Trojan

Trojanspy.Zbot.16979 removal

Malware Removal

The Trojanspy.Zbot.16979 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojanspy.Zbot.16979 virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojanspy.Zbot.16979?


File Info:

name: 5DD712E1CA402EAAC531.mlw
path: /opt/CAPEv2/storage/binaries/afbb6c198ac342cba92c3fe65fb29accb4c31816941c2b7d8910424062d8373a
crc32: 4C46A8D0
md5: 5dd712e1ca402eaac5313bc8f27688d6
sha1: b4ab3006cd6f93e00c514e2b4d6ad617703a577e
sha256: afbb6c198ac342cba92c3fe65fb29accb4c31816941c2b7d8910424062d8373a
sha512: 622d414456e17e4ab6347b20d4d391cffd1820890399fbd02f188c1d7bf44a05499b6575c83ff1809e03486874db98270d79964a87f9f812b947b34ce381d173
ssdeep: 384:jkWozDI/RndLVSRk/zotqd1bQ6tL4H1ntqF3+tRMHTtqx1tH:OA/RwqIa+6BMgJ+LMHTtqZH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1899270759FDA0AFAE373D9BB40F6A2C25871F523A712C6DF81C8170A0947AC29CB4D54
sha3_384: 5541a22465d4b894a98081bfe37ee8c69566c338faf42d3b74ce8b613cc037233360322641874d6a76229fc1b39ae2bf
ep_bytes: 558bec6aff689844400068c034400064
timestamp: 2014-04-13 10:53:24

Version Info:

0: [No Data]

Trojanspy.Zbot.16979 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zbot.4!c
MicroWorld-eScanTrojan.GenericKDZ.94832
FireEyeTrojan.GenericKDZ.94832
CAT-QuickHealTrojanspy.Zbot.16979
ALYacTrojan.GenericKDZ.94832
MalwarebytesWaski.Trojan.Downloader.DDS
ZillyaTrojan.Zbot.Win32.155315
SangforSuspicious.Win32.Save.ins
K7AntiVirusTrojan-Downloader ( 0048f6391 )
AlibabaTrojanDownloader:Win32/Kryptik.3808e8c8
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.6cd6f9
BaiduWin32.Trojan-Downloader.Waski.a
VirITTrojan.Win32.Generic.CCCG
CyrenW32/S-781168a9!Eldorado
SymantecTrojan.Gen.2
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Downloader.Upatre-5744094-0
BitDefenderTrojan.GenericKDZ.94832
AvastWin32:Agent-AUID [Trj]
TencentTrojan-spy.Win32.Zbot.sipca
SophosMal/Zbot-QL
DrWebTrojan.DownLoad3.28161
VIPRETrojan.GenericKDZ.94832
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Downloader.lm
EmsisoftTrojan.GenericKDZ.94832 (B)
IkarusTrojan-Downloader.Win32.Waski
GDataWin32.Trojan.PSE1.1GFB86K
JiangminTrojanSpy.Zbot.ehyz
GoogleDetected
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.TrojanDownloader.Waski.BAEA@5p2zlv
ArcabitTrojan.Generic.D17270
ViRobotTrojan.Win32.Upatre.17808
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Downloader.R110839
Acronissuspicious
McAfeeDownloader-FSH!5DD712E1CA40
MAXmalware (ai score=85)
Cylanceunsafe
PandaTrj/Chgt.AD
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingDownloader.Waski!1.A489 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Agent.BAVS!tr
AVGWin32:Agent-AUID [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojanspy.Zbot.16979?

Trojanspy.Zbot.16979 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment