Trojan

Trojan.PWS.ZOB (file analysis)

Malware Removal

The Trojan.PWS.ZOB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.PWS.ZOB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the XpertRAT malware family
  • Anomalous binary characteristics

How to determine Trojan.PWS.ZOB?


File Info:

name: D85F991270D120B86B3B.mlw
path: /opt/CAPEv2/storage/binaries/499fa24e894c6a310ea8d8ca696ecb474ae6ea8fe5218c6657482d2ed9758c50
crc32: D41FC7CE
md5: d85f991270d120b86b3b421eb33a3dce
sha1: 3e8fd7d9675592e4a27e492aa89bb2352b53d96e
sha256: 499fa24e894c6a310ea8d8ca696ecb474ae6ea8fe5218c6657482d2ed9758c50
sha512: ec276835b8bd6dfbb3d1bed79e52b291d52dc05cef458edb6b261ec2cebc0b38fb3b29d608991ff4c078ca85a8ffe63ff7f1526aa0a8f3081fd513edf5a0c6d2
ssdeep: 3072:O4evOVoI9v0QhO3UZuGAT1PFluuXD5FNof9ziCl7xJMJa/Z6CNvS+xkDQ:Brh0hFtFe9mCBsJaci6+f
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T178442977B7C20F89E51D2A3529DAC7E267A3B80A0F07864F765433696C31D312DA6B13
sha3_384: d1cbd45d8172215e688d32f393e8b20d8e5be106eb6b16e31d58f784127b66eb11c3bdbcbba80f5f97cfc3b5478929ec
ep_bytes: 6830174000e8f0ffffff000000000000
timestamp: 2015-10-25 12:12:32

Version Info:

Translation: 0x0409 0x04b0
CompanyName: Abronsius
ProductName: Source
FileVersion: 3.00.0010
ProductVersion: 3.00.0010
InternalName: 1
OriginalFilename: 1.exe

Trojan.PWS.ZOB also known as:

tehtrisGeneric.Malware
DrWebTrojan.Siggen7.59190
MicroWorld-eScanTrojan.PWS.ZOB
FireEyeGeneric.mg.d85f991270d120b8
CAT-QuickHealTrojan.VBCrypt.MF.1072
ALYacTrojan.PWS.ZOB
CylanceUnsafe
Sangfor[MICROSOFT VISUAL BASIC V6.0]
BitDefenderThetaAI:Packer.A541646020
CyrenW32/VB-Dialog-Spyer-based!Maxim
SymantecML.Attribute.HighConfidence
ElasticWindows.Trojan.Xpertrat
ESET-NOD32a variant of Win32/XRat.AT
APEXMalicious
KasperskyWorm.Win32.VBNA.b
BitDefenderTrojan.PWS.ZOB
NANO-AntivirusTrojan.Win32.XRat.fjhldr
SUPERAntiSpywareTrojan.Agent/Gen-Vbject
AvastWin32:FakeVimes-B [Trj]
Ad-AwareTrojan.PWS.ZOB
EmsisoftTrojan.PWS.ZOB (B)
VIPRETrojan.PWS.ZOB
McAfee-GW-EditionBehavesLike.Win32.Trickbot.dm
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.PWS.ZOB
JiangminWorm.VBNA.arsy
GoogleDetected
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
ArcabitTrojan.PWS.ZOB
ZoneAlarmWorm.Win32.VBNA.b
MicrosoftWorm:Win32/Vobfus.gen!D
CynetMalicious (score: 99)
AhnLab-V3Worm/Win32.RL_VBNA.R271549
McAfeeGenericRXAA-AA!D85F991270D1
VBA32Trojan.VB.Motil
RisingTrojan.Autorun!1.DA78 (CLASSIC)
IkarusTrojan.Win32.VBKrypt
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:FakeVimes-B [Trj]
Cybereasonmalicious.270d12

How to remove Trojan.PWS.ZOB?

Trojan.PWS.ZOB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment