Malware

PWS:Win32/Zbot!MSR removal guide

Malware Removal

The PWS:Win32/Zbot!MSR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Zbot!MSR virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine PWS:Win32/Zbot!MSR?


File Info:

crc32: 2CB6CA36
md5: 04960483f6bc53968fb4357ec458440f
name: img.exe
sha1: f05b1d0c04b07b216267fe132a0ccedfe23cc035
sha256: 898b21cd0ae618efb896cbe5ba2bf382888e2770761f39151b5e003942939595
sha512: 9185ac85028af45fd4f50ee6625413707ad4f7c7b69a344cd7ebb1fc2c4d9f92b0f7377d877346d847327cdd6ad3a9e185d903df5179996acb678c22db02a489
ssdeep: 24576:bNA3R5drXadBZWwl7DnyAP572k1QhDIpDkc1jZFQYcHO6lp:G5CBl7LX572LWh1jZ63v
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

PWS:Win32/Zbot!MSR also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.33285759
CylanceUnsafe
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.33285759
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.c04b07
Invinceaheuristic
SymantecTrojan.Gen.MBT
APEXMalicious
ClamAVWin.Malware.Autoit-7599063-0
GDataTrojan.GenericKD.33285759
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/runner.ali1000123
RisingTrojan.Pack-RAR!1.BB61 (CLASSIC)
Endgamemalicious (high confidence)
F-SecureTrojan.TR/AD.AgentTesla.gtvba
TrendMicroTROJ_FRS.VSNW11B20
McAfee-GW-EditionBehavesLike.Win32.Backdoor.tc
Trapminesuspicious.low.ml.score
FireEyeGeneric.mg.04960483f6bc5396
SophosMal/Generic-S
IkarusTrojan.Autoit
CyrenW32/Trojan.TQUW-3663
AviraTR/AD.AgentTesla.gtvba
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftPWS:Win32/Zbot!MSR
ArcabitTrojan.Generic.D1FBE67F
ZoneAlarmHEUR:Trojan.Win32.Generic
AhnLab-V3Trojan/Win32.Injector.C4001769
McAfeeArtemis!04960483F6BC
MAXmalware (ai score=86)
MalwarebytesTrojan.Agent.AutoIt
ZonerProbably RARAutorun
ESET-NOD32VBS/Starter.NCV
TrendMicro-HouseCallTROJ_FRS.VSNW11B20
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Generic/HEUR/QVM06.3.8703.Malware.Gen

How to remove PWS:Win32/Zbot!MSR?

PWS:Win32/Zbot!MSR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment