Trojan

Trojan:Win32/Zbot!pz removal instruction

Malware Removal

The Trojan:Win32/Zbot!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot!pz virus can do?

  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Zbot!pz?


File Info:

name: A9512E6C5B7F73463324.mlw
path: /opt/CAPEv2/storage/binaries/0b2297250d81d30f8c2054050a26c7754c5d2be14e1ca3e079320b82e4b3814f
crc32: 558FA56A
md5: a9512e6c5b7f734633249b77b781235e
sha1: 0e24692a5e390b2cfaa6e70bcd46775548ce67d1
sha256: 0b2297250d81d30f8c2054050a26c7754c5d2be14e1ca3e079320b82e4b3814f
sha512: 76852aedf9a357c0b8d064f7821fd23564a6322af0e50c304a6132a3ef527fb90a37020f90a00d7245c165b0a44f58ba647282dea463fe8d4bfbaf0f33a0811c
ssdeep: 768:T9ECL7YPvPfhBLCY5RRHV5GuUt9H+HRCVpNEIxfqymnb2+l0V5I8cssgBhw:gDGuUYCVphxfH2bPl0V5I8C
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18383D0386ED55A76E37BDEB6C6F651C6F935B0233C029C0D40DA43840863F66EDA1A1E
sha3_384: 47dfb1d099f04a038abac64144fe1be27448fa68bd53b32611715941b44335614aa4c6ec066aa06278d30c64f32918ac
ep_bytes: 558d6c248881ecd408000053565733db
timestamp: 2014-01-27 12:19:18

Version Info:

0: [No Data]

Trojan:Win32/Zbot!pz also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanTrojan.GenericKD.69920831
ClamAVWin.Downloader.Upatre-10005716-0
CAT-QuickHealDownloader.Upatre.27298
SkyhighBehavesLike.Win32.Generic.lz
McAfeeGenericRXRZ-CQ!A9512E6C5B7F
Cylanceunsafe
VIPRETrojan.GenericKD.69920831
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.a5e390
VirITTrojan.Win32.Upatre.BY
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Bublik.pef
BitDefenderTrojan.GenericKD.69920831
NANO-AntivirusTrojan.Win32.DownLoad3.frlegi
AvastWin32:Upatre-V [Trj]
TencentTrojan.Win32.Delf.wa
TACHYONTrojan/W32.Bublik.81824
EmsisoftTrojan.GenericKD.69920831 (B)
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.DownLoad3.33424
ZillyaTrojan.Waski.Win32.3906
TrendMicroTROJ_GEN.R03BC0DB224
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.a9512e6c5b7f7346
SophosML/PE-A
IkarusTrojan-Spy.Zbot
GDataWin32.Trojan-Downloader.Upatre.BJ
JiangminTrojanSpy.Zbot.fois
GoogleDetected
AviraTR/Crypt.XPACK.Gen
Antiy-AVLVirus/Win32.Expiro.imp
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.TrojanDownloader.Waski.BU@7nmtnf
ArcabitTrojan.Generic.D42AE83F
ZoneAlarmHEUR:Trojan.Win32.Bublik.pef
MicrosoftTrojan:Win32/Zbot!pz
VaristW32/Upatre.NG.gen!Eldorado
AhnLab-V3Trojan/Win.Upatre.R476095
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.eqZ@aeybIUdi
ALYacTrojan.GenericKD.69920831
MAXmalware (ai score=88)
VBA32Trojan.Download
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R03BC0DB224
RisingSpyware.Zbot!8.16B (TFE:3:zHMEcYKLCaB)
YandexTrojan.Delf!x3yOfYLFlis
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/EncPk.ACO!tr
AVGWin32:Upatre-V [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Zbot!pz?

Trojan:Win32/Zbot!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment