Spy Trojan

TrojanSpy:MSIL/Tzeebot removal instruction

Malware Removal

The TrojanSpy:MSIL/Tzeebot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:MSIL/Tzeebot virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid

How to determine TrojanSpy:MSIL/Tzeebot?


File Info:

name: D84C3D678F269A0C6BEB.mlw
path: /opt/CAPEv2/storage/binaries/d045ea925cf461da5c58cc2af8a0f96ec7c961ea62ffcf1de0b04abf9b0fa8ac
crc32: 06C2370A
md5: d84c3d678f269a0c6beb22ed266efac0
sha1: bc2a7e71c27ea520d3567ecce16d459436c46d63
sha256: d045ea925cf461da5c58cc2af8a0f96ec7c961ea62ffcf1de0b04abf9b0fa8ac
sha512: a2fb3e8ad4d20574082c9262449bf484ac1755e96fd9e318830f9a85a6a1d10c705bba9a153a449351468491124bee0e0813153c6467004d184a9a307b29ff6a
ssdeep: 384:2GJmIpvNpN5ivPHO82V8mNtHDhMT93WpjfDDgrlMY2xHZ3BWoDW:2GJmIRNj4HsHiT9GpbKp2ZlN
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FAB2080933E8C23AEAAE4B3A6D724A504671F2479431DB8E4CDA51D90E737858E01FE7
sha3_384: 7852a028197a6c118cad247642f373392278c6fb6ba7291a7671cb1fd748d713aa1d7b744594327f597aed5a1eecab8a
ep_bytes: ff250020400000000000000000000000
timestamp: 2014-08-26 19:08:32

Version Info:

Translation: 0x0000 0x04b0
CompanyName: Microsoft
FileDescription: Windows Explorer
FileVersion: 1.1.0.121
InternalName: netscp.exe
LegalCopyright: Copyright © Microsft 2008
OriginalFilename: netscp.exe
ProductName: Microsoft
ProductVersion: 1.1.0.121
Assembly Version: 1.1.0.1

TrojanSpy:MSIL/Tzeebot also known as:

LionicTrojan.MSIL.Tnzbt.m!c
MicroWorld-eScanIL:Trojan.MSILZilla.9494
ClamAVWin.Trojan.Agent-1304372
FireEyeIL:Trojan.MSILZilla.9494
ALYacMisc.HackTool.NetCrawler.Zhoupin
CylanceUnsafe
ZillyaBackdoor.Tnzbt.Win32.6
SangforTrojan.MSIL.Tzeebot.mt
K7AntiVirusTrojan ( 700000121 )
BitDefenderIL:Trojan.MSILZilla.9494
K7GWTrojan ( 700000121 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Generic.BBDC
CyrenW32/MSIL_TZBot.B.gen!Eldorado
SymantecTrojan.Tzeebot
Elasticmalicious (high confidence)
ESET-NOD32a variant of MSIL/Spy.TzeeBot.C
APEXMalicious
AvastMSIL:Agent-CIU [Trj]
CynetMalicious (score: 99)
KasperskyBackdoor.MSIL.Tnzbt.t
AlibabaBackdoor:MSIL/Tnzbt.b79fc273
NANO-AntivirusTrojan.Win32.Tnzbt.dvslie
ViRobotTrojan.Win32.S.Agent.24576.AXI
RisingBackdoor.Tnzbt!8.80DD (CLOUD)
Ad-AwareIL:Trojan.MSILZilla.9494
EmsisoftIL:Trojan.MSILZilla.9494 (B)
ComodoMalware@#3fs686fqa0lsj
DrWebTrojan.KillFiles.17492
VIPREIL:Trojan.MSILZilla.9494
TrendMicroTSPY_TZEEBOT.AA
McAfee-GW-EditionTrojan-Cleaver
SophosMal/Generic-R + Troj/MSIL-BBV
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.MSIL.dfee
WebrootW32.Trojan.Gen
AviraTR/Agent.24576.1205
Antiy-AVLTrojan/Generic.ASMalwS.3F60
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojanSpy:MSIL/Tzeebot
GDataIL:Trojan.MSILZilla.9494
GoogleDetected
AhnLab-V3Trojan/Win32.FakeMS.R127229
McAfeeTrojan-Cleaver
TACHYONBackdoor/W32.DN-Tnzbt.24576
MalwarebytesMalware.AI.60269637
PandaTrj/GdSda.A
TrendMicro-HouseCallTSPY_TZEEBOT.AA
TencentWin32.Trojan.Agent.Wqwq
YandexBackdoor.Tnzbt!412xdyA2+bs
MAXmalware (ai score=100)
FortinetMSIL/TzeeBot.C!tr.spy
BitDefenderThetaGen:NN.ZemsilF.34592.bm0@aOwHUm
AVGMSIL:Agent-CIU [Trj]
Cybereasonmalicious.78f269
Paloaltogeneric.ml

How to remove TrojanSpy:MSIL/Tzeebot?

TrojanSpy:MSIL/Tzeebot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment