Trojan

Trojan.Zbot.HEEP (file analysis)

Malware Removal

The Trojan.Zbot.HEEP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Zbot.HEEP virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Zbot.HEEP?


File Info:

crc32: 61046F50
md5: 06e17fa57817cb76fb6764d693af839e
name: 06E17FA57817CB76FB6764D693AF839E.mlw
sha1: 7131362b6ac939277fc47447962d4aa63d02875b
sha256: f645bc38628900b64c3fc6a0ba93d4ad01701b2d04d900c945762f86c5464a1f
sha512: b583718799ad8cdf6ced29243c434cb9542bdfec471ebbfc60834e1eac9351f2c6afc8f1d5398b3542c34ed01606aa5ab5fd863947e5fc05f7dc7dcf2748ecde
ssdeep: 3072:mPZmoSJ8NDX7CnOWOcCHZaExUUynFKOzYZLR9e6Gs121CE4f3TjLi9HwBC+bkom:mPsV8NyOWOrAsFgKxZLS6GsSCE4vvLP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Zbot.HEEP also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.8284
FireEyeGeneric.mg.06e17fa57817cb76
ALYacGen:Variant.Symmi.8284
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Zbot.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusPassword-Stealer ( 0040f1d21 )
BitDefenderGen:Variant.Symmi.8284
K7GWPassword-Stealer ( 0040f1d21 )
Cybereasonmalicious.57817c
BitDefenderThetaGen:NN.ZexaF.34590.lqW@aOmBUYni
CyrenW32/S-bdbb76fa!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAO
APEXMalicious
AvastWin32:Zbot-QGB [Trj]
KasperskyTrojan-Spy.Win32.Zbot.hjcf
AlibabaTrojanSpy:Win32/EncPk.4183cf65
NANO-AntivirusTrojan.Win32.Zbot.ehismx
RisingSpyware.Zbot!8.16B (CLOUD)
Ad-AwareGen:Variant.Symmi.8284
TACHYONTrojan-Spy/W32.ZBot.188416.BS
EmsisoftGen:Variant.Symmi.8284 (B)
ComodoMalware@#3uahsbplizfru
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.PWS.Panda.2005
ZillyaTrojan.Zbot.Win32.91957
McAfee-GW-EditionBehavesLike.Win32.ZBot.cc
SophosML/PE-A + Mal/EncPk-AIN
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.Troj.Zbot.hj.(kcloud)
MicrosoftPWS:Win32/Zbot!CI
ArcabitTrojan.Symmi.D205C
SUPERAntiSpywareTrojan.Agent/Gen-Festo
AhnLab-V3Trojan/Win32.Zbot.R46918
ZoneAlarmTrojan-Spy.Win32.Zbot.hjcf
GDataGen:Variant.Symmi.8284
CynetMalicious (score: 100)
Acronissuspicious
McAfeePWS-Zbot.ak
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
MalwarebytesTrojan.Zbot.HEEP
PandaTrj/Ransom.AB
TrendMicro-HouseCallHV_RANSOM_CG153EE7.RDXN
TencentWin32.Trojan-Spy.Zbot.cpt
YandexTrojan.GenAsa!I1vHH1tkqwo
IkarusTrojan-PWS.Win32.Zbot
MaxSecureTrojan.Malware.4995638.susgen
FortinetW32/Zbot.ASJ!tr
AVGWin32:Zbot-QGB [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_60% (D)
Qihoo-360Win32/Trojan.Zbot.HwcBZHsA

How to remove Trojan.Zbot.HEEP?

Trojan.Zbot.HEEP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment