Spy Trojan

Trojan-Spy.Win32.Zbot.aymu removal guide

Malware Removal

The Trojan-Spy.Win32.Zbot.aymu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.aymu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Zbot.aymu?


File Info:

name: DD7D621DBA0028A91472.mlw
path: /opt/CAPEv2/storage/binaries/faa76d56c6e8f80876cca77d48b0feb2791e57879d26fb617ef38ab499fe2ba3
crc32: 74940164
md5: dd7d621dba0028a91472810250c98968
sha1: c0000076684171d51959895b94c363e0c723b505
sha256: faa76d56c6e8f80876cca77d48b0feb2791e57879d26fb617ef38ab499fe2ba3
sha512: 2f1da7fbeb579e300ff6fca181db4b15d080a579bac835adf051caa3c816618f6b5dec505a27c4caf327bb8f8124ee196901b652d98a7ee91ae47da81a7371c0
ssdeep: 3072:yo72iYd5XbdocDtiiJxGmr3wgTD8F9mqqzBZCZ4on4p8nYkaIC0r:naiC/ocDu+ggTymqqzH6YkaI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15124CF05A1854B27D6B8A736FD43DE87A27D306535E54A1B13A24F04BEF362F7607322
sha3_384: 7f4d90972d391be0bc565c448b2b78a221d127a977ea4dd3938717e24612cd0dd7bd40e5e63e2426db20411eaf984aa8
ep_bytes: 558bec83c4f051ff75e48d4de051ff75
timestamp: 2008-08-19 16:28:49

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.aymu also known as:

DrWebTrojan.PWS.Panda.387
FireEyeGeneric.mg.dd7d621dba0028a9
McAfeePWS-Spyeye.fe
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.33266
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004bcce41 )
AlibabaTrojanSpy:Win32/Kryptik.3efee019
K7GWTrojan ( 004bcce41 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.BFBE3D131F
VirITTrojan.Win32.FakeAV.IEP
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.JSA
TrendMicro-HouseCallTROJ_SPYEYE.SMEP
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.aymu
BitDefenderMemScan:Trojan.Spy.ZBot.EQH
NANO-AntivirusTrojan.Win32.Zbot.ctahi
ViRobotTrojan.Win32.A.Zbot.223744.E
MicroWorld-eScanMemScan:Trojan.Spy.ZBot.EQH
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Zbot.Wtxl
Ad-AwareMemScan:Trojan.Spy.ZBot.EQH
EmsisoftMemScan:Trojan.Spy.ZBot.EQH (B)
ComodoPacked.Win32.MUPX.Gen@24tbus
VIPREPacked.Win32.PWSZbot.gen (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.dm
SophosMal/Generic-R + Mal/EncPk-OJ
IkarusTrojan.Win32.Spyeye
GDataMemScan:Trojan.Spy.ZBot.EQH
JiangminTrojanSpy.Zbot.auqs
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Spy]/Win32.Zbot
SUPERAntiSpywareTrojan.Agent/Gen-DitherC
ZoneAlarmTrojan-Spy.Win32.Zbot.aymu
MicrosoftPWS:Win32/Zbot.gen!Y
AhnLab-V3Trojan/Win32.Zbot.R2835
Acronissuspicious
ALYacMemScan:Trojan.Spy.ZBot.EQH
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.Heuristic.1003
APEXMalicious
RisingMalware.Undefined!8.C (TFE:2:h3sNNANEVvM)
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Zbot.AYMU!tr
WebrootW32.Infostealer.Zeus
AVGWin32:Trojan-gen
Cybereasonmalicious.dba002
PandaTrj/CI.A

How to remove Trojan-Spy.Win32.Zbot.aymu?

Trojan-Spy.Win32.Zbot.aymu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment