Malware

TjnPWS.Zbot.S12447 removal

Malware Removal

The TjnPWS.Zbot.S12447 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TjnPWS.Zbot.S12447 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)

How to determine TjnPWS.Zbot.S12447?


File Info:

name: A36301793916C4AAF3FB.mlw
path: /opt/CAPEv2/storage/binaries/efae77548153bde68ee31868558e4378e108c7a3fb76fce007adac35254da01d
crc32: EFA3D92A
md5: a36301793916c4aaf3fb23581e213e70
sha1: b5867ab2c10c0d80c94927a2f75aefcf5a0b84e2
sha256: efae77548153bde68ee31868558e4378e108c7a3fb76fce007adac35254da01d
sha512: bdc02a9e0b3f1c7adcedf59104cb9d504d234eb9f5ac62ba6d176d64ecb1be51dc1be2d21f962b9191fcc1db0e7cf729fe7caa63038978dd1bc8fedfc41bbc19
ssdeep: 6144:y6KYUASfq3GlB0AvGGFXH1T7+rRaAVOlMumyreL:lUA81MmGS7+clM/X
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T153541202D31E50A2E50E7DB016A5E3E6AC7B6C113727236BBEB5386F127927508E15DC
sha3_384: 14b3d73710b49b6bad06b1cb4c6361c8aa0ecb93865bf114d496f9c1594b0d0895834a357cf93689d2f76e57851bd66b
ep_bytes: 6a00ff15c82040008b44240c85c07518
timestamp: 2014-01-30 05:44:40

Version Info:

FileDescription: Lexinny
FileVersion: 2.0.7.9
InternalName: Lexinny
LegalCopyright: Copyright © 1998-2014
ProductVersion: 2.0.7.9
Translation: 0x0409 0x04b0

TjnPWS.Zbot.S12447 also known as:

LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanGen:Trojan.ProcessHijack.sq0@aiWmxYk
FireEyeGeneric.mg.a36301793916c4aa
CAT-QuickHealTjnPWS.Zbot.S12447
McAfeePWSZbot-FQM!A36301793916
CylanceUnsafe
SangforTrojan.Win32.Agent.abxa
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/ProcessHijack.6a4585b0
K7GWTrojan ( 004daf6c1 )
K7AntiVirusTrojan ( 004daf6c1 )
VirITTrojan.Win32.Generic.ZOY
CyrenW32/Zbot.PT.gen!Eldorado
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.ProcessHijack.sq0@aiWmxYk
NANO-AntivirusTrojan.Win32.Zbot.ctirzs
SUPERAntiSpywareTrojan.Agent/Gen-Luder
AvastWin32:Malware-gen
TencentMalware.Win32.Gencirc.10b58425
Ad-AwareGen:Trojan.ProcessHijack.sq0@aiWmxYk
EmsisoftGen:Trojan.ProcessHijack.sq0@aiWmxYk (B)
ComodoTrojWare.Win32.Spy.Zbot.BT@596eyr
DrWebTrojan.PWS.Panda.5908
VIPRETrojan.Win32.Generic!BT
TrendMicroTSPY_ZBOT.SMAA7
SophosMal/Generic-R + Troj/Agent-AFVO
IkarusVirus.Win32.Zbot
JiangminTrojanSpy.Zbot.ebjs
MaxSecureTrojan.Malware.300983.susgen
AviraTR/Agent.abxa.14
MAXmalware (ai score=99)
GridinsoftRansom.Win32.Zbot.sa
ArcabitTrojan.ProcessHijack.E21C67
ViRobotTrojan.Win32.U.Agent.299008.A
MicrosoftPWS:Win32/Zbot.AJB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R96860
VBA32Malware-Cryptor.Inject.gen
ALYacGen:Trojan.ProcessHijack.sq0@aiWmxYk
TACHYONTrojan/W32.ZBot.299008.D
MalwarebytesTrojan.Zbot
TrendMicro-HouseCallTSPY_ZBOT.SMAA7
RisingTrojan.Injector!8.C4 (CLOUD)
YandexTrojanSpy.Zbot!belvt9nnyM4
SentinelOneStatic AI – Suspicious PE
eGambitGeneric.PSW
FortinetW32/Injector.PDA!tr
AVGWin32:Malware-gen
PandaTrj/Genetic.gen

How to remove TjnPWS.Zbot.S12447?

TjnPWS.Zbot.S12447 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment