Trojan

Trojan.ZbotCS.S28233656 removal guide

Malware Removal

The Trojan.ZbotCS.S28233656 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.ZbotCS.S28233656 virus can do?

  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Creates Zeus (Banking Trojan) mutexes

How to determine Trojan.ZbotCS.S28233656?


File Info:

name: 47F4F4596565360E9C8C.mlw
path: /opt/CAPEv2/storage/binaries/dd828acb245e906788c402c99cd9365b072ff4446763defa2439efc1ecdef25c
crc32: 80A03B68
md5: 47f4f4596565360e9c8c8177a0872eb2
sha1: 020b45154c1e32136deb30652ef6f8559e99766a
sha256: dd828acb245e906788c402c99cd9365b072ff4446763defa2439efc1ecdef25c
sha512: 05f4bd94e2f88a279a4c160ebe1ec93a62fbdeec3d3f960646b9efb284747efccfc11cb129c455c93ee72534d96b4f55d5b85107160c4b1a7df5b67617c493cf
ssdeep: 1536:NB8GgPtAELj0OK6QYKKpsTwbRXNRu1q9xzGC1tcXN:NB8GgP56KcowqyCEX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T163638F3172C1D2B1D4BA40329D5747A21DAA782A222B85EFCE61CD476953FC1EF3B346
sha3_384: b41d3d7fc36131d8446f0a661f98462916d5d44a388dbf607a770109df7b7d6b65291000a68526c649dcab600f7bd144
ep_bytes: 558bec81ec340400005356576a01e832
timestamp: 2009-06-25 21:14:51

Version Info:

0: [No Data]

Trojan.ZbotCS.S28233656 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.ts2a
MicroWorld-eScanDropped:Backdoor.Kollah.E
ClamAVWin.Trojan.Zbot-9951812-0
FireEyeGeneric.mg.47f4f4596565360e
CAT-QuickHealTrojan.ZbotCS.S28233656
ALYacDropped:Backdoor.Kollah.E
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2816753
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 004b91991 )
AlibabaTrojanSpy:Win32/Katusha.c0a452f3
K7GWSpyware ( 004b91991 )
Cybereasonmalicious.965653
VirITBackdoor.Win32.Agent.MPX
CyrenW32/Zbot.BS.gen!Eldorado
SymantecTrojan.Zbot
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Agent.PZ
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Proxy.Win32.Agent.ox
BitDefenderDropped:Backdoor.Kollah.E
NANO-AntivirusTrojan.Win32.Panda.vpjct
AvastWin32:Agent-LQE [Trj]
TencentBackdoor.Win32.Small.ha
Ad-AwareDropped:Backdoor.Kollah.E
ComodoTrojWare.Win32.TrojanSpy.Zbot.Gen@176vha
DrWebTrojan.PWS.Panda.264
VIPREDropped:Backdoor.Kollah.E
TrendMicroTROJ_ZBOT.SMUC
McAfee-GW-EditionBehavesLike.Win32.Trojan.km
EmsisoftDropped:Backdoor.Kollah.E (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.62Q8N6
JiangminTrojanSpy.Zbot.qkc
WebrootW32.Infostealer.Zeus
AviraTR/Rootkit.Gen
Antiy-AVLTrojan/Generic.ASMalwS.12F
MicrosoftTrojan:Win32/Zbot.DM!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Hupe.Gen
McAfeeGenericRXLW-CB!47F4F4596565
MAXmalware (ai score=83)
VBA32Trojan.Inject.01376
MalwarebytesTrojan.ProxyAgent
TrendMicro-HouseCallTROJ_ZBOT.SMUC
RisingSpyware.Agent!8.C6 (TFE:3:p1Wk2PBxqmJ)
YandexTrojan.GenAsa!0a2M2SLlL48
IkarusPacked.Win32.Katusha
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Agent.PZ!tr
BitDefenderThetaAI:Packer.8385B9B81F
AVGWin32:Agent-LQE [Trj]
PandaTrj/Genetic.gen

How to remove Trojan.ZbotCS.S28233656?

Trojan.ZbotCS.S28233656 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment