Trojan

How to remove “Trojan.Zbot.264”?

Malware Removal

The Trojan.Zbot.264 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Zbot.264 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Zbot.264?


File Info:

name: 7CD48660B6FCE928EAA3.mlw
path: /opt/CAPEv2/storage/binaries/f1c259dcc2ea7c414018547cfee33abc264c11dc406df1fabba2aea029aaf629
crc32: 2FD0E4CA
md5: 7cd48660b6fce928eaa34caf222c52cb
sha1: 0a315d0a69d7210d6c0892c1f3812f5b49fc08cb
sha256: f1c259dcc2ea7c414018547cfee33abc264c11dc406df1fabba2aea029aaf629
sha512: b5232d234942bd6a019a052e5d72d6d13e0ef25b20370210ee49da66469c197e0eb97dfd6764d66ddcf5733ce55e4693bb29a95ffb62eb6ba49cd87d81ad57be
ssdeep: 24576:lGJKIdvl5kHHV0SJjDV0q+Rdzr9nIjMMf2n8H+tQZMJpYfZkfKf2A1:Gvl5kHHV0SJjDV0Hxr9naMMJe+i7qZk8
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C025392B23F6B0C3D8B289B1376AD1E2A5D4B83D5911E503F7826F1582B0659D762F33
sha3_384: cac700a5876ec7554a861782d25d5733a155c10ec1479e6c537d406d4d56f1bd969bcdece129d934dda30ea9cbcce41c
ep_bytes: 6870bc4000e8f0ffffff000000000000
timestamp: 2010-01-16 07:56:39

Version Info:

Translation: 0x0409 0x04b0
Comments: RQhlnfESL
CompanyName: tzHwclmkpMSa
FileDescription: vSNrt
LegalCopyright: jgCYwplwNdy
LegalTrademarks: egAdivs
ProductName: oNN
FileVersion: 3.37.0095
ProductVersion: 3.37.0095
InternalName: zdlknfaegae
OriginalFilename: zdlknfaegae.exe

Trojan.Zbot.264 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Buzus.4!c
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Zbot.264
ClamAVWin.Trojan.Buzus-7481
FireEyeGeneric.mg.7cd48660b6fce928
CAT-QuickHealTrojan.VB.XR4
McAfeePWS-Zbot.gen.ho
CylanceUnsafe
VIPRETrojan.Zbot.264
SangforSuspicious.Win32.Save.vb
K7AntiVirusNetWorm ( 700000151 )
AlibabaTrojanPSW:Win32/Buzus.e0d4b5b6
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.0b6fce
ArcabitTrojan.Zbot.264
CyrenW32/VB.AS.gen!Eldorado
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Injector.ATZ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Buzus.czrx
BitDefenderTrojan.Zbot.264
NANO-AntivirusTrojan.Win32.Buzus.ccqxr
AvastWin32:Dropper-CUX [Drp]
TencentWin32.Trojan.Buzus.Jcnw
Ad-AwareTrojan.Zbot.264
SophosMal/Generic-R + Mal/VB-LJ
ComodoTrojWare.Win32.Buzus.czoc@24y1l5
DrWebWin32.HLLW.Autoruner.10356
ZillyaTrojan.Buzus.Win32.33884
TrendMicroTROJ_BUZUS.BGE
McAfee-GW-EditionPWS-Zbot.gen.ho
EmsisoftTrojan.Zbot.264 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Buzus.blej
WebrootW32.Trojan.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.AA
KingsoftWin32.Troj.Buzus.cz.(kcloud)
MicrosoftPWS:Win32/Zbot
GDataTrojan.Zbot.264
GoogleDetected
AhnLab-V3Trojan/Win32.Buzus.C326613
Acronissuspicious
BitDefenderThetaGen:NN.ZevbaF.34682.7m3@aascPcji
ALYacTrojan.Zbot.264
MAXmalware (ai score=99)
VBA32Trojan.VBO.092
MalwarebytesMalware.AI.3444026052
TrendMicro-HouseCallTROJ_BUZUS.BGE
RisingMalware.Zbot!8.E95E (TFE:3:yMhH4zbc7M)
YandexTrojan.GenAsa!aXbBCbMLv3U
IkarusTrojan.Win32.Injector
FortinetW32/Refroso.DZP!tr
AVGWin32:Dropper-CUX [Drp]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Zbot.264?

Trojan.Zbot.264 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment