Spy Trojan

Trojan-Spy.Win32.Zbot.zeil removal guide

Malware Removal

The Trojan-Spy.Win32.Zbot.zeil is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.zeil virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Steals private information from local Internet browsers
  • Spoofs its process name and/or associated pathname to appear as a legitimate process
  • Creates a hidden or system file
  • Creates a copy of itself
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system

Related domains:

eweeodoy.ru

How to determine Trojan-Spy.Win32.Zbot.zeil?


File Info:

crc32: 8E49166F
md5: d2748c2b4f6d86b34e40ddbca45932a0
name: D2748C2B4F6D86B34E40DDBCA45932A0.mlw
sha1: 15b1498bc931c82c17c3c9f39e08ca31b324162c
sha256: 3c29f239ae489d6a5ccd34a1f3ab26aaa09c4cc3203b79348e56f7966d94ed7c
sha512: 2d8a053c8bed7c035d78ff58c3df71e4ca78b93f4db70d776738b67e802a1be8cd4c2f5f1ce2a3d7d9fa0856f274aa2c15337914a599e2119e822433c537ed68
ssdeep: 6144:dgFSiiP51zsM10kaQRiiS7soFMSdBOk0RR43cTM:dg5iDwMjMiSriSirrrTM
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Cisco Systems xa9. All rights reserved.
FileVersion: 8.2.8.7
CompanyName: Cisco Systems
PrivateBuild: 8.2.8.7
ProductName: Xl
ProductVersion: 8.2.8.7
FileDescription: Appropriately Asr
Translation: 0x0409 0x04b0

Trojan-Spy.Win32.Zbot.zeil also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Stealer.24236
CynetMalicious (score: 99)
ALYacGen:Variant.Ransom.Scarab.43
CylanceUnsafe
SangforTrojan.Win32.Malware.gen
AlibabaTrojanSpy:Win32/Kryptik.3c435354
Cybereasonmalicious.b4f6d8
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GIWU
APEXMalicious
AvastFileRepMalware
KasperskyTrojan-Spy.Win32.Zbot.zeil
BitDefenderGen:Variant.Ransom.Scarab.43
NANO-AntivirusTrojan.Win32.Stealer.ffnyoc
MicroWorld-eScanGen:Variant.Ransom.Scarab.43
TencentWin32.Trojan-spy.Zbot.Wpsu
Ad-AwareGen:Variant.Ransom.Scarab.43
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34050.smKfaCej0nki
VIPREPacker.NSAnti.Gen (v)
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.d2748c2b4f6d86b3
EmsisoftGen:Variant.Ransom.Scarab.43 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.Zbot.fqas
AviraTR/Crypt.Agent.pzclx
Antiy-AVLTrojan/Generic.ASMalwS.27D1E2D
MicrosoftProgram:Win32/Wacapew.C!ml
GDataGen:Variant.Ransom.Scarab.43
Acronissuspicious
McAfeeArtemis!D2748C2B4F6D
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
PandaTrj/GdSda.A
IkarusTrojan-Ransom.GandCrab
FortinetW32/Kryptik.GKDU!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Zbot.HxMBEpsA

How to remove Trojan-Spy.Win32.Zbot.zeil?

Trojan-Spy.Win32.Zbot.zeil removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment