Malware

How to remove “Troj/ZAccess-PI”?

Malware Removal

The Troj/ZAccess-PI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/ZAccess-PI virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Uses Windows utilities for basic functionality
  • Attempted to write to a harddisk volume
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Attempts to identify installed AV products by installation directory
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/ZAccess-PI?


File Info:

name: 062A689F23B625419A85.mlw
path: /opt/CAPEv2/storage/binaries/fda3457af3ee62993b607925e3b5fb8c0bca98512f5b6262b4bed915f126dcde
crc32: A64FC237
md5: 062a689f23b625419a851431f6447336
sha1: 44b7bc39071bd576ce0430c60b56b7214fb9ebe1
sha256: fda3457af3ee62993b607925e3b5fb8c0bca98512f5b6262b4bed915f126dcde
sha512: 29e2637aeb0418c3b4e48be8a1fd8f814c7f0ccedd4832e4d77d0098c498b41474ce6f9dae053ab5cb2d97ecad93372cc6b9dd172556cce81af0b5b7ae0a1514
ssdeep: 3072:PF74n6b7PXvo8SmTYRYnpp3gbQ7+o8efT/Kc72DryRIaeE3FRr:Pha6/fvo8nTYRYnR7Kc72Du3pHr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EDE3F106B74D3A9FF1AA0E35007E151B8695BE34271347CB650DBD6F6A6E3F29B14302
sha3_384: 2f5c64fafbc29c2d8490633ee679f573d3acde1abb8fe19c54f4185f3330b467495ed8802584bb38c4c2be8ff1eb8694
ep_bytes: 6a00588d14388d04308d3d6034020189
timestamp: 2013-08-17 15:33:00

Version Info:

CompanyName: TorchSoft
FileDescription: Registry Workshop
FileVersion: 4, 1, 0, 0
InternalName: Registry Workshop
LegalCopyright: Copyright 2004-2009
OriginalFilename: RegWorkshop.dll
ProductName: Registry Workshop
ProductVersion: 4, 1, 0, 0
Translation: 0x0409 0x04b0

Troj/ZAccess-PI also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Cridex.2
SkyhighZeroAccess-FBE!062A689F23B6
McAfeeZeroAccess-FBE!062A689F23B6
ZillyaTrojan.Kryptik.Win32.582598
SangforTrojan.Win32.Sirefef.Vco2
K7AntiVirusTrojan ( 0040f6661 )
AlibabaVirTool:Win32/Obfuscator.7870cec2
K7GWTrojan ( 004c484c1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Crypt_s.CPJ
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BIFQ
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Cridex.2
NANO-AntivirusTrojan.Win32.Maxplus.dclahz
AvastWin32:Evo-gen [Trj]
TencentWin32.Trojan.Generic.Agow
SophosTroj/ZAccess-PI
F-SecureTrojan.TR/Kazy.14796812
DrWebBackDoor.Maxplus.12847
VIPREGen:Heur.Cridex.2
TrendMicroTROJ_SIRFEF.SMAU
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.062a689f23b62541
EmsisoftGen:Heur.Cridex.2 (B)
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=85)
GDataGen:Heur.Cridex.2
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Kazy.14796812
VaristW32/S-b9845c87!Eldorado
Antiy-AVLTrojan[Backdoor]/Win32.ZAccess
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.BUFZ@4zx7zj
ArcabitTrojan.Cridex.2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sirefef.P
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.ZAccess.R79091
Acronissuspicious
ALYacGen:Heur.Cridex.2
VBA32BScope.Backdoor.Maxplus
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_SIRFEF.SMAU
RisingTrojan.Sirefef!8.137 (TFE:5:tTOfbPrEpKI)
IkarusTrojan.Crypt_s
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ZAccess.CVX!tr.bdr
BitDefenderThetaGen:NN.ZexaF.36738.ju0@aeCu25ai
AVGWin32:Evo-gen [Trj]
Cybereasonmalicious.9071bd
DeepInstinctMALICIOUS

How to remove Troj/ZAccess-PI?

Troj/ZAccess-PI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment