Malware

PWS:Win32/Zbot!GO malicious file

Malware Removal

The PWS:Win32/Zbot!GO is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Zbot!GO virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.

How to determine PWS:Win32/Zbot!GO?


File Info:

crc32: 89E72F04
md5: ddc94c5d767e58ed778d4b5612f90477
name: DDC94C5D767E58ED778D4B5612F90477.mlw
sha1: c45737c90873efb57a68f3093c3051b02e11bdc9
sha256: 6a2b8adb273c4a1f9f2dda485d2cef9a14dc7096c6351395a6341393bf4ae9b2
sha512: 4fe10b1b7e60f6f838f917214d8f558d6ee2283d0d1c06857927726c59282236c7d05b0a5a754d601de606adbecc3cae06f69bd09f9f80fe5e6b861d5a5aedd6
ssdeep: 6144:HNWTBJscxRWECObFSFaZM3jQU366aCOjFQtl9IONmzw6zpIV/z8k2ckER:HNWTrscTWWbYFa4B3naCOtOHRokjks
type: MS-DOS executable

Version Info:

0: [No Data]

PWS:Win32/Zbot!GO also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 00404d661 )
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Proxy.24702
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Generic.5979
ALYacGen:Variant.Kazy.55566
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.204612
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanPSW:Win32/ShellCode.438add21
K7GWSpyware ( 00404d661 )
Cybereasonmalicious.d767e5
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Zbot.AAU
APEXMalicious
AvastSf:ShellCode-R [Trj]
ClamAVWin.Spyware.Zbot-1275
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Kazy.55566
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Kazy.55566
TencentTrojan.Win32.Zbot.aaw
Ad-AwareGen:Variant.Kazy.55566
SophosML/PE-A + Mal/Behav-010
ComodoTrojWare.Win32.Spy.ZBot.AAU@4wkkp5
BitDefenderThetaGen:NN.ZexaF.34058.qmX@amej4Yp
VIPRETrojan.Win32.Zbot.aka (v)
TrendMicroCryp_Xin1
McAfee-GW-EditionBehavesLike.Win32.Dropper.dh
FireEyeGeneric.mg.ddc94c5d767e58ed
EmsisoftGen:Variant.Kazy.55566 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.bidrj
AviraTR/Spy.Gen
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Unknown
MicrosoftPWS:Win32/Zbot!GO
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Kazy.55566
AhnLab-V3Trojan/Win32.Zbot.R81885
Acronissuspicious
McAfeePWS-Zbot.gen.apr
MAXmalware (ai score=81)
VBA32BScope.Trojan.Zbot.6713
MalwarebytesMalware.AI.1106844228
PandaTrj/Genetic.gen
TrendMicro-HouseCallCryp_Xin1
RisingRansom.Satan!1.AEB7 (CLASSIC)
YandexTrojan.GenAsa!C8cQqij0e9U
IkarusTrojan-PWS.Win32.Zbot
FortinetW32/Zbot.AAU!tr
AVGSf:ShellCode-R [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/TrojanSpy.Generic.HxQBEpsA

How to remove PWS:Win32/Zbot!GO?

PWS:Win32/Zbot!GO removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment