Spy Trojan

Trojan-Spy.Win32.Zbot.rmug removal guide

Malware Removal

The Trojan-Spy.Win32.Zbot.rmug is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.rmug virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Trojan-Spy.Win32.Zbot.rmug?


File Info:

name: F849882E20FC01C66B3F.mlw
path: /opt/CAPEv2/storage/binaries/9d0ea484722b768f02a39370ccac459fcdae7bf9c5aefa34602cf3140ca407bf
crc32: DD88817A
md5: f849882e20fc01c66b3fcf435b984ac6
sha1: cb51a5dfa273c0f2dccb12ca7b3355d0627e0c37
sha256: 9d0ea484722b768f02a39370ccac459fcdae7bf9c5aefa34602cf3140ca407bf
sha512: 6e75d184171604feebd34aa67de65dc7c08207e5f69f2036df71f93cca780aee05cf2b40171b17cae300a1af4bd3018c5ac3ff4faccfb36dc28d9b7a541b7bf3
ssdeep: 6144:7pe4cA+M5iz9abnFF/pNN2xCy95+WhJGtYg2KVytqlzN4xlFoaU4B:koizgNN2x795+aGtJ2bBlFoaUe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E84D0D5B56ED037D1233474302A9173C4B78DF38A5ACA8303F19EAEDA7C68B421A597
sha3_384: 8c6fdcdc767fb8bdf99714435072a221ba13c55a29c57872b3a290caca232f3b91f43b033dbacd2dd791954f4b9cb155
ep_bytes: e8471b0000e989feffff660fefc05153
timestamp: 2014-02-02 19:50:11

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.rmug also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.m4GC
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.1568778
FireEyeGeneric.mg.f849882e20fc01c6
ALYacTrojan.GenericKD.1568778
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/Generic.ae347240
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.e20fc0
VirITTrojan.Win32.Panda.IKI
CyrenW32/Trojan.CMEL-2108
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.rmug
BitDefenderTrojan.GenericKD.1568778
NANO-AntivirusTrojan.Win32.Zbot.ctrzss
TencentMalware.Win32.Gencirc.114cb60a
Ad-AwareTrojan.GenericKD.1568778
SophosML/PE-A + Troj/Zbot-HPW
ComodoMalware@#ptwxp796hxfm
DrWebTrojan.PWS.Panda.5676
ZillyaTrojan.Zbot.Win32.147723
TrendMicroTSPY_ZBOT.TEYHH
McAfee-GW-EditionBehavesLike.Win32.Trojan.fh
EmsisoftTrojan.GenericKD.1568778 (B)
IkarusTrojan-Dropper
GDataWin32.Trojan.Agent.QANB1X
JiangminTrojanSpy.Zbot.ebxy
WebrootW32.Infostealer.Zeus
AviraTR/PSW.Zbot.akz.13
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ArcabitTrojan.Generic.D17F00A
ZoneAlarmTrojan-Spy.Win32.Zbot.rmug
MicrosoftPWS:Win32/Zbot.AKZ
AhnLab-V3Spyware/Win32.Zbot.C287721
Acronissuspicious
McAfeeGeneric.dfc
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/WLT.A
TrendMicro-HouseCallTSPY_ZBOT.TEYHH
RisingTrojan.Spy.Win32.Zbot.gig (CLOUD)
YandexTrojanSpy.Zbot!VSccvgrL/64
SentinelOneStatic AI – Suspicious PE
eGambitGeneric.PSW
FortinetW32/Zbot.RYVR!tr
BitDefenderThetaGen:NN.ZexaF.34212.xqW@ayxGE9ai
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Spy.Win32.Zbot.rmug?

Trojan-Spy.Win32.Zbot.rmug removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment