Trojan

Should I remove “Trojanpws.Zbot.7337”?

Malware Removal

The Trojanpws.Zbot.7337 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojanpws.Zbot.7337 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Enumerates running processes
  • Reads data out of its own binary image
  • Authenticode signature is invalid

How to determine Trojanpws.Zbot.7337?


File Info:

name: 565FD1984CD02E0E7FF3.mlw
path: /opt/CAPEv2/storage/binaries/398c6df0e1e9034bb65cc3ae2ce1169ba27fd52b80f72177678433db37b6a5a1
crc32: 5F4776E3
md5: 565fd1984cd02e0e7ff3d8fd70f1cd9c
sha1: c2a5bdf921ac99dffcf4625b5f94deccb70f37f9
sha256: 398c6df0e1e9034bb65cc3ae2ce1169ba27fd52b80f72177678433db37b6a5a1
sha512: f275536d862a686c386ca99bcc66a30586e01343a9d5eb1e3724a8a70c29c4e6f6be546fb81ba2b22caa9bcdd7710761288185d7dc9e264fa99b45b5fb05ef09
ssdeep: 6144:yiK9TBZVrJqyxrk5c+b5y4lWuAguYN9seAecRqSC2Jq:yiK9T5JxwzQ4lWuAg59qBRx9J
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13844BF52F68840F7EE9339B848EA771EAAFAA9053F1445E393D52E851C01191B63C3DF
sha3_384: 3a6e6da34630c235bdaa9657abcb6ec521a6b898e8d234bb1a036414cfb2519add8dd8870cd8a2db3f12b41136f2fc91
ep_bytes: 558bec51535633f633c946e820f5ffff
timestamp: 2014-10-03 12:58:31

Version Info:

0: [No Data]

Trojanpws.Zbot.7337 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.5676
MicroWorld-eScanGen:Variant.Ransom.GlobeImposter.28
FireEyeGeneric.mg.565fd1984cd02e0e
CAT-QuickHealTrojanpws.Zbot.7337
ALYacGen:Variant.Ransom.GlobeImposter.28
MalwarebytesMalware.AI.1559019732
ZillyaTrojan.Zbot.Win32.211532
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004aea031 )
K7GWTrojan ( 004aea031 )
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaGen:NN.ZexaF.34182.qqW@amF6LEh
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAU
TrendMicro-HouseCallCryp_Xin1
AvastSf:Injector-G [Trj]
ClamAVWin.Trojan.Zbot-64722
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.GlobeImposter.28
NANO-AntivirusTrojan.Win32.Panda.dgnnak
EmsisoftGen:Variant.Ransom.GlobeImposter.28 (B)
VIPRETrojan.Win32.Zbot.hzx (v)
TrendMicroCryp_Xin1
McAfee-GW-EditionBehavesLike.Win32.ZBot.dh
SophosML/PE-A + Mal/Behav-010
JiangminTrojan/Generic.biigi
AviraTR/Spy.Gen
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftPWS:Win32/Zbot!GOA
GDataGen:Variant.Ransom.GlobeImposter.28
CynetMalicious (score: 100)
AhnLab-V3Backdoor/Win32.Necurs.R121059
McAfeePWS-Zbot.gen.apr
MAXmalware (ai score=88)
VBA32BScope.Trojan.Zbot.6713
CylanceUnsafe
APEXMalicious
RisingMalware.Heuristic!ET#99% (RDMK:cmRtazp4dw+J3c6F22DCsR+eX24E)
YandexTrojan.GenAsa!wbBez+nKmyk
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.AAU!tr
AVGSf:Injector-G [Trj]
Cybereasonmalicious.84cd02
PandaTrj/Genetic.gen

How to remove Trojanpws.Zbot.7337?

Trojanpws.Zbot.7337 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment