Spy Trojan

Trojan.Spy.Zeus.C (file analysis)

Malware Removal

The Trojan.Spy.Zeus.C is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Zeus.C virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Spy.Zeus.C?


File Info:

name: 6ED332F14CE4EAFE4E43.mlw
path: /opt/CAPEv2/storage/binaries/f3ddda2c0558d8f5480a04a86bdd3c01062342de16437dcb887e786aa1d79945
crc32: CAAB3E06
md5: 6ed332f14ce4eafe4e4381c5ef8f9989
sha1: e5538fca079f581fbc03a273430e1f57400bf396
sha256: f3ddda2c0558d8f5480a04a86bdd3c01062342de16437dcb887e786aa1d79945
sha512: 028ca32e400ca1cfbc0ce8017e56cb7dfef291b766dd20258ba2ce9c5b3f27ef12a4f636349ff82108c0b635dfd26ad8d6786f0a075e66ee5f8811602a9edf51
ssdeep: 1536:unSawBwA2l+kDNE2wV/F4gliD8aX4ztQYXKO9Iv7uHjsHB:uSawolb+4tzoRL9GdH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D193BF6D7AA07CF3DA5515726640363367FFEC3828296C93D350CF8A685A4C2A32D783
sha3_384: 4d5b1d6d43e65b15caf52bba322c30ac355d250676d3ba23117f1366a6c78eb8a0977b3fc6ab6a3f6319e85060e7bee1
ep_bytes: 820000003c0d747e3c0a747a84c07476
timestamp: 2008-01-24 16:28:07

Version Info:

0: [No Data]

Trojan.Spy.Zeus.C also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Spy.Zeus.C
FireEyeGeneric.mg.6ed332f14ce4eafe
CAT-QuickHealTrojanspy.Zbot.20200
McAfeeArtemis!6ED332F14CE4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00071a9a1 )
AlibabaTrojanSpy:Win32/XPACK.cab1aef8
K7GWTrojan ( 00071a9a1 )
Cybereasonmalicious.14ce4e
VirITTrojan.Win32.Panda.EK
CyrenW32/Zbot.AG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Spy.Zbot.JF
APEXMalicious
ClamAVWin.Spyware.Zbot-9841872-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Spy.Zeus.C
NANO-AntivirusTrojan.Win32.Panda.ifgd
AvastSf:Zbot-CQ [Trj]
TencentWin32.Trojan.Generic.Wtxr
Ad-AwareTrojan.Spy.Zeus.C
SophosMal/Generic-S
ComodoTrojWare.Win32.Spy.Zbot.ABW@1qnp50
DrWebTrojan.PWS.Panda.114
ZillyaTrojan.Zbot.Win32.11842
TrendMicroTSPY_ZBOT.SMRL
McAfee-GW-EditionBehavesLike.Win32.Generic.nm
EmsisoftTrojan.Spy.Zeus.C (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.Spy.Zeus.C
JiangminTrojanSpy.Zbot.vpr
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.D35BE
ArcabitTrojan.Spy.Zeus.C
MicrosoftPWS:Win32/Zbot.gen!R
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Zbot.Gen
BitDefenderThetaGen:NN.ZexaF.34212.fqX@aqF30!i
ALYacTrojan.Spy.Zeus.C
MAXmalware (ai score=100)
MalwarebytesMalware.AI.2217174620
TrendMicro-HouseCallTSPY_ZBOT.SMRL
RisingTrojan.Win32.Ntos.adi (CLOUD)
YandexTrojan.PWS.Zbot!2LAAUUI4SRI
eGambitGeneric.Malware
FortinetW32/Dx.FGO!tr
AVGSf:Zbot-CQ [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.7164915.susgen

How to remove Trojan.Spy.Zeus.C?

Trojan.Spy.Zeus.C removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment