Spy Trojan

Trojan-Spy.Win32.Zbot.xill malicious file

Malware Removal

The Trojan-Spy.Win32.Zbot.xill is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.xill virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Zbot.xill?


File Info:

name: 513A9CC95F22B3FB7DBB.mlw
path: /opt/CAPEv2/storage/binaries/846ad173e980d701b9aa3e8e28406e05a020efd84dcb3fe1eed014b0d74ff6f2
crc32: 420F4255
md5: 513a9cc95f22b3fb7dbb85a63da49a14
sha1: 6545fd393d31c4389d6d28471553b8867c33464f
sha256: 846ad173e980d701b9aa3e8e28406e05a020efd84dcb3fe1eed014b0d74ff6f2
sha512: 44b70cbfaeadc379a6c216953fc85965d6c81892064e89f7e5d448a9b9856602521ace6cfdf68eb7ac41f488407875891ef52968405d3c94873635f93b70e3d4
ssdeep: 6144:ocTgjZMgOOEV7DONeRsr6L/CoOgPydNzv7nWIXlcW:jTgtizU6LzPONzTnWal
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F3D4E04CB101450ACAB6DE758774DE6E53D66C33E6382883054B05ECDBFEB990AB82F5
sha3_384: b94101ccc2560851ef4519c2f9eda69b684fb97f33d59fdf564264ed84c3f9cd2e05ebbb0cc726df50bf80ad9ec2b835
ep_bytes: 6870914800e8eeffffff000000000000
timestamp: 2016-10-24 18:05:10

Version Info:

Translation: 0x0409 0x04b0
Comments: Toldernes7
CompanyName: EA Sports
ProductName: Ilanddrevnes1
FileVersion: 5.04.0002
ProductVersion: 5.04.0002
InternalName: AX
OriginalFilename: AX.exe

Trojan-Spy.Win32.Zbot.xill also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.10359
MicroWorld-eScanGen:Heur.PonyStealer.Lm0@dKNjbAki
FireEyeGeneric.mg.513a9cc95f22b3fb
ALYacGen:Heur.PonyStealer.Lm0@dKNjbAki
CylanceUnsafe
Cybereasonmalicious.95f22b
ArcabitTrojan.PonyStealer.E24AC0
BitDefenderThetaGen:NN.ZevbaF.34062.Lm0@aKNjbAki
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
ClamAVWin.Packer.VbPack-0-6334882-0
KasperskyTrojan-Spy.Win32.Zbot.xill
BitDefenderGen:Heur.PonyStealer.Lm0@dKNjbAki
NANO-AntivirusTrojan.Win32.Panda.ehvgkf
Ad-AwareGen:Heur.PonyStealer.Lm0@dKNjbAki
EmsisoftGen:Heur.PonyStealer.Lm0@dKNjbAki (B)
McAfee-GW-EditionFareit-FRJ!513A9CC95F22
SophosML/PE-A + Mal/FareitVB-M
JiangminTrojanSpy.Zbot.fhog
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataGen:Heur.PonyStealer.Lm0@dKNjbAki
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R189474
McAfeeFareit-FRJ!513A9CC95F22
MAXmalware (ai score=86)
VBA32TScope.Trojan.VB
TrendMicro-HouseCallTrojanSpy.Win32.LOKI.SM.hp
RisingMalware.FakeDOC/ICON!1.9C3B (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DGRT!tr
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan-Spy.Win32.Zbot.xill?

Trojan-Spy.Win32.Zbot.xill removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment