Spy Trojan

Should I remove “Trojan-Spy.Win32.Zbot.ujst”?

Malware Removal

The Trojan-Spy.Win32.Zbot.ujst is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.ujst virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Zbot.ujst?


File Info:

name: 0BD642D720B371B0D2E8.mlw
path: /opt/CAPEv2/storage/binaries/22ad2736003c9bf0c93359698113f4c98792074252474f60649ec4b2e5850519
crc32: 09C38E27
md5: 0bd642d720b371b0d2e804a3e96d0ae2
sha1: a530a1d9d5f70ec5402c1afa3d88be9522ac76c0
sha256: 22ad2736003c9bf0c93359698113f4c98792074252474f60649ec4b2e5850519
sha512: 9d0ecaf4b5c9973657eee824a33c7884f68bd663d63076066b05eb3f965b9086cb6ff3fb09c7fa4cefb293af2f895d72166576bd03bc93786930619525acdc24
ssdeep: 3072:VTLx50VJqtHGbu5XCniylWrtGA1GHvGXaCH1Fukp1A3wQek:VTLoGtmiYlW4A1QvGXjB/Q3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EEF3AF667584E0F3C9AB2271AA6D7376A3FFDD3421388C83E3144D6A2571893B21D74B
sha3_384: af17b2cb2ad656949a912aa6a25cb82acf8d85a033707742cb4970b3b65f838eb54c0edc7a5e1118046fa1e82d0c6b4d
ep_bytes: 558bec83ec10536a0032dbe86cf0ffff
timestamp: 2013-12-19 00:10:29

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.ujst also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Proxy.27230
CynetMalicious (score: 100)
FireEyeGeneric.mg.0bd642d720b371b0
CAT-QuickHealTrojan.Necurs.MUE.A3
ALYacTrojan.AutoIT.Injector.AN
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 002891031 )
K7GWTrojan ( 004aea031 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34212.jmW@a4d3lkp
VirITTrojan.Win32.Generic.BFTQ
CyrenW32/Zbot.BR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAQ
TrendMicro-HouseCallTSPY_ZBOT.SMIG
ClamAVWin.Spyware.Zbot-1275
KasperskyTrojan-Spy.Win32.Zbot.ujst
BitDefenderTrojan.AutoIT.Injector.AN
NANO-AntivirusTrojan.Win32.Panda.cswodz
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
MicroWorld-eScanTrojan.AutoIT.Injector.AN
AvastSf:Crypt-BT [Trj]
TencentTrojan-spy.Win32.Zbot.sbdja
Ad-AwareTrojan.AutoIT.Injector.AN
EmsisoftTrojan.AutoIT.Injector.AN (B)
ComodoTrojWare.Win32.Kazy.MKD@4qchol
BaiduWin32.Trojan.Zbot.a
VIPRETrojan-PWS.Win32.Zbot.aac (v)
TrendMicroTSPY_ZBOT.SMIG
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
SophosML/PE-A + Troj/PWS-BSF
IkarusTrojan-Spy.Zbot
GDataWin32.Trojan-Spy.Zbot.DB
JiangminTrojanSpy.Zbot.eeog
AviraTR/Kazy.MK
ArcabitTrojan.AutoIT.Injector.AN
ZoneAlarmTrojan-Spy.Win32.Zbot.ujst
MicrosoftPWS:Win32/Zbot!ZA
AhnLab-V3Win-Trojan/Malpacked3.Gen
Acronissuspicious
McAfeePWS-Zbot.gen.ave
MAXmalware (ai score=87)
VBA32SScope.Trojan.FakeAV.01110
MalwarebytesMalware.AI.1727413644
APEXMalicious
RisingSpyware.Zbot!1.648A (RDMK:cmRtazr6YLG8ACAX4WymnxWFhzXQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AT!tr
AVGSf:Crypt-BT [Trj]
PandaTrj/WLT.B

How to remove Trojan-Spy.Win32.Zbot.ujst?

Trojan-Spy.Win32.Zbot.ujst removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment