Spy Trojan

Trojan.Spy.Zeus.1.Gen removal guide

Malware Removal

The Trojan.Spy.Zeus.1.Gen is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Zeus.1.Gen virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates Zeus (Banking Trojan) mutexes

How to determine Trojan.Spy.Zeus.1.Gen?


File Info:

name: 9DDD0D16348ABA48AEA3.mlw
path: /opt/CAPEv2/storage/binaries/4dc17b03e1539802b83c78b94fcef1d14e5ef6e12defb121f7ed0a8d356c56bd
crc32: CFA74D22
md5: 8a0bc8e9d89ef7695d35e3f62b0673d8
sha1: 49bd025b6ed55889132bfdc7dba187981168341b
sha256: 4dc17b03e1539802b83c78b94fcef1d14e5ef6e12defb121f7ed0a8d356c56bd
sha512: 7162179a767ce0ca4a20713c8ec0e0059ac2aad7717c756549a005f9898ac02774e708c39e9bd09630aa8d6ce8dfe1a04c5311cc356e2f955b8d370b70133940
ssdeep: 12288:c/OLCSwElz2IV9ElXiJTf6jRysE0pvtL+cZibcYpW:cmLC5ElyWEZ+61ysE0pvUaAXpW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13CC42306171A6EB3D6BDCF79A02F3CBA113EE297CEC0193E816481D58D4CA5F758B605
sha3_384: 3829fe89d59be14197eea040430762372079b875fe72cad889a24c9890e68ed4782f5d9b06b59d04925b622586dcf76d
ep_bytes: eb00508bc483ec30c744240a00000000
timestamp: 2001-05-09 04:00:33

Version Info:

0: [No Data]

Trojan.Spy.Zeus.1.Gen also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.kZAq
Elasticmalicious (high confidence)
DrWebTrojan.Packed.511
MicroWorld-eScanTrojan.Spy.Zeus.1.Gen
FireEyeGeneric.mg.8a0bc8e9d89ef769
McAfeeGeneric PWS.cq
CylanceUnsafe
VIPRETrojan-Spy.Win32.Zbot.ga (v)
SangforTrojan.Win32.Zbot.KH
K7AntiVirusTrojan ( 000204251 )
AlibabaTrojanPSW:Win32/Kryptik.8fb2f735
K7GWTrojan ( 000204251 )
Cybereasonmalicious.9d89ef
BitDefenderThetaAI:Packer.3F3FF7DF1E
VirITTrojan.Win32.Packed.TR
CyrenW32/Zbot.J.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.N
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-2921
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Spy.Zeus.1.Gen
NANO-AntivirusTrojan.Win32.Zbot.unle
AvastWin32:Susn-G [Trj]
TencentWin32.Trojan.Generic.Dzjv
Ad-AwareTrojan.Spy.Zeus.1.Gen
SophosML/PE-A + ATK/Behav-321
ComodoMalware@#1o4lk42laos4b
ZillyaTrojan.Zbot.Win32.4778
TrendMicroTSPY_ZBOT.SMT
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
EmsisoftTrojan.Spy.Zeus.1.Gen (B)
IkarusTrojan-Spy.Win32.Zbot
GDataTrojan.Spy.Zeus.1.Gen
JiangminTrojanSpy.Zbot.bxo
WebrootW32.Malware.Gen
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Zbot
ArcabitTrojan.Spy.Zeus.1.Gen
ViRobotTrojan.Win32.A.Zbot.55296.L
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot.KH
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.IRCBot.C92440
Acronissuspicious
VBA32Trojan.Inject.01376
ALYacTrojan.Spy.Zeus.1.Gen
TrendMicro-HouseCallTSPY_ZBOT.SMT
RisingTrojan.Win32.Ntos.hl (CLOUD)
YandexTrojanSpy.ZBot.Gen!Pac.6
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.W!tr
AVGWin32:Susn-G [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Malware.1795128.susgen

How to remove Trojan.Spy.Zeus.1.Gen?

Trojan.Spy.Zeus.1.Gen removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment