Spy Trojan

Trojan-Spy.Win32.Zbot.ajcr (file analysis)

Malware Removal

The Trojan-Spy.Win32.Zbot.ajcr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.ajcr virus can do?

  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary

How to determine Trojan-Spy.Win32.Zbot.ajcr?


File Info:

name: 71BE5E368F24D806768A.mlw
path: /opt/CAPEv2/storage/binaries/115fdd8b77be4422de73f3fb5314cc69f653ca71795df2d6f63249e303cf59b7
crc32: 2BAF43A2
md5: 71be5e368f24d806768a84112f9f89fe
sha1: 119d7743734db3ba2aa6b0c9679637e831b7178d
sha256: 115fdd8b77be4422de73f3fb5314cc69f653ca71795df2d6f63249e303cf59b7
sha512: 6babab23950aeb8a243089002e0eabeb37218222248b1cfab82de22819ed5017016ee4eb329d7ed6e7e4a6dda61bc0271c58d98232df0cc416c8eefba2c907ed
ssdeep: 49152:stWHVR24F27Dwy9Sja0MWFoKP11110/a572:mQRBA7UyUJdq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A7A53325E3688AF6E4973271E501313661F7D46C4039BDE8D742A93E7CAFE14AF38522
sha3_384: 24a11973ce5c97055a2b4ee39f65bd39fd3d6b73ff9ca29bc5fbd5c3b2546adf9fe18b4fc018e5294bbae819a82397b4
ep_bytes: 558bec81ec4004000053565733db33ff
timestamp: 2008-01-14 15:11:43

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.ajcr also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.UserStartup.gwZ@aq6jt@f
FireEyeGeneric.mg.71be5e368f24d806
CAT-QuickHealTrojanspy.Zbot.20720
ALYacGen:Trojan.UserStartup.gwZ@aq6jt@f
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.20727
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 004da6c81 )
K7GWSpyware ( 004da6c81 )
Cybereasonmalicious.68f24d
ArcabitTrojan.UserStartup.E3F0DA
BitDefenderThetaGen:NN.ZexaF.34062.gwZ@aq6jt@f
CyrenW32/Zbot.AG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Zbot.ACH
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.ajcr
BitDefenderGen:Trojan.UserStartup.gwZ@aq6jt@f
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastSf:Zbot-CQ [Trj]
TencentMalware.Win32.Gencirc.11da28ee
Ad-AwareGen:Trojan.UserStartup.gwZ@aq6jt@f
EmsisoftGen:Trojan.UserStartup.gwZ@aq6jt@f (B)
ComodoTrojWare.Win32.Spy.Zbot.AKF@5s5xv5
DrWebTrojan.Webmoner.60984
SophosML/PE-A
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.aeiz
eGambitUnsafe.AI_Score_99%
AviraTR/Dropper.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.34D9CF3
MicrosoftPWS:Win32/Zbot.gen!R
APEXMalicious
GDataGen:Trojan.UserStartup.gwZ@aq6jt@f
AhnLab-V3Spyware/Win.Zbot.R455111
McAfeeGenericRXAA-AA!71BE5E368F24
VBA32SScope.Trojan.Bofa
MalwarebytesMalware.AI.2217174620
RisingTrojan.Generic@ML.86 (RDML:6C6TNARpzj9mQhRsbDy09w)
YandexTrojanSpy.Zbot!IG8ZxSXsJIk
IkarusTrojan-Spy.Win32.Zbot
FortinetW32/Zbot.JF!tr.spy
AVGSf:Zbot-CQ [Trj]
PandaTrj/Sinowal.WZX
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Spy.Win32.Zbot.ajcr?

Trojan-Spy.Win32.Zbot.ajcr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment