Spy Trojan

Trojan-Spy.Win32.Zbot.xptp removal guide

Malware Removal

The Trojan-Spy.Win32.Zbot.xptp is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.xptp virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Attempts to identify installed AV products by registry key
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Zbot.xptp?


File Info:

crc32: C4F03C43
md5: b85b4236db84b823f951027426b8268c
name: B85B4236DB84B823F951027426B8268C.mlw
sha1: bff32952ed7eb1d14eeb8e7e7280b704004ac8e2
sha256: 9231d8b6080418d4bf09c044053eca773bf8a93861c1045db6e752b08529730e
sha512: 0848e882dfe0896d77a7e7fd73810ea0cde0d2ab8f73ddda41dae50182cd3926bb012759c0c70b0ca81191c393839c7eccbbcb0b58b5ed08f5d3c6b1973d0060
ssdeep: 6144:Q8dNXSE1bLe+GMG6MGDhWHoz1XLlZQF5QG5vfVIGYCoxneMGkKw3WPgKB6DOJqJ+:z1bLe+p4IJWQgCNuwvKB6DOJqJYe+lf
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.xptp also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.761
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A
ALYacTrojan.NSIS.Androm.CM
CylanceUnsafe
SangforSuspicious.Win32.Mikey.57069
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.6db84b
SymantecRansom.Cerber!g14
ESET-NOD32Win32/Filecoder.TorrentLocker.A
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Spy.Win32.Zbot.xptp
BitDefenderTrojan.NSIS.Androm.CM
NANO-AntivirusTrojan.Win32.Mikey.evnzca
MicroWorld-eScanTrojan.NSIS.Androm.CM
TencentWin32.Trojan-spy.Zbot.Pfjf
Ad-AwareTrojan.NSIS.Androm.CM
SophosMal/Generic-R + Mal/Miuref-L
F-SecureTrojan.TR/Injector.ajxoh
BitDefenderThetaGen:NN.ZedlaF.34678.eu4@aqWVcsb
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Cerber-NS3
McAfee-GW-EditionNSIS/ObfusRansom.i
FireEyeGeneric.mg.b85b4236db84b823
EmsisoftTrojan.NSIS.Androm.CM (B)
AviraHEUR/AGEN.1116903
MicrosoftRansom:Win32/Enestaller.A!rfn
ArcabitTrojan.NSIS.Androm.CM
AegisLabTrojan.Win32.Zbot.l!c
ZoneAlarmTrojan-Spy.Win32.Zbot.xptp
GDataTrojan.NSIS.Androm.CM
McAfeeArtemis!B85B4236DB84
MAXmalware (ai score=99)
VBA32BScope.Trojan.Agentb
PandaTrj/CI.A
TrendMicro-HouseCallMal_Cerber-NS3
RisingRansom.Enestedel!8.E513 (CLOUD)
YandexTrojan.Injector!oIWq05HLK6M
SentinelOneStatic AI – Suspicious PE
FortinetPossibleThreat
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan-Spy.Win32.Zbot.xptp?

Trojan-Spy.Win32.Zbot.xptp removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment