Trojan

Trojan:Win32/Zombie!pz removal tips

Malware Removal

The Trojan:Win32/Zombie!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zombie!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zombie!pz?


File Info:

name: 27D0AD09C6AAF93EE3E8.mlw
path: /opt/CAPEv2/storage/binaries/0b72ae3c180da990d593549083ee08808e8d741b8a7b4ba7bfd2aa60143722d3
crc32: E4326598
md5: 27d0ad09c6aaf93ee3e8935c8f375d8a
sha1: 86144c119735e28d92530855a0f4e1cac7c77c89
sha256: 0b72ae3c180da990d593549083ee08808e8d741b8a7b4ba7bfd2aa60143722d3
sha512: 9adb3ccd33702f3bf120f190c0bc4bc478a76279879ab51b3fbdc15ba0cb5ed54fe2981081b7eafa032be06516f36ec684ee6164c05aab1264530a9b00f91176
ssdeep: 1536:6X0aX0wPNPJ060T7ZhA7pApaX0aX0wPNPJ060H:mlbPNPJ060xe7WpGlbPNPJ060H
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1668407179ED6B99BC363C2FF155B36982C69EAC7B352DEB42E4271764410F7068E2043
sha3_384: 7d075264c4f7d3b28073c12f32d88048c6686f1b26cc182e688bbb6994ab28b7d5fe52d1161707160fc9bed774a7f9cc
ep_bytes: 00000000000000000000136000000000
timestamp: 2014-04-29 18:27:40

Version Info:

0: [No Data]

Trojan:Win32/Zombie!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Cosmu.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.92970
FireEyeTrojan.GenericKDZ.92970
SkyhighBehavesLike.Win32.Generic.fz
ALYacTrojan.GenericKDZ.92970
VIPRETrojan.GenericKDZ.92970
SangforSuspicious.Win32.Save.ins
BitDefenderTrojan.GenericKDZ.92970
SymantecML.Attribute.HighConfidence
CynetMalicious (score: 100)
ClamAVWin.Malware.Generickdz-9938530-0
AlibabaTrojan:Win32/Zombie.3ac3bc2d
RisingVirus.Zombie!1.AB2A (CLASSIC)
SophosGeneric ML PUA (PUA)
ZillyaTrojan.Cosmu.Win32.152467
TrendMicroTROJ_GEN.R03BC0DKA23
EmsisoftTrojan.GenericKDZ.92970 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.92970
JiangminTrojan.Cosmu.atj
VaristW32/S-5a8d2096!Eldorado
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Tampering.27230
ArcabitTrojan.Generic.D16B2A
SUPERAntiSpywareTrojan.Agent/Gen-Crypt
MicrosoftTrojan:Win32/Zombie!pz
GoogleDetected
Acronissuspicious
VBA32Trojan.Cosmu
DeepInstinctMALICIOUS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BC0DKA23
IkarusTrojan.Win32.Zombie
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Shohdi.B!tr
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan:Win32/Zombie!pz?

Trojan:Win32/Zombie!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment