Spy Trojan

Trojan-Spy.Win32.Zbot.amqi removal instruction

Malware Removal

The Trojan-Spy.Win32.Zbot.amqi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.amqi virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Attempts to modify browser security settings
  • Modifies Terminal Server registry keys for persistence
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Zbot.amqi?


File Info:

name: BEBC979F37AD76DB77A5.mlw
path: /opt/CAPEv2/storage/binaries/326bf4e4017db87be4fb3cc653956d0f0b333df5599b5211bb09bea97a2e6593
crc32: 0B81EC75
md5: bebc979f37ad76db77a51106cc8bde42
sha1: d87775bac19cb1154b9c61bddb001ee25d90a617
sha256: 326bf4e4017db87be4fb3cc653956d0f0b333df5599b5211bb09bea97a2e6593
sha512: ed6c59b631342a2a983864b14329b3b47760d38847aa1d1ed35698b3865fb65f555b8de76422c9748b13475dfe323f098966edc246c005572cbff28cbe3b433d
ssdeep: 49152:lcqdOBSttso3Nlkj5N8vIF4pFP2bV7mGIs3Vk+UZVtiAmd2E:lcNBuj9lk1N8+4pB2LVkfzmd2E
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D1C53307C35921B1DCE09B7FB94222EA2BEF79741A16957239C7370335A23B50D827B6
sha3_384: f36fedf0aa6b267303ec9349806934050ca895a9dcbc1011630093c173f2f2ce05a7f0d1ee3982439465de7aa8bb10fb
ep_bytes: 6a7dffb5c4feffffe88be9ffffffb594
timestamp: 2008-04-05 22:00:33

Version Info:

InternalName: vyfsnkn
Author: houfwul
FileDescription: rjlikdu
FileVersion: 9.61.9
LegalCopyright: 2000-
Comments: lginp
CompanyName: mnjb
Web: pvrds
Translation: 0x0409 0x04b0

Trojan-Spy.Win32.Zbot.amqi also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.ManBat.1
FireEyeGeneric.mg.bebc979f37ad76db
McAfeeArtemis!BEBC979F37AD
CylanceUnsafe
VIPRETrojan-PWS.Win32.Zbot.gen.y (v)
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderGen:Heur.ManBat.1
BitDefenderThetaAI:Packer.A03FC3021F
CyrenW32/Trojan3.BXZ
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.MKS
ClamAVWin.Spyware.Zbot-1282
KasperskyTrojan-Spy.Win32.Zbot.amqi
NANO-AntivirusTrojan.Win32.Zbot.iutgfg
ViRobotTrojan.Win32.A.Zbot.1460120
RisingSpyware.Zbot!8.16B (RDMK:cmRtazpY+/ssoCfFbJK9ROKeA0di)
EmsisoftGen:Heur.ManBat.1 (B)
ComodoMalCrypt.Indus!@1qrzi1
DrWebTrojan.Packed.20343
ZillyaTrojan.Kryptik.Win32.897597
McAfee-GW-EditionBehavesLike.Win32.BadFile.vc
SophosML/PE-A + Mal/Qbot-B
APEXMalicious
JiangminTrojanSpy.Zbot.akuc
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=86)
Antiy-AVLTrojan/Generic.ASMalwS.1027D19
MicrosoftBackdoor:Win32/Bladabindi!ml
GDataGen:Heur.ManBat.1
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R2104
VBA32SScope.Trojan.Psyhopath.xh
ALYacGen:Heur.ManBat.1
IkarusTrojan-Spy.Win32.Zbot
PandaTrj/Sinowal.XER
YandexTrojan.GenAsa!IplvB5ptL3Q
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.GM!tr
AVGWin32:MalOb-IJ [Cryp]
Cybereasonmalicious.f37ad7
AvastWin32:MalOb-IJ [Cryp]

How to remove Trojan-Spy.Win32.Zbot.amqi?

Trojan-Spy.Win32.Zbot.amqi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment