Spy

Spyware.Citadel (file analysis)

Malware Removal

The Spyware.Citadel is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Citadel virus can do?

  • Creates RWX memory
  • Reads data out of its own binary image

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Spyware.Citadel?


File Info:

crc32: DD5BD603
md5: 69544310ceb1493b07fb221ac19351a4
name: 69544310CEB1493B07FB221AC19351A4.mlw
sha1: 41aa96646df46be7f110fc8046279b6e5d346fac
sha256: 45cd0ee90d0fafd7e147e14923cdbe0467d78242609924eedb6afc9b2aa08418
sha512: d3f39093c81cb371908954490a6a62f2c52ece0aebe529b42a395b05b57f9bef7a15b331c7f375ff8979208a4374bd4a3c9cdd593c0722837496714eb08a77f8
ssdeep: 6144:w0N4lA7SlqqDLPD5apPv+dzqjjUXIQuRkNq2GWQnu9b+0w:w0N4lA7Bqnr2EzqjjUXRuRk42Pfyh
type: MS-DOS executable

Version Info:

0: [No Data]

Spyware.Citadel also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2401
MicroWorld-eScanGen:Heur.Mint.Dreidel.nmX@x4dNcTl
FireEyeGeneric.mg.69544310ceb1493b
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Heur.Mint.Dreidel.nmX@x4dNcTl
CylanceUnsafe
VIPRETrojan.Win32.Zbot.n (v)
SangforMalware
K7AntiVirusSpyware ( 0029a43a1 )
BitDefenderGen:Heur.Mint.Dreidel.nmX@x4dNcTl
K7GWSpyware ( 0029a43a1 )
CrowdStrikewin/malicious_confidence_100% (D)
TrendMicroTSPY_ZBOT.SMQF
BitDefenderThetaGen:NN.ZexaF.34634.nmX@a4dNcTl
CyrenW32/Zbot.BR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastSf:Crypt-BR [Trj]
ClamAVWin.Spyware.Zbot-1275
KasperskyTrojan-Spy.Win32.Zbot.scrb
Ad-AwareGen:Heur.Mint.Dreidel.nmX@x4dNcTl
TACHYONTrojan/W32.Agent.226304.II
SophosMal/Zbot-HX
ComodoTrojWare.Win32.Zbot.NEWA@4qfujn
F-SecureTrojan.TR/Spy.Gen
BaiduWin32.Trojan.Zbot.a
ZillyaTrojan.ZbotGen.Win32.5
InvinceaML/PE-A + Mal/Zbot-HX
McAfee-GW-EditionBehavesLike.Win32.ZBot.dh
EmsisoftGen:Heur.Mint.Dreidel.nmX@x4dNcTl (B)
IkarusTrojan-Spy.Banker.Citadel
JiangminTrojan/Generic.aqwbd
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Spy.Gen
MicrosoftPWS:Win32/Zbot!CI
ArcabitTrojan.Mint.Dreidel.E88EC0
ZoneAlarmTrojan-Spy.Win32.Zbot.scrb
GDataGen:Heur.Mint.Dreidel.nmX@x4dNcTl
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R27121
Acronissuspicious
McAfeePWS-Zbot.gen.vo
MAXmalware (ai score=85)
VBA32SScope.Trojan.FakeAV.01110
MalwarebytesSpyware.Citadel
PandaTrj/Genetic.gen
ZonerTrojan.Win32.36443
ESET-NOD32a variant of Win32/Spy.Zbot.YW
TrendMicro-HouseCallTSPY_ZBOT.SMQF
RisingStealer.Zbot!1.648A (CLASSIC)
YandexTrojan.GenAsa!CxzTiQAZHn0
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Zbot.AT!tr
WebrootW32.InfoStealer.Zeus
AVGSf:Crypt-BR [Trj]
Cybereasonmalicious.0ceb14
Qihoo-360HEUR/QVM20.1.3FBB.Malware.Gen

How to remove Spyware.Citadel?

Spyware.Citadel removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment