Trojan

What is “Trojan:Win32/Zbot!atmnm”?

Malware Removal

The Trojan:Win32/Zbot!atmnm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot!atmnm virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid
  • Creates Zeus (Banking Trojan) mutexes

How to determine Trojan:Win32/Zbot!atmnm?


File Info:

name: EC967E15C20532F1B6A0.mlw
path: /opt/CAPEv2/storage/binaries/707782e1098f7bf18c7bc478477dc7461f9657911becdf6b26d99b7182071796
crc32: C76193D2
md5: ec967e15c20532f1b6a02d79f511cf5b
sha1: 490cdcabcf76e5291f669797b6822d614f4b91d9
sha256: 707782e1098f7bf18c7bc478477dc7461f9657911becdf6b26d99b7182071796
sha512: adda4f2660ec6c818b1cb603983e6d6414aed3ce0643abaa490e7ea08c5e6d08e1b806f6fd5f335cdbdcb0745862c05830b4b89806f38c256d90483ced20c9ab
ssdeep: 3072:mB+U/pvyvJjtKeXea6109jEgTMA3VQUhHw18n5HC:mBxyvL6e97MUxtC
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C0D3BF22F3E2817DF4B312321A714663DEFB7D21293A952D56D20A6D0F326B1D53A393
sha3_384: 397f3316fa741d5766d1c09d5d1f35bde20c0def015eaf44cec0f800580b280104ba8fc74bc7cb77af787bc77a8e352d
ep_bytes: 558bec81ec3804000053565733ff4757
timestamp: 2007-05-30 19:33:01

Version Info:

0: [No Data]

Trojan:Win32/Zbot!atmnm also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanDropped:Generic.Malware.SFM6g.AB5CA48C
ClamAVWin.Malware.Zbot-9951822-0
CAT-QuickHealTrojanpws.Zbot.29195
ALYacDropped:Generic.Malware.SFM6g.AB5CA48C
MalwarebytesMalware.AI.3826158925
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0053eecd1 )
K7GWSpyware ( 0053eecd1 )
Cybereasonmalicious.5c2053
VirITTrojan.Win32.Generic.FZC
CyrenW32/Zbot.BS.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Spy.Agent.PZ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.wqmk
BitDefenderDropped:Generic.Malware.SFM6g.AB5CA48C
NANO-AntivirusTrojan.Win32.Agent.mram
SUPERAntiSpywareTrojan.Agent/Gen-Zusy
AvastWin32:BankerX-gen [Trj]
TencentTrojan-Spy.Win32.Zbot.xa
EmsisoftDropped:Generic.Malware.SFM6g.AB5CA48C (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen
DrWebWin32.HLLM.Detail
VIPREDropped:Generic.Malware.SFM6g.AB5CA48C
TrendMicroTROJ_ZBOT.SMUC
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ch
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.ec967e15c20532f1
SophosTroj/Zbot-PQK
IkarusTrojan-Spy.Win32.Zbot
GDataWin32.Trojan.PSE.54PMYO
JiangminHTool.Agent.ky
AviraTR/Crypt.ZPACK.Gen
Antiy-AVLTrojan[Spy]/Win32.Zbot
XcitiumTrojWare.Win32.TrojanSpy.Zbot.Gen@1gsefs
ArcabitGeneric.Malware.SFM6g.AB5CA48C
ZoneAlarmTrojan-Spy.Win32.Zbot.wqmk
MicrosoftTrojan:Win32/Zbot!atmnm
GoogleDetected
AhnLab-V3Win-Trojan/Hupe.Gen
McAfeeGenericRXAY-YJ!EC967E15C205
MAXmalware (ai score=85)
VBA32Trojan.Inject.01376
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.22153
TrendMicro-HouseCallTROJ_ZBOT.SMUC
RisingTrojan.Win32.Wsnpoem.cl (CLASSIC)
YandexTrojan.GenAsa!qLYLJyebXzo
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.PZ!tr.spy
BitDefenderThetaAI:Packer.7289C79A1E
AVGWin32:BankerX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Zbot!atmnm?

Trojan:Win32/Zbot!atmnm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment