Spy Trojan

Trojan-Spy.Win32.Zbot.wptw (file analysis)

Malware Removal

The Trojan-Spy.Win32.Zbot.wptw is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.wptw virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Zbot.wptw?


File Info:

name: E5292CA5F7D8CD9D499B.mlw
path: /opt/CAPEv2/storage/binaries/f3416632211dabcf036f95e0818b5391d8d83a4a051fc06b05758de46780eeeb
crc32: 52BA3A55
md5: e5292ca5f7d8cd9d499bbe4c1c909be2
sha1: 0142a08be889ba29388a268641e22c222a532fd2
sha256: f3416632211dabcf036f95e0818b5391d8d83a4a051fc06b05758de46780eeeb
sha512: 39f7069054c4e62b4d0bc2fda1dda2fe3188c566aa875e5ac7b6882f4601e12fe0d6985d88f7436a83b915096b1567d51d67af5137e6958e930642003466ffc2
ssdeep: 3072:7tsaTXN2uHKN/BDzh/5jrCIHer7Zmv3HSruNyLamWjMAKdWr5:7GarN2uHKNfYJmaiNyVWPdr5
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17FD3AF27758090F3C5AB2271AAA9772563FFDD24323CDC83E2D84D6929A1993732D347
sha3_384: 756b2726ee3401bc4ed719e58dc6457f2bfaa8dfcca05c4c972002e78d58b1a7f6e93ef79445bf72126d7db57ce25f5b
ep_bytes: 558bec83ec10536a0032dbe86af0ffff
timestamp: 2011-11-13 19:26:48

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.wptw also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Mint.Dreidel.imX@xycrTBd
FireEyeGeneric.mg.e5292ca5f7d8cd9d
CAT-QuickHealTrojan.Zbot.AJ3
McAfeePWS-Zbot.gen.ds
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.47668
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 002891031 )
BitDefenderGen:Heur.Mint.Dreidel.imX@xycrTBd
K7GWSpyware ( 002891031 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34182.imX@aycrTBd
VirITTrojan.Win32.Generic.APFM
CyrenW32/Zbot.BR.gen!Eldorado
SymantecTrojan.Zbot!gen19
ESET-NOD32a variant of Win32/Spy.Zbot.YW
BaiduWin32.Trojan.Zbot.a
TrendMicro-HouseCallTSPY_ZBOT.SMIG
AvastSf:Crypt-BT [Trj]
ClamAVWin.Spyware.Zbot-1275
KasperskyTrojan-Spy.Win32.Zbot.wptw
NANO-AntivirusTrojan.Win32.Zbot.rilgh
RisingSpyware.Zbot!1.648A (RDMK:cmRtazpfBJRGln562sHwxFBPwiMZ)
Ad-AwareGen:Heur.Mint.Dreidel.imX@xycrTBd
EmsisoftGen:Heur.Mint.Dreidel.imX@xycrTBd (B)
ComodoTrojWare.Win32.Kazy.MKD@4qchol
DrWebBackDoor.Qbot.81
VIPRETrojan-PWS.Win32.Zbot.aac (v)
TrendMicroTSPY_ZBOT.SMIG
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
SentinelOneStatic AI – Malicious PE
SophosML/PE-A + Troj/PWS-BSF
APEXMalicious
JiangminTrojan/Generic.pxne
WebrootW32.Infostealer.Zeus
AviraTR/Kazy.MK
Antiy-AVLTrojan[Spy]/Win32.Zbot
MicrosoftPWS:Win32/Zbot!CI
ArcabitTrojan.Mint.Dreidel.EE70DD
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
ZoneAlarmTrojan-Spy.Win32.Zbot.wptw
GDataGen:Heur.Mint.Dreidel.imX@xycrTBd
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R4880
Acronissuspicious
VBA32SScope.Trojan.FakeAV.01110
ALYacGen:Heur.Mint.Dreidel.imX@xycrTBd
TACHYONTrojan-Spy/W32.ZBot.141824.AK
MalwarebytesSpyware.Zbot
PandaTrj/Genetic.gen
TencentTrojan.Win32.Zbot.b
YandexTrojanSpy.Zbot!NnHgntcZaqY
MAXmalware (ai score=85)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AT!tr
AVGSf:Crypt-BT [Trj]
Cybereasonmalicious.5f7d8c

How to remove Trojan-Spy.Win32.Zbot.wptw?

Trojan-Spy.Win32.Zbot.wptw removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment