Trojan

About “Trojan:Win32/Zombie!pz” infection

Malware Removal

The Trojan:Win32/Zombie!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zombie!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zombie!pz?


File Info:

name: 0A1C1FF4A509864FE1CF.mlw
path: /opt/CAPEv2/storage/binaries/e0fd0a2a12140368287568069648e2e3dd5466cdc6584347c976066c1af89434
crc32: AD176D71
md5: 0a1c1ff4a509864fe1cfeaee1d07a0f3
sha1: 68d858a95a98eaac3889b66d2658f62bee39ee31
sha256: e0fd0a2a12140368287568069648e2e3dd5466cdc6584347c976066c1af89434
sha512: 822a9652083ae0151c7f7c71c89b20f8a711c3535d6b11054aed091dd0a79990bb3306503d5afc74328c1140c472be8e6f1f98d1f4802cae32bb506e1ae9d79a
ssdeep: 768:qKVeIuKVeIaCgx+qsaCgx+qswPNPoRRTFMu+RRTFMux:6X0aX0wPNPoLKLV
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1841407039DE9BA9BD37392FF265A37542C28EEC77B52CEB51D51B1668411F30A893013
sha3_384: 9ef6e80c6bdd8d18b17f29d3b6a8167568d4868de274030ff738ac7b358b240895e765edcb79071c94a1f9d3fac621ae
ep_bytes: 00000000000000000000136000000000
timestamp: 2014-04-29 18:27:40

Version Info:

0: [No Data]

Trojan:Win32/Zombie!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.92970
FireEyeGeneric.mg.0a1c1ff4a509864f
SkyhighBehavesLike.Win32.Generic.cz
McAfeeArtemis!0A1C1FF4A509
ZillyaTrojan.Cosmu.Win32.152467
SangforSuspicious.Win32.Save.a
AlibabaTrojan:Win32/Zombie.e5ad384f
CynetMalicious (score: 100)
ClamAVWin.Malware.Lazy-9954277-0
BitDefenderTrojan.GenericKDZ.92970
SophosGeneric ML PUA (PUA)
VIPRETrojan.GenericKDZ.92970
EmsisoftTrojan.GenericKDZ.92970 (B)
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKDZ.92970
JiangminTrojan.Cosmu.atj
VaristW32/S-5a8d2096!Eldorado
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Tampering.27230
ArcabitTrojan.Generic.D16B2A
MicrosoftTrojan:Win32/Zombie!pz
GoogleDetected
ALYacTrojan.GenericKDZ.92970
TrendMicro-HouseCallTROJ_GEN.R03BH01KC23
RisingTrojan.Generic@AI.100 (RDML:Pn7EzMNqlvMQwhDoLaKM7Q)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Shohdi.B!tr
DeepInstinctMALICIOUS
CrowdStrikewin/grayware_confidence_60% (D)

How to remove Trojan:Win32/Zombie!pz?

Trojan:Win32/Zombie!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment