Spy Trojan

Should I remove “Trojan-Spy.Win32.Zbot.ypnd”?

Malware Removal

The Trojan-Spy.Win32.Zbot.ypnd is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.ypnd virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Zbot.ypnd?


File Info:

crc32: 3E5D942B
md5: 8ba5fbc5f4f88bc5081037af18bdf971
name: 8BA5FBC5F4F88BC5081037AF18BDF971.mlw
sha1: 420adef6acee0eb21094a5f7cc39d9cdbf8f38d0
sha256: 47bc8d713d1dec1f0936db4e4c78dac4e49369f1a7abf1847fdddec7426d3efb
sha512: be1dfff9fa1d67e7eda60141c75dd28232eddeef4f5298fd98f2f30160e8de684fa247267d630fb37b55add7a5bfff0bf62a024d9504a7304b56fdf7b1acf8b9
ssdeep: 12288:w+XvXZ/4UMqWzddFrgwjdgSQJBH+XT9Mn6TIGZSkq:pXPZ/4KWfFrVdZQJBH+XBMn6EGZSb
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (C) DJSoft.Net
FileVersion: 2.5.1.8
CompanyName: DJSoft.Net
ProductName: Certifications
ProductVersion: 2.5.1.8
FileDescription: Propertyname Quantity Savannah Indicator
Translation: 0x0409 0x04b0

Trojan-Spy.Win32.Zbot.ypnd also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00503ae41 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2401
CynetMalicious (score: 100)
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.207136
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 00503ae41 )
Cybereasonmalicious.6acee0
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HAGO
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Spy.Win32.Zbot.ypnd
NANO-AntivirusTrojan.Win32.Zbot.evdgqj
TencentMalware.Win32.Gencirc.114952f8
Ad-AwareGen:Trojan.Heur.PM.2
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34110.Dq0@aWVHsVli
TrendMicroRansom_HPLOCKY.SME1
McAfee-GW-EditionGenericRXDJ-PU!8BA5FBC5F4F8
FireEyeGeneric.mg.8ba5fbc5f4f88bc5
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.flrg
AviraTR/Crypt.ZPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.22B6FC9
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Spyware/Win32.Zbot.C2368509
Acronissuspicious
McAfeeGenericRXDJ-PU!8BA5FBC5F4F8
VBA32TrojanSpy.Zbot
MalwarebytesMachineLearning/Anomalous.97%
TrendMicro-HouseCallRansom_HPLOCKY.SME1
RisingTrojan.Generic@ML.90 (RDML:VP6LPcemyKgEqSvTofXgxw)
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.FQUM!tr
AVGWin32:Malware-gen

How to remove Trojan-Spy.Win32.Zbot.ypnd?

Trojan-Spy.Win32.Zbot.ypnd removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment