Trojan

How to remove “TrojanDropper:Win32/Zampol.A!bit”?

Malware Removal

The TrojanDropper:Win32/Zampol.A!bit is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDropper:Win32/Zampol.A!bit virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • A process created a hidden window
  • Drops a binary and executes it
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself

How to determine TrojanDropper:Win32/Zampol.A!bit?


File Info:

crc32: 272A40BC
md5: 12995a34c4915b32a3e6c3f50ccc460d
name: 12995A34C4915B32A3E6C3F50CCC460D.mlw
sha1: 439cc7c1d947d03c7cf941ed8a5bce8a1366240c
sha256: 00b9e38547c85e5944e829d5f327a722c6426ce94e62223ea5ac2aa89a47ea3f
sha512: 833b906f33acb43ec83d19ec9a6112bf669390a8c491c8a18a468f500f6c03479368789b18f2f8057bd0aa883e778df9da22f95095b4c87db995be5a7c2e65fd
ssdeep: 24576:0NR2zaQBt37/CZ0w1PeWnzqhqCC6+PEIIKffF4t3vtgoJo:xUsrC6aEmi3Wr
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.1.23.00
ProductName:
ProductVersion: 1.1.23.00
FileDescription:
OriginalFilename:
Translation: 0x0409 0x04b0

TrojanDropper:Win32/Zampol.A!bit also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.12995a34c4915b32
Qihoo-360Win32/Trojan.Dropper.c2e
McAfeeArtemis!12995A34C491
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforVirus_Suspicious.Win32.Sality.ae
K7GWTrojan ( 004f59331 )
K7AntiVirusTrojan ( 004f59331 )
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Gamarue-6699318-0
KasperskyTrojan-Dropper.Win32.AutoHK.h
NANO-AntivirusTrojan.Win32.AutoHK.feapmo
ViRobotTrojan.Win32.Agent.812032.I
RisingWorm.VBInjectEx!1.99E6 (CLASSIC)
ComodoApplication.Win32.BlkIC.IMG@1qp8gx
McAfee-GW-EditionBehavesLike.Win32.Dropper.th
SophosMal/Generic-S
IkarusTrojan.Cryptic
JiangminTrojan.Deshacop.iv
MAXmalware (ai score=96)
MicrosoftTrojanDropper:Win32/Zampol.A!bit
ZoneAlarmTrojan-Dropper.Win32.AutoHK.h
CynetMalicious (score: 100)
VBA32Trojan.Hotkeychick
ZonerTrojan.Win32.73221
ESET-NOD32Win32/TrojanDropper.AHK.AAO
TencentWin32.Trojan-dropper.Autohk.Dxdh
YandexTrojan.DR.AutoHK!BVqIDRiBBXQ
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_71%
FortinetW32/AHK.AAO!tr
AVGWin32:Malware-gen
Cybereasonmalicious.1d947d
Paloaltogeneric.ml

How to remove TrojanDropper:Win32/Zampol.A!bit?

TrojanDropper:Win32/Zampol.A!bit removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment