Trojan

How to remove “Trojan:Win32/Zbot!pz”?

Malware Removal

The Trojan:Win32/Zbot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot!pz virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Zbot!pz?


File Info:

name: 64FC3F76F86BFD575789.mlw
path: /opt/CAPEv2/storage/binaries/412b2c0be42ef51091252a9ce1b145af5ea4df784f68e5abbf23b4bcf30dc4bf
crc32: D31B3C6D
md5: 64fc3f76f86bfd5757898f1387995177
sha1: 9694f3af3333b61b780e07d495238a95531e756a
sha256: 412b2c0be42ef51091252a9ce1b145af5ea4df784f68e5abbf23b4bcf30dc4bf
sha512: f8ce8c1a8902aa3a7ecc0d8161cf7b380438e5ead00895e688383dbd92e7df7576bf35c704bc0f3571068d75c0f23ca1acef672ea9acd1d9d355f83f0570c3b3
ssdeep: 3072:QulagTsDAJJRjOcXRRdZLnQDeJcLFZhh2D+0caj3kyRACd:QuljJJ1RDYzn9ozd
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17484BD97D50F0B15EC6F9EBB8299D038149C67694B430F9FC6E4CE89E623CB44729A70
sha3_384: 7905a30ae04c98dd251351edd737e32fe906a54572fe102b8f9f9097347258053cfa678a6958b4162e556eb9f689a9f5
ep_bytes: 558bec51c745fc6dd30000c745fc6dd3
timestamp: 2013-04-03 18:11:11

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Редактор личных символов
Translation: 0x0419 0x04b0

Trojan:Win32/Zbot!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.95227
CAT-QuickHealTrojanPWS.Zbot.Y
SkyhighBehavesLike.Win32.PWSZbot.ft
McAfeePWS-Zbot.gen.xs
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.Kryptik.Win32.387197
SangforRansom.Win32.Cerber_23.se
K7AntiVirusTrojan ( 005a7b881 )
K7GWTrojan ( 005a7b881 )
Cybereasonmalicious.f3333b
ArcabitTrojan.Generic.D173FB
BaiduWin32.Trojan.Agent.eq
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AXZK
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Shipup-10003855-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.95227
NANO-AntivirusTrojan.Win32.ShipUp.bqoeah
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
AvastWin32:Gepys-E [Trj]
TencentTrojan.Win32.Kryptik.16000652
EmsisoftTrojan.GenericKDZ.95227 (B)
F-SecureTrojan.TR/Obfuscate.adj
DrWebTrojan.Redirect.140
VIPRETrojan.GenericKDZ.95227
TrendMicroTROJ_KRYPTK.SML3
SophosTroj/Gyepis-A
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Generic.avokq
VaristW32/Zbot.JC.gen!Eldorado
AviraTR/Obfuscate.adj
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Unknown
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
MicrosoftTrojan:Win32/Zbot!pz
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan.PSE.1QA13WY
GoogleDetected
AhnLab-V3Dropper/Win32.Injector.R59840
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.wS1@aSdpjUnc
VBA32BScope.Trojan.Redirect
Cylanceunsafe
PandaTrj/Hexas.HEU
TrendMicro-HouseCallTROJ_KRYPTK.SML3
RisingTrojan.Kryptik!1.AB8B (CLASSIC)
YandexTrojan.GenAsa!Dn0ebPHwSik
IkarusVirus.Win32.Injector
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.AXXI!tr
AVGWin32:Gepys-E [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Zbot!pz?

Trojan:Win32/Zbot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment