Trojan

Should I remove “Trojan:Win32/Zbot!pz”?

Malware Removal

The Trojan:Win32/Zbot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot!pz virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zbot!pz?


File Info:

name: 3B6DCB71319845CD8BAA.mlw
path: /opt/CAPEv2/storage/binaries/b8cf335a32260b0308f998aa7939356602308587e77adafdf651cd43fddc7680
crc32: 723B2A55
md5: 3b6dcb71319845cd8baae53a9f1d532b
sha1: 0fdfc4df36d759abba38a251be55d65ddc8fc05f
sha256: b8cf335a32260b0308f998aa7939356602308587e77adafdf651cd43fddc7680
sha512: 49662b7eaf175c248e8d92e8b95a7b184ad922766d1dcbdde1a9f7c236b12e3f678726cd5d33aa08d85b1018383858cf972bfd2eb7eb87fa0595c46a617db8ae
ssdeep: 192:KzWum0y4CCVDQkRmpRyL7TodFed1bWviAgzwpHKbwpGJfvOhpPnJUOZO9xp1D9:K1m0y4DD4pUDH3ATZKbTRWmXzbx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12792EE3C6ED55677E37BDAB6C5F645CAF925B02339029C0E40CA43850C13F96AEE1A1E
sha3_384: bbf33126253ef5df47c528544a76066bad8249f73890fc8a79d3fab50933a99af01d43d4fe910edb322798257a8bfe8c
ep_bytes: 558d6c248881ecd408000053565733db
timestamp: 2014-01-27 12:19:18

Version Info:

0: [No Data]

Trojan:Win32/Zbot!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.70682294
CAT-QuickHealDownloader.Upatre.27298
SkyhighBehavesLike.Win32.Generic.mz
McAfeeDownloader-FML!3B6DCB713198
MalwarebytesGeneric.Malware.AI.DDS
VIPRETrojan.GenericKD.70682294
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan-Downloader ( 004941701 )
K7GWTrojan-Downloader ( 004941701 )
Cybereasonmalicious.f36d75
ArcabitTrojan.Generic.D43686B6
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.B
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Upatre-6997681-0
KasperskyHEUR:Trojan-Spy.Win32.Convagent.gen
BitDefenderTrojan.GenericKD.70682294
NANO-AntivirusTrojan.Win32.DownLoad3.frlegi
SUPERAntiSpywareTrojan.Agent/Gen-Upatre
AvastWin32:Upatre-V [Trj]
TencentTrojan-DL.Win32.Upatre.kah
EmsisoftTrojan.GenericKD.70682294 (B)
F-SecureHeuristic.HEUR/AGEN.1317165
DrWebTrojan.DownLoad3.33424
ZillyaDownloader.Waski.Win32.10024
SophosTroj/Agent-BCEQ
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojanSpy.Zbot.fois
VaristW32/S-654ac031!Eldorado
AviraHEUR/AGEN.1317165
Antiy-AVLTrojan/Win32.Waski.a
Kingsoftmalware.kb.a.999
XcitiumTrojWare.Win32.TrojanDownloader.Waski.BU@7nmtnf
MicrosoftTrojan:Win32/Zbot!pz
ZoneAlarmHEUR:Trojan-Spy.Win32.Convagent.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Malware/Win32.Generic.R98727
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.byY@aqL9O8ci
ALYacTrojan.GenericKD.70682294
VBA32Trojan.Download
Cylanceunsafe
PandaTrj/Genetic.gen
RisingSpyware.Zbot!8.16B (TFE:1:mhy8irZdGSI)
YandexTrojan.GenAsa!FYPjqD2mojE
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/EncPk.ACO!tr
AVGWin32:Upatre-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Zbot!pz?

Trojan:Win32/Zbot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment