Spy Trojan

Trojan-Spy.Win32.Zbot.yvsz removal guide

Malware Removal

The Trojan-Spy.Win32.Zbot.yvsz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.yvsz virus can do?

  • Reads data out of its own binary image
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Zbot.yvsz?


File Info:

crc32: 8A3E69FA
md5: 9b4abc5ec562861af2eba860bf03c8ca
name: 9B4ABC5EC562861AF2EBA860BF03C8CA.mlw
sha1: 79ae46f0b50906c450d95fc8c7a5fa25bc7477da
sha256: 33de9e5cff9f67419ebce14ad0283e607bd7855fa79f196050ad5aa5aa424df5
sha512: 164febafc1d304dd9253acd394b23ea22c4d9a5d007c6bb114e3a14d2e1d7aa0a0248eb185edc2ab4b8eb6db8a281b11c7bf43ac89cce06dd2c8aa960054c98c
ssdeep: 48:6ladQmZmsZphFjTA6BB9tyiH6qgzp/La9+wDW+bQg3Ebjn+CXFrV:amgelr1t5aX/YPJX2xrV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: System Server (32bit)
FileVersion: 4.12
FileDescription: System Server (32bit)
Translation: 0x0409 0x04b0

Trojan-Spy.Win32.Zbot.yvsz also known as:

K7AntiVirusTrojan ( 0017c3171 )
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.Starter.1480
ClamAVWin.Trojan.Xblocker-2
ALYacGen:Variant.Ulise.23277
CylanceUnsafe
ZillyaTrojan.XBlocker.Win32.195
SangforTrojan.Win32.Agent.8
BitDefenderGen:Variant.Ulise.23277
K7GWTrojan ( 0017c3171 )
Cybereasonmalicious.ec5628
CyrenW32/Risk.HRHC-2539
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Small.NIE
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.yvsz
NANO-AntivirusTrojan.Win32.XBlocker.cprmd
ViRobotTrojan.Win32.Ransom.5632.A
MicroWorld-eScanGen:Variant.Ulise.23277
TencentMalware.Win32.Gencirc.11c309b4
Ad-AwareGen:Variant.Ulise.23277
SophosMal/Generic-S
ComodoTrojWare.Win32.Ransom.XBlocker.A@2a393l
BitDefenderThetaAI:Packer.4AF922EA20
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionGenericRXAI-FM!9B4ABC5EC562
FireEyeGeneric.mg.9b4abc5ec562861a
EmsisoftGen:Variant.Ulise.23277 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/XBlocker.vn
WebrootW32.Trojan.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASBOL.1923
MicrosoftTrojan:Win32/Pynamer.A!rfn
GDataGen:Variant.Ulise.23277
AhnLab-V3Trojan/Win32.XBlocker.C57700
McAfeeGenericRXAI-FM!9B4ABC5EC562
MAXmalware (ai score=100)
VBA32Trojan.Qhost
MalwarebytesMalware.AI.1668232860
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_RANSOM_000001d.TOMA
RisingTrojan.Generic@ML.100 (RDML:5pSP9IDNhRPowRpTKWumLQ)
YandexTrojan.GenAsa!pk/WK0+MRpk
IkarusTrojan-Ransom.XBlocker
MaxSecureTrojan.Malware.1785519.susgen
FortinetW32/Generic.AC.32B5F!tr
Paloaltogeneric.ml

How to remove Trojan-Spy.Win32.Zbot.yvsz?

Trojan-Spy.Win32.Zbot.yvsz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment