Spy

Spyware.Zbot.ED (file analysis)

Malware Removal

The Spyware.Zbot.ED is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Zbot.ED virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Unconventionial binary language: Russian
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Spyware.Zbot.ED?


File Info:

crc32: 265A2B41
md5: 585f5f15d3020664b7db8bd9d2416950
name: 585F5F15D3020664B7DB8BD9D2416950.mlw
sha1: 71a1ca3583e923b3f56cde4ebe05d0c11fbe49e0
sha256: b6099c1712bd1989b25c9b166fa8d15e6b34c6e3b8c712cc197b41e6356d115f
sha512: 5221dba295075c835d5af92f1949dc4a7a648f552c1adad9459a446a1d001426f80b2754c4e5a7ed853361d3a06a04e1d1a971df8f68946acee68ffe50daaeaa
ssdeep: 3072:Esq0QN5YzXCcIz7giBVbehbG7qxglBcVG5HgByej:Esq0qjz7jWdGOxGBGMg
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 gora
InternalName: Button For 7z SFX
FileVersion: Version of file 4.2.4 build 2000 [x86]
CompanyName: Company 'gora-sah'
PrivateBuild: 08.06.2012
LegalTrademarks: Still is not present
Comments: Button For creation and job with 7z SXF archives
ProductName: Button v4.2.4 [x86]
SpecialBuild: For all users
ProductVersion: Version of product 4.2.4 [x86]
FileDescription: 7z SFX archive tool. The last version of 'Button' you can find on http://buttontc.7zsfx.info
OriginalFilename: Button.exe
Translation: 0x0419 0x04b0

Spyware.Zbot.ED also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.44785131
FireEyeGeneric.mg.585f5f15d3020664
Qihoo-360HEUR/QVM40.1.AC78.Malware.Gen
McAfeeGenericRXMU-JE!585F5F15D302
CylanceUnsafe
SangforMalware
K7AntiVirusSpyware ( 0040f0131 )
BitDefenderTrojan.GenericKD.44785131
K7GWSpyware ( 0040f0131 )
CrowdStrikewin/malicious_confidence_80% (D)
BitDefenderThetaGen:NN.ZedlaF.34670.Kz8@aGFec3di
SymantecML.Attribute.HighConfidence
APEXMalicious
Ad-AwareTrojan.GenericKD.44785131
SophosML/PE-A + Mal/EncPk-APV
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.44785131 (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.Kryptik.VJLFH4
MAXmalware (ai score=87)
Antiy-AVLGrayWare/Win32.Kryptik.ehls
GridinsoftMalware.Win32.Pack.40712!se
ArcabitTrojan.Generic.D2AB5DEB
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
VBA32BScope.Backdoor.Qbot
ALYacTrojan.GenericKD.44785131
MalwarebytesSpyware.Zbot.ED
FortinetW32/Kryptik.HDJM!tr

How to remove Spyware.Zbot.ED?

Spyware.Zbot.ED removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment