Malware

PWS:Win32/Zbot!DLY malicious file

Malware Removal

The PWS:Win32/Zbot!DLY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Zbot!DLY virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine PWS:Win32/Zbot!DLY?


File Info:

name: 5888AA7E8BFE0E49FAB5.mlw
path: /opt/CAPEv2/storage/binaries/8c75ffc28a995fec8e1f6b804f991c04c16cc540707ed770233edae9c647c8e7
crc32: A906809E
md5: 5888aa7e8bfe0e49fab53d06e0f18d50
sha1: 2a5200eb8278a750152ee6b6423f6258b461f315
sha256: 8c75ffc28a995fec8e1f6b804f991c04c16cc540707ed770233edae9c647c8e7
sha512: c302162bdf61df1fd2ca1f18f055fe325f865199bda3833e143aed054a144ab593dbdecb792b1b7d847592b9cc193d4a861c3d8347d0617a55f22d6d372d05ce
ssdeep: 3072:+sqZFwKO8aOaN2i8m6+Ms6Hpa5dafReTOUg1xg9PTg4obNPUwFCVSzcM5z90rN4R:+7FwKODH0c5dafsTXlevF9oKzm54UWJn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10054E06163E18462E4BF5B3169235EA15927FCA147AE22F70110F1F818F2780DEB9BDD
sha3_384: 16435cb424917fe6aa8e1991a8a1cb1df26759d0dc106b0e8e2dbf7deb5da8881be32f6b70878777d4c4b4b4915d0817
ep_bytes: 558bec416aff680440430068c0154000
timestamp: 2010-12-02 23:29:12

Version Info:

CompanyName: Subeuiz. Oin
FileDescription: jeee
FileVersion: 5.3.0.2400
InternalName: overc, It
LegalCopyright: exeedom exacy 1984-2011
OriginalFilename: unwiksio.exe
ProductName: Underhe
ProductVersion: 5.3.0.2400
Translation: 0x0409 0x04b0

PWS:Win32/Zbot!DLY also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2977
MicroWorld-eScanGen:Variant.Razy.842677
FireEyeGeneric.mg.5888aa7e8bfe0e49
McAfeePWSZbot-FVO!5888AA7E8BFE
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusSpyware ( 0055e3db1 )
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.e8bfe0
BitDefenderThetaGen:NN.ZexaF.34084.sq1@aaaxedei
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAO
ClamAVWin.Spyware.Zbot-9868862-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.842677
NANO-AntivirusTrojan.Win32.Zbot.cqiilm
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10c843cf
Ad-AwareGen:Variant.Razy.842677
TACHYONTrojan-Spy/W32.ZBot.295936.AA
EmsisoftGen:Variant.Razy.842677 (B)
ZillyaTrojan.Zbot.Win32.155687
McAfee-GW-EditionPWSZbot-FVO!5888AA7E8BFE
SophosML/PE-A + Troj/Agent-AEYZ
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Razy.842677
JiangminTrojanSpy.Zbot.dxrp
Webroot
AviraTR/Spy.Zbot.29593641
Antiy-AVLTrojan/Generic.ASMalwS.594316
MicrosoftPWS:Win32/Zbot.gen!DLY
CynetMalicious (score: 100)
VBA32TrojanSpy.Zbot
ALYacGen:Variant.Razy.842677
MAXmalware (ai score=80)
APEXMalicious
RisingTrojan.Generic@ML.92 (RDML:0icpX34R05UEny98FvdMsA)
YandexTrojanSpy.Zbot!jomUZdnPhPw
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_95%
FortinetW32/Kryptik.BTT!tr
AVGWin32:Malware-gen
PandaTrj/Dtcontx.I
CrowdStrikewin/malicious_confidence_100% (D)

How to remove PWS:Win32/Zbot!DLY?

PWS:Win32/Zbot!DLY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment