8f0da3bc10592d916491843e9c0e6
ep_bytes: 558bec81ec3804000053565733ff4757
timestamp: 2008-04-02 08:25:35

Version Info:

0: [No Data]

PWS:Win32/Zbot!atmnm also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.1b2cd52e5e8ace39
CAT-QuickHealTrojanpws.Zbot.29195
Cylanceunsafe
VIPREDropped:Generic.Malware.SFMg.A28EF40E
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 000108081 )
K7GWSpyware ( 000108081 )
Cybereasonmalicious.e5e8ac
CyrenW32/Zbot.BS.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Agent.PZ
APEXMalicious
ClamAVWin.Malware.Zbot-9951822-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDropped:Generic.Malware.SFMg.A28EF40E
NANO-AntivirusTrojan.Win32.Agent.cvvyro
MicroWorld-eScanDropped:Generic.Malware.SFMg.A28EF40E
AvastWin32:BankerX-gen [Trj]
TencentMalware.Win32.Gencirc.10beba6e
SophosMal/Behav-010
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.DownLoader9.46698
TrendMicroTROJ_ZBOT.SMUC
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
Trapminemalicious.moderate.ml.score
EmsisoftDropped:Generic.Malware.SFMg.A28EF40E (B)
IkarusTrojan-Downloader.Win32.Small
GDataDropped:Generic.Malware.SFMg.A28EF40E
AviraTR/Dropper.Gen
Antiy-AVLTrojan[PSW]/Win32.Zbot
ArcabitGeneric.Malware.SFMg.A28EF40E
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot!atmnm
AhnLab-V3Win-Trojan/Hupe.Gen
Acronissuspicious
BitDefenderThetaAI:Packer.6D9389A21E
ALYacDropped:Generic.Malware.SFMg.A28EF40E
MAXmalware (ai score=83)
VBA32Trojan.Inject.01376
MalwarebytesGeneric.Spyware.Stealer.DDS
PandaGeneric Malware
TrendMicro-HouseCallTROJ_ZBOT.SMUC
RisingStealer.Zbot!8.109D7 (TFE:4:B7IyWuCXsYJ)
YandexTrojan.GenAsa!NoTYJPNe6OI
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Zbot.PZ!tr.spy
AVGWin32:BankerX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PWS:Win32/Zbot!atmnm?

PWS:Win32/Zbot!atmnm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment