Trojan

Trojan:Win32/Zbot!pz removal guide

Malware Removal

The Trojan:Win32/Zbot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Zbot!pz?


File Info:

name: 110950031BE31E82C002.mlw
path: /opt/CAPEv2/storage/binaries/1d3e85878533cf2f7d9f9a4a863f4e36aee10e94bdc90eda9339820a6a0dc4b3
crc32: 28532C50
md5: 110950031be31e82c002b438986e5e43
sha1: ad865b24deea2c0e340d8e4209a7f2ef56f93968
sha256: 1d3e85878533cf2f7d9f9a4a863f4e36aee10e94bdc90eda9339820a6a0dc4b3
sha512: 3b70e5350c20b0aa096ab0b8ec1a0085e07a03e9c54ac9e293c1bb3341be9b485e30e1bae4638d2b0c29a524e4e35061af90edff1c2d9dbd68f9d31ea3e69b33
ssdeep: 384:w2F9EYpD/L/DYPvPfhlbLCY5RR178K4iD5CrgL:T9ECL7YPvPfhBLCY5RRAiD+gL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18CE297786AD55A72E37BDEB58AF641C6F974B0233C02D90D40DA43850C23FA6DDB1A1E
sha3_384: 869ad15c1297ce92a8c6601f8642f0b58b4494f0450c528e9c9a357492db82ec17228f0c7b5756d3386f76e6f4b9f181
ep_bytes: 558d6c248881ecd408000053565733db
timestamp: 2014-01-27 12:19:18

Version Info:

0: [No Data]

Trojan:Win32/Zbot!pz also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Ppatre.Gen.1
CAT-QuickHealDownloader.Upatre.27298
SkyhighBehavesLike.Win32.Generic.nz
McAfeeGenericRXRZ-CQ!110950031BE3
Cylanceunsafe
VIPRETrojan.Ppatre.Gen.1
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan-Downloader ( 004941701 )
CrowdStrikewin/malicious_confidence_100% (D)
ArcabitTrojan.Ppatre.Gen.1
VirITTrojan.Win32.Upatre.BY
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.B
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Bavs-6804154-0
KasperskyHEUR:Trojan-Downloader.Win32.Upatre.gen
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.frlegi
AvastWin32:Upatre-V [Trj]
TencentTrojan.Win32.Delf.wa
EmsisoftTrojan.Ppatre.Gen.1 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoad3.33424
ZillyaTrojan.Waski.Win32.3906
SophosTroj/Upatre-YS
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojanSpy.Zbot.fois
VaristW32/Upatre.NG.gen!Eldorado
AviraTR/Crypt.XPACK.Gen
Antiy-AVLVirus/Win32.Expiro.imp
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Waski.BU@7nmtnf
MicrosoftTrojan:Win32/Zbot!pz
ZoneAlarmHEUR:Trojan-Downloader.Win32.Upatre.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
GoogleDetected
AhnLab-V3Trojan/Win.Upatre.R476095
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36680.bqY@aeybIUdi
ALYacTrojan.Ppatre.Gen.1
VBA32Trojan.Download
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
RisingSpyware.Zbot!8.16B (TFE:3:zHMEcYKLCaB)
YandexTrojan.Delf!x3yOfYLFlis
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/EncPk.ACO!tr
AVGWin32:Upatre-V [Trj]
Cybereasonmalicious.4deea2
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zbot!pz?

Trojan:Win32/Zbot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment