Spy Trojan

How to remove “Trojan-Spy.Win32.Zbot.bene”?

Malware Removal

The Trojan-Spy.Win32.Zbot.bene is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.bene virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Attempts to modify desktop wallpaper
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Harvests credentials from local FTP client softwares
  • Collects information to fingerprint the system
  • Clears web history

How to determine Trojan-Spy.Win32.Zbot.bene?


File Info:

name: 9D2D7CC7385BFB870972.mlw
path: /opt/CAPEv2/storage/binaries/4136f331a70b343934cd2a452891beb307d567ac099a6e52d623d31ae3f943f1
crc32: 15A99850
md5: 9d2d7cc7385bfb870972b277b5e5c959
sha1: 7b3b92e7a0681c3d7e796cc3403344d39c935886
sha256: 4136f331a70b343934cd2a452891beb307d567ac099a6e52d623d31ae3f943f1
sha512: 6857f101392cc69c33d2bb2540b31624ed370a91d6f932dfd56b527d480636001dccaaacae014f9a6e1437efa4627fd7d61927f9f2624108cf89ba30afeab0cf
ssdeep: 3072:EZE4glNXqhzMxf5H7E0/yqDoUP/lpCn3yyxamPDyLYOP:CEF2wrhfvP/jmDyk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T116D312DCD07CA1B2CB83A73220DA67985E32FA14C3164D9FCEC459255F0C652754DEEA
sha3_384: 6d23ab194b09e31e02c67a3026a4496f0dddfc7eb579bc3f0059317b3d55879737d236fe2248bb959f5e3692892e15f1
ep_bytes: 60be15b042008dbeeb5ffdff57eb0b90
timestamp: 2006-11-21 22:17:43

Version Info:

CompanyName: Yjraeuwh Wvlgdqex
FileDescription: Yjraeuwh Wepjre Osopx
FileVersion: 5, 4, 52, 114
InternalName: Yjraeuwh
LegalCopyright: Copyright © Yjraeuwh Wvlgdqex 1996-2011
OriginalFilename: Yjraeuwh.exe
ProductName: Yjraeuwh Wepjre Osopx
ProductVersion: 27, 4, 106, 27
Translation: 0x0409 0x04e4

Trojan-Spy.Win32.Zbot.bene also known as:

BkavW32.MosquitoQKK.Fam.Trojan
LionicTrojan.Win32.Zbot.l!c
DrWebTrojan.PWS.Panda.387
MicroWorld-eScanGen:Heur.VIZ.!e!.1
FireEyeGeneric.mg.9d2d7cc7385bfb87
CAT-QuickHealWorm.SlenfBot.Gen
McAfeeW32/Pinkslipbot.gen.af
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.31927
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f1000f011 )
AlibabaTrojanSpy:Win32/Kryptik.98914049
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.7385bf
BitDefenderThetaGen:NN.ZexaF.34212.imKfamC6ZTjc
VirITTrojan.Win32.Generic.AZZE
CyrenW32/Zbot.CN.gen!Eldorado
SymantecW32.Qakbot!gen5
ESET-NOD32a variant of Win32/Kryptik.LJO
TrendMicro-HouseCallBKDR_QAKBOT.SMG
ClamAVWin.Trojan.Zbot-27439
KasperskyTrojan-Spy.Win32.Zbot.bene
BitDefenderGen:Heur.VIZ.!e!.1
NANO-AntivirusTrojan.Win32.Zbot.cjiry
SUPERAntiSpywareTrojan.Agent/Gen-Cryptic
AvastFileRepMetagen [Malware]
TencentWin32.Trojan-spy.Zbot.Huft
Ad-AwareGen:Heur.VIZ.!e!.1
SophosMal/Generic-R + Mal/FakeAV-IU
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
VIPRETrojan.Win32.Kryptik.lbu (v)
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionW32/Pinkslipbot.gen.af
EmsisoftGen:Heur.VIZ.!e!.1 (B)
IkarusTrojan.Win32.Crypt
GDataGen:Heur.VIZ.!e!.1
JiangminTrojanSpy.Zbot.avqz
eGambitGeneric.PSW
AviraTR/Crypt.ULPM.Gen
Antiy-AVLTrojan/Generic.ASMalwS.18E3415
ViRobotTrojan.Win32.A.Zbot.133120.BG
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Bagsu!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.FraudPack.R3415
ALYacGen:Heur.VIZ.!e!.1
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
APEXMalicious
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.GenAsa!6PQm0jGs8mw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.NAS!tr
WebrootW32.Backdoor.Mosucker
AVGFileRepMetagen [Malware]
PandaBck/Qbot.AO

How to remove Trojan-Spy.Win32.Zbot.bene?

Trojan-Spy.Win32.Zbot.bene removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment