Trojan

Trojan:Win32/Zombie!pz malicious file

Malware Removal

The Trojan:Win32/Zombie!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zombie!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zombie!pz?


File Info:

name: 7B6F3385F1858C0EE3E5.mlw
path: /opt/CAPEv2/storage/binaries/0e189744b9880cdfa337956e65882b088b65e8b64a32ea04b02c9fc1635d2719
crc32: 852324BE
md5: 7b6f3385f1858c0ee3e5276169773164
sha1: 997710530543af6f3483203bbe83844b03ca7036
sha256: 0e189744b9880cdfa337956e65882b088b65e8b64a32ea04b02c9fc1635d2719
sha512: e668e3ff2792f4ee89689aeece7fd4c4b2e06ee692cb16b2bd2312198a872de324876ce109900d37c3674083a3e893f4eff6907c99769b051ffc2cac4adfc7f4
ssdeep: 768:qKVeIuKVeIaCgx+qsaCgx+qs9lRlCaw85nd5nHlkSb:6X0aX09r5w8NdNCSb
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A204E65B9DE5E9A7C363D3FF656A36482866A2DB7352DEB01D41F26A0410F30A9C3027
sha3_384: 11510d2cb1022bdcc87f59c6e470e58acca1ead526bae37c4ef7b0755d33f29e16c0085e82e9043d94938411f19e9747
ep_bytes: 00000000000000000000136000000000
timestamp: 2014-04-29 18:27:40

Version Info:

0: [No Data]

Trojan:Win32/Zombie!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.92970
SkyhighBehavesLike.Win32.Generic.cz
McAfeeArtemis!7B6F3385F185
ZillyaTrojan.Cosmu.Win32.152467
SangforSuspicious.Win32.Save.a
ArcabitTrojan.Generic.D16B2A
CynetMalicious (score: 100)
ClamAVWin.Malware.Lazy-9954277-0
BitDefenderTrojan.GenericKDZ.92970
EmsisoftTrojan.GenericKDZ.92970 (B)
VIPRETrojan.GenericKDZ.92970
FireEyeGeneric.mg.7b6f3385f1858c0e
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Cosmu.atj
VaristW32/S-5a8d2096!Eldorado
MAXmalware (ai score=80)
Antiy-AVLGrayWare/Win32.Tampering.27230
MicrosoftTrojan:Win32/Zombie!pz
GDataTrojan.GenericKDZ.92970
GoogleDetected
ALYacTrojan.GenericKDZ.92970
TrendMicro-HouseCallTROJ_GEN.R03BH01KM23
RisingTrojan.Generic@AI.100 (RDML:wPCiOlcC+B9Pzcfud+sRdg)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Shohdi.B!tr
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zombie!pz?

Trojan:Win32/Zombie!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment