Malware

Troj/Zbot-NY removal instruction

Malware Removal

The Troj/Zbot-NY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Zbot-NY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Zbot-NY?


File Info:

name: 18CB4400C739C9D01B2B.mlw
path: /opt/CAPEv2/storage/binaries/da21e67194c135e625e8d9330c8b0e57c62cc5a298d34c16253108b96af70e32
crc32: F420433D
md5: 18cb4400c739c9d01b2b566d3d012870
sha1: 5a1b717c6d48887aa9b4ca178f31ffc999bbc8d1
sha256: da21e67194c135e625e8d9330c8b0e57c62cc5a298d34c16253108b96af70e32
sha512: 526db16bab43d398cecf29ed0780e6763659698ed0942ca075a9943dbaece0ffcb878fc2b885b6ba9b4e497ce2a42f53d9e0e5a11c42f214740356639bdc8aa6
ssdeep: 768:P0IrCuVNxSZDF+xOF4/i/BEYkp7P6lweQDhDmpU5GFrrEzWsdSE0d8pUHIkI0I4v:PRWdcxO+2G40OIkaxC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AF73C57EBCC65856E584023A371BCFDA95933A0CBF5F91C262982FBD8C28D544836673
sha3_384: 9d3dbc9e5c98e881a75298ff759058328c0ebf41cd5d179d4d1656e715b94b717faffb2867fc417470978c0b8948fbc7
ep_bytes: 53565755fc648b15300000008b520c8b
timestamp: 2009-12-10 13:38:26

Version Info:

Translation: 0x0409 0x04b0
CompanyName: kkYpePzU
ProductName: kkYpePzU
FileVersion: 3.38
ProductVersion: 3.38
InternalName: kkYpePzU
OriginalFilename: kkYpePzU.exe

Troj/Zbot-NY also known as:

BkavW32.AlterEIP.PE
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.87868
ClamAVWin.Trojan.VB-1207
CAT-QuickHealTrojan.Patched.AM
McAfeeVBObfus.b
MalwarebytesSmall.Trojan.Downloader.DDS
VIPRETrojan.GenericKDZ.87868
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 00133ee01 )
K7GWTrojan ( 00133ee01 )
CrowdStrikewin/malicious_confidence_100% (D)
BaiduWin32.Worm.Autorun.z
VirITWin32.Patched.J
CyrenW32/Zbot.T.gen!Eldorado
SymantecW32.Changeup
tehtrisGeneric.Malware
ESET-NOD32Win32/TrojanDownloader.Small.OUC
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.ZbotPatched.a
BitDefenderTrojan.GenericKDZ.87868
NANO-AntivirusVirus.Win32.Dlder.lbyd
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
AvastWin32:Zbodo [Inf]
TencentTrojan.Win32.Patched.k
SophosTroj/Zbot-NY
DrWebTrojan.Siggen.34201
ZillyaVirus.Starter.Win32.1
TrendMicroPE_ZBOT.A
McAfee-GW-EditionBehavesLike.Win32.VBObfus.lm
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.18cb4400c739c9d0
EmsisoftTrojan.GenericKDZ.87868 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.87868
JiangminTrojanDownloader.Genome.ghl
AviraTR/Patched.ZB
MAXmalware (ai score=86)
Antiy-AVLWorm/Win32.Vobfus
XcitiumTrojWare.Win32.Patched.O@1mj32s
ArcabitTrojan.Generic.D1573C
ViRobotWin32.PatchedZBot.A
MicrosoftVirus:Win32/Zbot.A
GoogleDetected
AhnLab-V3Win-Trojan/Patched.AE
Acronissuspicious
VBA32Trojan.ZbotPatched
ALYacTrojan.GenericKDZ.87868
TACHYONTrojan/W32.ZbotPatched.77824.B
Cylanceunsafe
TrendMicro-HouseCallPE_ZBOT.A
RisingWorm.Autorun!1.D162 (CLASSIC)
YandexTrojan.GenAsa!BuQA6xuGzUk
IkarusVirus.Worm
MaxSecureVirus.W32.ZbotPatched.A
FortinetW32/VBObfus.BDBD!tr
BitDefenderThetaAI:Packer.598D940D1F
AVGWin32:Zbodo [Inf]
Cybereasonmalicious.0c739c
PandaW32/Patched.L

How to remove Troj/Zbot-NY?

Troj/Zbot-NY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment