Trojan

Trojan:Win32/Zbot!pz (file analysis)

Malware Removal

The Trojan:Win32/Zbot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zbot!pz?


File Info:

name: FCBD15F209C9D046122C.mlw
path: /opt/CAPEv2/storage/binaries/585422f8867a3405719d8ea1305f741ad012dbd11a96d4e942427a9c6f6e795d
crc32: 49BAED92
md5: fcbd15f209c9d046122cdf51a9be07ea
sha1: 04dbc76ad4d061891437af434fd0edd59ac9f93a
sha256: 585422f8867a3405719d8ea1305f741ad012dbd11a96d4e942427a9c6f6e795d
sha512: 74fbcc2be77469f1a0de4008fd54b8331edc4518a6340f59d02987389e7590f033fb2f2c3527dcbbddc9dc6d55371f6909d10b3b7f5df1ec64421009cf4a0bc3
ssdeep: 384:iXET14X4f0y4liVlhox+a8lvDIU+mMaV0tOLuYClcF90p+N2uKoY:HT1g40QlgglvDIUPV04TzqpyfKn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T181F2E1386ED95676E37BCEB6C5F651C6F935B0233C02980D40DA43850C63FA6EDA1A1E
sha3_384: 34032e1afcad86409601ca628dee65d5692da533ba4a158a190d387191384f5daee322035905682af8d5981aa0f9a427
ep_bytes: 558d6c248881ecd808000053565733db
timestamp: 2014-05-07 11:58:56

Version Info:

0: [No Data]

Trojan:Win32/Zbot!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Ppatre.Gen.1
ClamAVWin.Malware.Upatre-6997924-0
CAT-QuickHealTrojan.Mauvaise.SL1
SkyhighBehavesLike.Win32.Generic.nz
McAfeeDownloader-FBVZ!FCBD15F209C9
MalwarebytesGeneric.Malware.AI.DDS
ZillyaDownloader.Waski.Win32.8133
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 004941701 )
K7GWTrojan-Downloader ( 004941701 )
Cybereasonmalicious.ad4d06
SymantecDownloader
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Waski.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Convagent.gen
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.Zbot.euxmcg
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Upatre-V [Trj]
TencentTrojan-DL.Win32.Upatre.kw
SophosTroj/Upatre-XO
F-SecureHeuristic.HEUR/AGEN.1317165
DrWebTrojan.DownLoad4.14155
VIPRETrojan.Ppatre.Gen.1
TrendMicroTROJ_GEN.R03BC0DBT24
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.fcbd15f209c9d046
EmsisoftTrojan.Ppatre.Gen.1 (B)
IkarusTrojan-Downloader.Win32.Waski
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanSpy.Zbot.fkxb
GoogleDetected
AviraHEUR/AGEN.1317165
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Waski.BU@7nmtnf
ArcabitTrojan.Ppatre.Gen.1
ViRobotTrojan.Win32.Downloader.5632.LY
ZoneAlarmHEUR:Trojan.Win32.Convagent.gen
MicrosoftTrojan:Win32/Zbot!pz
VaristW32/Risk.MOKC-5546
AhnLab-V3Trojan/Win32.Upatre.C369973
Acronissuspicious
VBA32TrojanSpy.Zbot
ALYacTrojan.Ppatre.Gen.1
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DBT24
RisingDownloader.Waski!1.A489 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/EncPk.ACO!tr
BitDefenderThetaGen:NN.ZexaF.36744.cyY@aGXohAki
AVGWin32:Upatre-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Zbot!pz?

Trojan:Win32/Zbot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment