Trojan

TrojanPWS.AutoIt.Zbot.S malicious file

Malware Removal

The TrojanPWS.AutoIt.Zbot.S is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanPWS.AutoIt.Zbot.S virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to execute a powershell command with suspicious parameter/s
  • Reads data out of its own binary image
  • A process created a hidden window
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Anomalous binary characteristics

Related domains:

lapoire1.hopto.org

How to determine TrojanPWS.AutoIt.Zbot.S?


File Info:

crc32: 976350AE
md5: aaf9e9ecb72c1cd5f0d2bfdcd1803b41
name: Reve.jpg
sha1: 303b109e4ab7d29086cab2fa151954d1e819d005
sha256: 8d58467162a034fdab25c3d1a5b5ea9e879f6baf973300d248777f7d926c3718
sha512: 167b58b6ad9e1452af129a395279030cbd6408ec20e48468875ebb8cb55e296dbd2fa4a63661d812cface6f8e05e5f3e64d162605c058bc393dd3e760b8bb767
ssdeep: 24576:CAHnh+eWsN3skA4RV1Hom2KXMmHa3BL5:Fh+ZkldoPK8Ya3j
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

TrojanPWS.AutoIt.Zbot.S also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanTrojan.GenericKD.41501192
FireEyeTrojan.GenericKD.41501192
CAT-QuickHealTrojanPWS.AutoIt.Zbot.S
ALYacTrojan.GenericKD.41501192
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabHacktool.Win32.Gamehack.3!e
SangforMalware
BitDefenderTrojan.GenericKD.41501192
Cybereasonmalicious.e4ab7d
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34098.2uW@a04IpAbi
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R002C0PB320
AvastWin32:Malware-gen
GDataTrojan.GenericKD.41501192
KasperskyTrojan.MSIL.Revenge.dbc
AlibabaTrojan:MSIL/Revenge.482ae600
NANO-AntivirusTrojan.Win32.Revenge.ftwdua
APEXMalicious
TencentMsil.Trojan.Revenge.Lqyr
Ad-AwareTrojan.GenericKD.41501192
SophosMal/Generic-S
ComodoMalware@#1gcwdsilex0eu
F-SecureHeuristic.HEUR/AGEN.1038819
DrWebTrojan.DownLoader29.77
TrendMicroTROJ_GEN.R002C0PB320
McAfee-GW-EditionBehavesLike.Win32.Downloader.ch
EmsisoftTrojan.GenericKD.41501192 (B)
SentinelOneDFI – Suspicious PE
eGambitUnsafe.AI_Score_99%
AviraHEUR/AGEN.1038819
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D2794208
ZoneAlarmTrojan.MSIL.Revenge.dbc
MicrosoftTrojan:Win32/Tiggre!rfn
AhnLab-V3Malware/Win32.Generic.C3371373
McAfeeRDN/Generic.fgo
TACHYONTrojan/W32.Revenge.894464
VBA32Trojan.MSIL.Revenge
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.Autoit.DSJ
RisingTrojan.Generic@ML.96 (RDML:K1dm0+f+7RbYG0TuNPelqg)
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.1728101.susgen
FortinetW32/Autoit.DSJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Win32/Trojan.a07

How to remove TrojanPWS.AutoIt.Zbot.S?

TrojanPWS.AutoIt.Zbot.S removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment