Trojan

Should I remove “TrojanPWS.Zbot”?

Malware Removal

The TrojanPWS.Zbot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanPWS.Zbot virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine TrojanPWS.Zbot?


File Info:

crc32: 00B5F5E8
md5: 166b855a41100b484d85feaf1e2dec52
name: 166B855A41100B484D85FEAF1E2DEC52.mlw
sha1: 7fb83948d26a833a6740ae91aadc55896516d58f
sha256: 20e832af9c8f28f7fd87c294d343e3fbd25a502f052b6897d373721569e175cd
sha512: 109a3009b4b782a1b1f847b887f9cfccda45778e4b87ca0316f2839b37baaa0aa99bba468be5f8a9a078540c68d688c46e6cb6a5b4e515be11442c52528a9977
ssdeep: 1536:QTH+9A/mpHiSQpKcI5mnnAEjuLCpgcl2YmO0hFZpLej7/Gvqi:OH+9Aup5QpK55gXuiXbwLejLGvF
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 2003 DaloozaSoft
InternalName: AU3_Spy
FileVersion: 1.0
CompanyName: DaloozaSoft
ProductName: AU3_Spy
ProductVersion: 1.0
FileDescription: AutoIt3 Window Info Spy
OriginalFilename: AU3_Spy.exe
Translation: 0x0409 0x04b0

TrojanPWS.Zbot also known as:

BkavW32.AIDetect.malware1
LionicVirus.Win32.Generic.n!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojanPWS.Zbot
CylanceUnsafe
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaVirus:Win32/Sality.63425ac1
Cybereasonmalicious.8d26a8
CyrenW32/Sality.E.gen!Eldorado
APEXMalicious
AvastWin32:Sality [Inf]
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
SophosMal/Generic-S
BitDefenderThetaGen:NN.ZexaF.34294.fu1@aeDTyWoi
VIPREVirus.Win32.Sality.atbh (v)
TrendMicroPE_SALITY.RL
McAfee-GW-EditionBehavesLike.Win32.Generic.mc
FireEyeGeneric.mg.166b855a41100b48
SentinelOneStatic AI – Malicious PE
JiangminWin32/HLLP.Kuku.poly2
MicrosoftPWS:Win32/Zbot!ml
Acronissuspicious
MAXmalware (ai score=95)
MalwarebytesMalware.Heuristic.1001
TrendMicro-HouseCallPE_SALITY.RL
RisingTrojan.Generic@ML.86 (RDML:3NzpR3hewF/25V0GTcLPbQ)
MaxSecureTrojan.Malware.300983.susgen
AVGWin32:Sality [Inf]
Paloaltogeneric.ml

How to remove TrojanPWS.Zbot?

TrojanPWS.Zbot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment