Trojan

How to remove “Trojan:Win32/Zbot!pz”?

Malware Removal

The Trojan:Win32/Zbot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Zbot!pz?


File Info:

name: DD4FEBBA114944B9466E.mlw
path: /opt/CAPEv2/storage/binaries/ce486c2619d3b9ea152e0e0622ee765d5c99bfe819512736e462e17bf2a55909
crc32: A1CF3EAB
md5: dd4febba114944b9466e0ebd5b7e3830
sha1: 4f1cfc7674b139a68d1ed84712f2e2809e53635d
sha256: ce486c2619d3b9ea152e0e0622ee765d5c99bfe819512736e462e17bf2a55909
sha512: a0ce5d69aec330642c4b51f223b6367b7c1efbed93a25e38c9f2207deba595d77e124e8683eb35b4baf98b1031337b50a6bb8418a470d452fc1a37969d39a248
ssdeep: 768:T9ECL7YPvPfhBLCY5RRHV5GuUt9H+HRCVpNEIxfqymnb2+lduiF8x4:gDGuUYCVphxfH2bPlHFm4
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1EF73E2386ED55A76E37BDEB6C6F651C6F975B0233C02980D40DA43840823F66EDE1A1E
sha3_384: 776fff995f7c8c2571abc3026627161b7eb7688b4fd025cbe6de81cf85082e913dc55bb96e9ab94be2a420b0d2fa6a5f
ep_bytes: 558d6c248881ecd408000053565733db
timestamp: 2014-01-27 12:19:18

Version Info:

0: [No Data]

Trojan:Win32/Zbot!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.69920831
ClamAVWin.Downloader.Upatre-10005716-0
CAT-QuickHealDownloader.Upatre.27298
SkyhighBehavesLike.Win32.Generic.lz
McAfeeGenericRXRZ-CQ!DD4FEBBA1149
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Waski.Win32.3906
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
BitDefenderTrojan.GenericKD.69920831
K7GWTrojan ( 0052964f1 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36680.eqZ@aeybIUdi
VirITTrojan.Win32.Upatre.BY
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
NANO-AntivirusTrojan.Win32.DownLoad3.frlegi
RisingSpyware.Zbot!8.16B (TFE:3:zHMEcYKLCaB)
SophosMal/Generic-S
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoad3.33424
VIPRETrojan.GenericKD.69920831
EmsisoftTrojan.GenericKD.69920831 (B)
IkarusTrojan-Downloader.Win32.Small
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanSpy.Zbot.fois
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLVirus/Win32.Expiro.imp
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Waski.BU@7nmtnf
ArcabitTrojan.Generic.D42AE83F
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
MicrosoftTrojan:Win32/Zbot!pz
VaristW32/Upatre.NG.gen!Eldorado
AhnLab-V3Trojan/Win.Upatre.R476095
Acronissuspicious
VBA32Trojan.Download
MAXmalware (ai score=84)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
TencentTrojan.Win32.Delf.wa
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/EncPk.ACO!tr
AVGWin32:Upatre-V [Trj]
Cybereasonmalicious.674b13
AvastWin32:Upatre-V [Trj]

How to remove Trojan:Win32/Zbot!pz?

Trojan:Win32/Zbot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment