Malware

How to remove “PWS:Win32/Zbot!G”?

Malware Removal

The PWS:Win32/Zbot!G is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Zbot!G virus can do?

  • At least one process apparently crashed during execution
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine PWS:Win32/Zbot!G?


File Info:

name: FE041B55BB2838326CC7.mlw
path: /opt/CAPEv2/storage/binaries/f60722449db369c5b0e0e1473c47da3426dd5dcb395bd783dcc1e9169f1a55f8
crc32: 230B30E9
md5: fe041b55bb2838326cc7dae1a066ed32
sha1: cc0dd67b9a91d13c5ba21899d658847bae898527
sha256: f60722449db369c5b0e0e1473c47da3426dd5dcb395bd783dcc1e9169f1a55f8
sha512: 11562d810154fc2dd9182595bbf8062aa1bf4c86d49fde16ff847cd02f35a6ba1adbb69fee37dc33ccb1ee5a4ac42c6674d787441328d109d764470db689a751
ssdeep: 12288:H25iieHNGs0jXrgTNcLTG4eEKp0bAiisJIJamKkyGyrvGY0KdUoh:HgiiYNGPXScTGpEWELisEa5NrvDdUoh
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A4E42392539EC383D87548BE36AF3A14A0F33C474A17D727A7B14CC5D919A82625B33B
sha3_384: 7b2c26c51d0fe2fa702f978707d7ed2cd2f409cf3e67dc353051d541b2215ff0557c17954a5b4038dfbbb39ad6638a5f
ep_bytes: 81e8882ddf43b87fc8ffffc1c80781c7
timestamp: 2008-05-14 08:27:53

Version Info:

0: [No Data]

PWS:Win32/Zbot!G also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.FakeAlert.Gen.1
ALYacTrojan.FakeAlert.Gen.1
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 0055e3da1 )
BitDefenderTrojan.FakeAlert.Gen.1
K7GWTrojan-Downloader ( 0055e3da1 )
Cybereasonmalicious.5bb283
ArcabitTrojan.FakeAlert.Gen.1
CyrenW32/Trojan.AWKM-6106
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.CVD
APEXMalicious
ClamAVWin.Trojan.Zbot-3295
KasperskyPacked.Win32.Katusha.a
NANO-AntivirusTrojan.Win32.Zbot.upjd
RisingDropper.Generic!8.35E (CLOUD)
Ad-AwareTrojan.FakeAlert.Gen.1
SophosML/PE-A + Mal/EncPk-CZ
ComodoMalCrypt.Indus!@1qrzi1
DrWebTrojan.Packed.569
ZillyaTrojan.Kryptik.Win32.251754
TrendMicroMal_FakeAV
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.fe041b55bb283832
EmsisoftTrojan.FakeAlert.Gen.1 (B)
IkarusTrojan.Win32.FraudPack
JiangminTrojanSpy.Zbot.abvh
AviraTR/Dropper.Gen
MicrosoftPWS:Win32/Zbot.gen!G
GDataTrojan.FakeAlert.Gen.1
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Fraudpack.Gen
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=81)
VBA32Malware-Cryptor.General.2
PandaTrj/CI.A
TrendMicro-HouseCallMal_FakeAV
YandexTrojanSpy.Zbot!zUHDGbgssOY
SentinelOneStatic AI – Malicious PE
FortinetW32/FraudPack.B!tr
BitDefenderThetaAI:Packer.3FE0F7EA1A
AVGWin32:Evo-gen [Susp]
AvastWin32:Evo-gen [Susp]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove PWS:Win32/Zbot!G?

PWS:Win32/Zbot!G removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment