Spy Trojan

Trojan-Spy.Win32.Zbot.awbh removal tips

Malware Removal

The Trojan-Spy.Win32.Zbot.awbh is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.awbh virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Zbot.awbh?


File Info:

name: 54488C7C18C74117851F.mlw
path: /opt/CAPEv2/storage/binaries/cba3646a96f4ea8842bf5a46392892eaea01e0dc4da6e065382d4c4a6683b800
crc32: B96F58A2
md5: 54488c7c18c74117851f786d2dc61fac
sha1: d3ab0272124d07583950734cd5734ee9bfe78b4c
sha256: cba3646a96f4ea8842bf5a46392892eaea01e0dc4da6e065382d4c4a6683b800
sha512: d88d94ad974b5d70133ce54c0cca7559d3690f7db049ee5a90b97609eeb1425d96447dd1281c22d0cf0d33511f70dd429237293e2baf43b6f4fdf5d24011eff9
ssdeep: 3072:hbGfm3VPasCYvXNYId0Kn0MCFm8qFphVcM0DJW1BlGFOY:8fehCeNYId0Kn0XFFQHVL2k
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T130E3132D130CDC68C18F5B7B32E2B92A1006DD259859425C69E1FA1FCDBBF067E2D798
sha3_384: bb01e39a147153c361a0029e27018e6451276bb837af34048329788f5b6523a94f94694f26a0af0d71e8647452d37d76
ep_bytes: 60be001041008dbe0000ffff57eb0b90
timestamp: 2004-09-06 12:29:09

Version Info:

Comments:
CompanyName: Avira GmbH
FileDescription: Antivirus Control Center
FileVersion: 8.00.70.08
InternalName: Control Center
LegalCopyright: Copyright © 2008 Avira GmbH. All rights reserved.
LegalTrademarks: AntiVir® is a registered trademark of Avira GmbH, Germany.
OriginalFilename: avcenter.exe
PrivateBuild:
ProductName: AntiVir Workstation
ProductVersion: 8.00.70.08
SpecialBuild:
Translation: 0x0800 0x04b0

Trojan-Spy.Win32.Zbot.awbh also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.54488c7c18c74117
CAT-QuickHealTrojanBNK.Zbot.mue
McAfeeArtemis!54488C7C18C7
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.42441
SangforTrojan.Win32.Zbot.ZA
K7AntiVirusTrojan ( 004af95c1 )
AlibabaTrojanSpy:Win32/Kryptik.82d09e4c
K7GWTrojan ( 004af95c1 )
Cybereasonmalicious.c18c74
VirITTrojan.Win32.Generic.AOQA
CyrenW32/S-5f8a72a3!Eldorado
SymantecTrojan.Spyeye
ESET-NOD32a variant of Win32/Kryptik.JAV
APEXMalicious
KasperskyTrojan-Spy.Win32.Zbot.awbh
BitDefenderGen:Variant.Bredo.22
NANO-AntivirusTrojan.Win32.Zbot.bvmma
SUPERAntiSpywareTrojan.Spys-Bredo
MicroWorld-eScanGen:Variant.Bredo.22
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Zbot.Stue
Ad-AwareGen:Variant.Bredo.22
EmsisoftGen:Variant.Bredo.22 (B)
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
DrWebBackDoor.Qbot.77
VIPREVirTool.Win32.Obfuscator.da!j (v)
TrendMicroTROJ_SPYEYE.SMEP
McAfee-GW-EditionPWS-Spyeye.fa
SophosML/PE-A + Mal/FakeAV-BW
IkarusTrojan.Win32.Spyeye
GDataGen:Variant.Bredo.22
JiangminTrojanSpy.Zbot.fphd
WebrootW32.InfoStealer.Zeus
AviraTR/Crypt.EPACK.Gen2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
AhnLab-V3Spyware/Win32.Zbot.R2551
BitDefenderThetaGen:NN.ZexaF.34212.jmKfa4@Tdrmc
ALYacGen:Variant.Bredo.22
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
RisingSpyware.SpyEyes!8.4AA (CLOUD)
YandexTrojanSpy.Zbot!QerNIxTd0g8
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1697573.susgen
FortinetW32/Kryptic!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan-Spy.Win32.Zbot.awbh?

Trojan-Spy.Win32.Zbot.awbh removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment