Spy Trojan

How to remove “Trojan-Spy.Win32.Zbot.zzvr”?

Malware Removal

The Trojan-Spy.Win32.Zbot.zzvr is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.zzvr virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Zbot.zzvr?


File Info:

crc32: B2A8BF19
md5: 04b88a3eb0a76036e10e87a3871c215f
name: upload_file
sha1: 327f8b95af6ee028447153366d6dc1fa1b45c21f
sha256: 359a83d05d6d30510f26f95146ddad7da943eb4e7014fa5c3a6caa41ac102681
sha512: 7949475844fb05df537ff43af30c6dfc12d7cea8b9b26014f7b34958d6acdae542f13ab3d6edb97cec3a73879c3d78c74757e5fef1516c9d944b37fe6ee36682
ssdeep: 6144:T2EDYH4aaPx2v909HPNvg/7K4GHTOmKcdKsXv5o7bKSMwaM0hY:qV5l09lg/7HGqm30sXv5gKSMwaM0hY
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.zzvr also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.69072
FireEyeGeneric.mg.04b88a3eb0a76036
McAfeeArtemis!04B88A3EB0A7
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0050b2d01 )
BitDefenderTrojan.GenericKDZ.69072
K7GWTrojan ( 0050b2d01 )
Cybereasonmalicious.eb0a76
Invinceaheuristic
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Trojan-gen
KasperskyTrojan-Spy.Win32.Zbot.zzvr
AlibabaRansom:Win32/generic.ali2000010
AegisLabTrojan.Win32.Malicious.4!c
TencentMalware.Win32.Gencirc.10bbe17d
Ad-AwareTrojan.GenericKDZ.69072
SophosMal/Generic-S
F-SecureHeuristic.HEUR/AGEN.1115437
DrWebTrojan.Encoder.32240
ZillyaTrojan.SageCrypt.Win32.204
TrendMicroMal_MiliCry-2t
FortinetW32/Kryptik.GPRG!tr
EmsisoftTrojan.GenericKDZ.69072 (B)
SentinelOneDFI – Suspicious PE
JiangminTrojan.SageCrypt.gg
AviraHEUR/AGEN.1115437
MAXmalware (ai score=85)
Antiy-AVLTrojan[Ransom]/Win32.SageCrypt
ArcabitTrojan.Generic.D10DD0
ZoneAlarmTrojan-Spy.Win32.Zbot.zzvr
MicrosoftTrojan:Win32/Ymacco.AA26
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R346410
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34142.zOW@aGbcdbdi
ALYacTrojan.GenericKDZ.69072
TACHYONRansom/W32.SageCrypt.416256
VBA32Hoax.SageCrypt
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Kryptik.GPRG
TrendMicro-HouseCallMal_MiliCry-2t
RisingStealer.Delf!8.415 (CLOUD)
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_99%
GDataTrojan.GenericKDZ.69072
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Trojan.Generic

How to remove Trojan-Spy.Win32.Zbot.zzvr?

Trojan-Spy.Win32.Zbot.zzvr removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment