Spy Trojan

Trojan-Spy.Win32.Zbot.wzzc removal

Malware Removal

The Trojan-Spy.Win32.Zbot.wzzc is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.wzzc virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • The binary likely contains encrypted or compressed data.
  • Behavior consistent with a dropper attempting to download the next stage.
  • Exhibits behavior characteristic of Locky ransomware
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
ujbbhgwipkqjsaicy.pw
mijdekojfb.info
uxeaayatyoywo.work
dxhfptjej.biz
afxmwhegxfkqwffl.biz
trlcfonolgjpvoe.biz
pqnxtjbjmdeubjkdt.org
nqibxpnga.pw
jbumalfkkhwdmn.work

How to determine Trojan-Spy.Win32.Zbot.wzzc?


File Info:

crc32: A7A9BD1B
md5: c9245f48a77e050b05cbbd8b2a193a08
name: C9245F48A77E050B05CBBD8B2A193A08.mlw
sha1: 2e8dea3813c3a5d0a526de7d39c84c80be96de8f
sha256: c888405d5126b6d826bd08cea83af52c01e34b1046859fa6c6a7a635bd5ab2c4
sha512: a597b0381af46d4304c506223e14606c34415876b890dcdf4d2d4ad256e8936d15cd6acd9f7f2d29d06142ab3d78dfaee1dd13919784308d601788ce2f41d610
ssdeep: 3072:9kr5h3oN8obmVWE40rD6iYE/Hkp5KOWj2MF86uhdoSjI0qiRXiN8yEPqHMDPF1ss:9kr5h39oSWN0rKQk4KMF86XSj9NYH1/0
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.wzzc also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 004eff041 )
LionicTrojan.Win32.Zbot.tnd3
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.3976
CynetMalicious (score: 100)
ALYacTrojan.CryptoLocker.EX
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.197804
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojanSpy:Win32/Obfuscator.c7c48730
K7GWTrojan ( 004eff041 )
Cybereasonmalicious.8a77e0
CyrenW32/Trojan.HNLZ-7537
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Filecoder.Locky.C
ZonerTrojan.Win32.44212
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Agent-7164882-1
KasperskyTrojan-Spy.Win32.Zbot.wzzc
BitDefenderTrojan.CryptoLocker.EX
NANO-AntivirusTrojan.Win32.Zbot.fjcros
MicroWorld-eScanTrojan.CryptoLocker.EX
TencentMalware.Win32.Gencirc.10b3a65a
Ad-AwareTrojan.CryptoLocker.EX
SophosMal/Generic-S
ComodoMalware@#o768y3e1dqkx
BitDefenderThetaGen:NN.ZexaF.34088.tyW@aCH5HOli
VIPRETrojan.Win32.Generic.pak!cobra
TrendMicroMal_Cerber-3
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.c9245f48a77e050b
EmsisoftTrojan.CryptoLocker.EX (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.fgik
AviraHEUR/AGEN.1127213
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.1AAE9AB
MicrosoftVirTool:Win32/Obfuscator.ALX
SUPERAntiSpywareRansom.Locky/Variant
ZoneAlarmTrojan-Spy.Win32.Zbot.wzzc
GDataTrojan.CryptoLocker.EX
TACHYONTrojan-Spy/W32.ZBot.315392.BCN
AhnLab-V3Trojan/Win32.Locky.C1531632
Acronissuspicious
McAfeeGenericRXAA-AA!C9245F48A77E
MAXmalware (ai score=100)
VBA32BScope.TrojanSpy.Zbot
MalwarebytesRansom.Locky
PandaTrj/RansomCrypt.J
TrendMicro-HouseCallMal_Cerber-3
RisingTrojan.Generic@ML.100 (RDML:t1Tjj7omvsMoOWkvLUOkfg)
YandexTrojan.GenAsa!q2h+r2/iVio
IkarusTrojan-Ransom.Locky
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Generic.AP.EE246!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Zbot.HgIASOoA

How to remove Trojan-Spy.Win32.Zbot.wzzc?

Trojan-Spy.Win32.Zbot.wzzc removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment