Spy Trojan

Trojan-Spy.Win32.Zbot.qkds information

Malware Removal

The Trojan-Spy.Win32.Zbot.qkds is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.qkds virus can do?

  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan-Spy.Win32.Zbot.qkds?


File Info:

name: C7C499D5C946F94ED371.mlw
path: /opt/CAPEv2/storage/binaries/d5bfab909768f3ebbf55b623094be4a93dd2b4f3ebf1228bc06e2249c95db31a
crc32: 5C102EBF
md5: c7c499d5c946f94ed371aea25ac5d073
sha1: 792b971db41eb3b1583b784cc9edcea1869cae63
sha256: d5bfab909768f3ebbf55b623094be4a93dd2b4f3ebf1228bc06e2249c95db31a
sha512: bd936418b6b0dbb5096fcdad3d373f0d0ceebc3e1e6c544a06e8e6827ac7a265398ce87f145431de68af59c2ae89206f7622440ae2169608512fe7d1e9e2045a
ssdeep: 3072:Xcaqyte6VV77snHLLxtnyaXOqdPNbnhW4IxZx5kCZuubFrhU1wKKrWNm:XcaBtj77snHR8Y7PNNW4IxZ7zbC0rWNm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B0D3AF677480A0B2C5A73671AFA9B22527FFDD3425389C83E3980D6A35B1893731E747
sha3_384: d029c238f61ba8d07eab5e278a4c0c945236d89e67dca74b24f0a2c1e0b41b4ce23d6b1bd940af80672aa6fdf6430f05
ep_bytes: 558bec83ec105333c932dbe8bbf0ffff
timestamp: 2011-04-14 15:07:12

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.qkds also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zbot.ts2S
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.SpyEye.S
ClamAVWin.Spyware.Zbot-1275
FireEyeGeneric.mg.c7c499d5c946f94e
CAT-QuickHealTrojan.Necurs.MUE.A3
ALYacTrojan.SpyEye.S
Cylanceunsafe
VIPRETrojan.SpyEye.S
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 002891031 )
AlibabaMalware:Win32/km_2871.None
K7GWSpyware ( 002891031 )
CrowdStrikewin/malicious_confidence_100% (W)
BaiduWin32.Trojan.Zbot.a
VirITTrojan.Win32.Zbot.BOPD
CyrenW32/Zbot.BR.gen!Eldorado
SymantecTrojan.Zbot!gen19
ESET-NOD32Win32/Spy.Zbot.YW
ZonerTrojan.Win32.36816
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.qkds
BitDefenderTrojan.SpyEye.S
NANO-AntivirusTrojan.Win32.Panda.eplpjz
SUPERAntiSpywareTrojan.Agent/Gen-Cryptor
AvastSf:Crypt-BT [Trj]
TencentTrojan.Win32.Zbot.vv
EmsisoftTrojan.SpyEye.S (B)
F-SecureTrojan-Spy:W32/Zbot.AVTH
DrWebTrojan.PWS.Panda.786
ZillyaTrojan.Zbot.Win32.223247
TrendMicroTROJ_AGENT_048941.TOMB
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
Trapminemalicious.high.ml.score
SophosTroj/PWS-BSF
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.10S29XQ
JiangminTrojan/Invader.cfa
WebrootW32.Rogue.Gen
AviraTR/Spy.Zbot.619281
Antiy-AVLTrojan[Spy]/Win32.Zbot
XcitiumTrojWare.Win32.Spy.Zbot.BPOD@4vmcr7
ArcabitTrojan.SpyEye.S
ZoneAlarmTrojan-Spy.Win32.Zbot.qkds
MicrosoftPWS:Win32/Zbot!CI
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R4880
VBA32SScope.Trojan.FakeAV.01110
MAXmalware (ai score=100)
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/WLT.A
TrendMicro-HouseCallTROJ_AGENT_048941.TOMB
RisingSpyware.Zbot!1.648A (CLASSIC)
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AT!tr
BitDefenderThetaGen:NN.ZexaF.36662.imW@a4Cv8Kp
AVGSf:Crypt-BT [Trj]
Cybereasonmalicious.db41eb
DeepInstinctMALICIOUS

How to remove Trojan-Spy.Win32.Zbot.qkds?

Trojan-Spy.Win32.Zbot.qkds removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment