Trojan

Trojan.ZbotCS.S27332935 removal instruction

Malware Removal

The Trojan.ZbotCS.S27332935 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ZbotCS.S27332935 virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.ZbotCS.S27332935?


File Info:

name: 9554A3569B5E15004218.mlw
path: /opt/CAPEv2/storage/binaries/3f5f09b63de46daa36a0f1949deed6ef9128d362a24719cdfa27169d2d202dab
crc32: 4D3439C4
md5: 9554a3569b5e1500421894ff1c7623e1
sha1: 5c1c35b3628bb09c8f25d87d4a55dce5a6d054fd
sha256: 3f5f09b63de46daa36a0f1949deed6ef9128d362a24719cdfa27169d2d202dab
sha512: 12be377860ba28c5db758f318ee71ca4d79421c21484410bf464cd87df92a723c31ee97e5658948cf738d556fc414e6d626645d33514178ef657071175bc1254
ssdeep: 384:HxTsQWRIcS1forPBnDDKPSXZU6p87RVhflYytm7jGhN:hshRS1fcPxDDKP8ZU6poRVhflYwN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C51348386AE95672E3BBCE75C9F651C6F974B4233D02D80D40DA43840C63F66EDA1A1E
sha3_384: 12da9e6d40925003c384b4820bc9047666d60f4964a3403760b0f3be8b3b73bd80ef8d9b23ab90235d4b5127caecdc34
ep_bytes: 558bec81ec3808000053565733db53ff
timestamp: 2013-12-02 15:44:08

Version Info:

0: [No Data]

Trojan.ZbotCS.S27332935 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanTrojan.Ppatre.Gen.1
CAT-QuickHealTrojan.ZbotCS.S27332935
McAfeeGenericRXJJ-UC!9554A3569B5E
CylanceUnsafe
SangforTrojan.Win32.Save.a
Cybereasonmalicious.69b5e1
BitDefenderThetaAI:Packer.651408CB20
CyrenW32/S-94becf64!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Malware.Upatre-7004553-0
KasperskyHEUR:Trojan-Spy.Win32.Zbot.vho
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad.cqofta
AvastWin32:Waski-A [Trj]
TencentTrojan-Downloader.Win32.Waski.16000151
Ad-AwareTrojan.Ppatre.Gen.1
EmsisoftTrojan.Ppatre.Gen.1 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.AQ@7t0jau
ZillyaDownloader.SmallGen.Win32.2
TrendMicroTROJ_UPATRE.SMAZ
McAfee-GW-EditionBehavesLike.Win32.Generic.pz
FireEyeGeneric.mg.9554a3569b5e1500
SophosML/PE-A + Mal/EncPk-ACO
IkarusTrojan-Downloader.Win32.Waski
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanDownloader.Upatre.aerk
AviraTR/Dldr.Waski.gzsbj
MAXmalware (ai score=82)
Antiy-AVLTrojan/Generic.ASMalwS.698385
ArcabitTrojan.Ppatre.Gen.1
MicrosoftTrojan:Win32/Waski.A!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R282018
VBA32Trojan.Agent
ALYacTrojan.Ppatre.Gen.1
MalwarebytesUpatre.Trojan.Downloader.DDS
TrendMicro-HouseCallTROJ_UPATRE.SMAZ
RisingSpyware.Zbot!8.16B (RDMK:cmRtazoFg2qcUDSQV+k)
YandexTrojan.GenAsa!Iaz+na8i5c0
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Waski-A [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.ZbotCS.S27332935?

Trojan.ZbotCS.S27332935 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment