Spy Trojan

How to remove “Trojan-Spy.Win32.Zbot.zyof”?

Malware Removal

The Trojan-Spy.Win32.Zbot.zyof is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.zyof virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Zbot.zyof?


File Info:

crc32: B186EAC1
md5: d44d6b1a10589c18f683310ae8c2f337
name: tmpu7uw8g_m
sha1: edb83c662a375d5166529cb05540fd2061fd0eec
sha256: 70dc6ed09fe1816be0e1f13eb096b9567c246f8aa139f33acba42017cfecb869
sha512: 69b9146bae44a9ae065de317912be6a113da5882f13775b34927197acda4b6f2f0e7e25c399e572c98dcb90e0f8e965b553f66d2388085bfcc0e216eada8df43
ssdeep: 6144:uNXhQpCHma2ON49tSukOTWYHB6QWdQQef8bCk60Lx086VGA4AsAfkJMVs7ALcmv:uXhQpBJ8y9PTWMPfCU098V4AsbMHkM8
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 1995-2011 Invent Handburn big Corporation. All rights reserved.
InternalName: No.dll
FileVersion: 7.0.7875.8290
CompanyName: Invent Handburn
ProductName: Invent Handburn Basicmajor keep
ProductVersion: 7.0.7875.8290
FileDescription: Basicmajor keep
OriginalFilename: No.dll
Translation: 0x0409 0x04b0

Trojan-Spy.Win32.Zbot.zyof also known as:

MicroWorld-eScanTrojan.GenericKD.42866194
FireEyeTrojan.GenericKD.42866194
CAT-QuickHealRiskware.Win32
Qihoo-360Win32/Trojan.Spy.af6
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zbot.l!c
SangforMalware
BitDefenderTrojan.GenericKD.42866194
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
F-ProtW32/Agent.BQN.gen!Eldorado
SymantecTrojan Horse
AvastWin32:Trojan-gen
GDataWin32.Trojan.Crypt.R
KasperskyTrojan-Spy.Win32.Zbot.zyof
AlibabaTrojanSpy:Win32/Occamy.755c8148
NANO-AntivirusTrojan.Win32.Zbot.hgfmiw
RisingSpyware.Zbot!8.16B (CLOUD)
Ad-AwareTrojan.GenericKD.42866194
SophosMal/Generic-S
F-SecureTrojan.TR/AD.ZLoader.bvoeu
ZillyaTrojan.Zbot.Win32.210852
TrendMicroTrojanSpy.Win32.ZBOT.CDY
McAfee-GW-EditionRDN/Generic PWS.y
EmsisoftTrojan.GenericKD.42866194 (B)
SentinelOneDFI – Suspicious PE
CyrenW32/Trojan.PLSV-7976
JiangminTrojanSpy.Zbot.fquz
WebrootW32.Trojan.Gen
AviraTR/AD.ZLoader.bvoeu
Antiy-AVLTrojan[Spy]/Win32.Zbot
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28E1612
ZoneAlarmTrojan-Spy.Win32.Zbot.zyof
MicrosoftTrojan:Win32/Occamy.C
TACHYONTrojan-Spy/W32.ZBot.460800.AO
AhnLab-V3Trojan/Win32.Zbot.R329636
ALYacTrojan.Agent.Wacatac
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
MalwarebytesSpyware.PasswordStealer
PandaTrj/GdSda.A
ESET-NOD32Win32/Spy.Zbot.ADI
TrendMicro-HouseCallTrojanSpy.Win32.ZBOT.CDY
TencentMalware.Win32.Gencirc.114b3b5b
YandexTrojanSpy.Zbot!jqdlzo8Ihlk
IkarusTrojan.Win32.Krypt
FortinetW32/GenKryptik.EGQU!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
MaxSecureTrojan.Malware.1728101.susgen

How to remove Trojan-Spy.Win32.Zbot.zyof?

Trojan-Spy.Win32.Zbot.zyof removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment