Trojan

Trojan:Win32/Zbot!pz removal instruction

Malware Removal

The Trojan:Win32/Zbot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Zbot!pz?


File Info:

name: 1C55B833C130B663EBA7.mlw
path: /opt/CAPEv2/storage/binaries/3d16234f337abf5143a37a3aa91c0dc7cecebd15e9b822a96f11ffbc64c1b284
crc32: BBAA6798
md5: 1c55b833c130b663eba7eb1fe42b1872
sha1: 5ba56ee75f6cd2303b31bf92ec702d49c26bb483
sha256: 3d16234f337abf5143a37a3aa91c0dc7cecebd15e9b822a96f11ffbc64c1b284
sha512: c667c769ea8afe87bf60a2080543296ad6960728180e2dcd18c84f472deb20bd05caa66f0c921e54fe2289052a6fc86eb34839b5f961bfa7d61955c5b670a922
ssdeep: 3072:bEVkH4ATRtqdEY82XLT79O6W/0aC0VrETTrDFzH3Pd:1ptqqY82X3RObR4frxz/d
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AAD3AE427385EC87E0590A708853CBB94BE5FC70DBA147A337D46F5FACB62909932B16
sha3_384: 4665d4c4e4e81453b54d6a1862d350ddff29d5880aedc3a39d80a4fa63923b56f4c1d0228c5618d29dd164a0f019046d
ep_bytes: 00000000000000000000000000000000
timestamp: 2013-05-22 12:53:50

Version Info:

0: [No Data]

Trojan:Win32/Zbot!pz also known as:

BkavW32.AIDetectMalware
FireEyeGeneric.mg.1c55b833c130b663
SkyhighBehavesLike.Win32.Generic.ch
MalwarebytesGeneric.Malware.AI.DDS
SangforSuspicious.Win32.Save.a
K7AntiVirusRiskware ( 00584baa1 )
K7GWRiskware ( 00584baa1 )
Cybereasonmalicious.75f6cd
BaiduWin32.Trojan.Inject.ag
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Downloader-TJC [Trj]
F-SecureTrojan.TR/Patched.Ren.Gen
DrWebTrojan.PackedENT.24720
TrendMicroTROJ_GEN.R03BC0DAN24
SophosML/PE-A
JiangminTrojan/ShipUp.oi
AviraTR/Patched.Ren.Gen
Antiy-AVLTrojan[Dropper]/Win32.Gepys
Kingsoftmalware.kb.a.996
XcitiumTrojWare.Win32.Kryptik.BBQP@4yhysc
MicrosoftTrojan:Win32/Zbot!pz
GDataWin32.Trojan.Agent.IH9444
Cylanceunsafe
TrendMicro-HouseCallTROJ_GEN.R03BC0DAN24
RisingTrojan.Generic@AI.100 (RDML:jTLJMONZCUys1ysy/4/KXQ)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.94721794.susgen
FortinetW32/PossibleThreat
AVGWin32:Downloader-TJC [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Zbot!pz?

Trojan:Win32/Zbot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment