Trojan

Trojan:Win32/Zombie!pz removal guide

Malware Removal

The Trojan:Win32/Zombie!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zombie!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zombie!pz?


File Info:

name: E193BCAD859EAA7B7FA2.mlw
path: /opt/CAPEv2/storage/binaries/b95319dfa505ec2ab3b7fae03c025f6252fd2a0820f3b3116dee1436bc2750dd
crc32: 2174E1F3
md5: e193bcad859eaa7b7fa224ae38b12fc8
sha1: b8cb5cb4283b3af37d99957a502450b3aaf2199d
sha256: b95319dfa505ec2ab3b7fae03c025f6252fd2a0820f3b3116dee1436bc2750dd
sha512: 98f74a4e7be0a3205df621006aadd79fff42232eb0a59cf742b183aeaea14fb51543cf021092c83c226509f9a291afd02810d09138ab1809c6a5b574bd6a86d1
ssdeep: 768:qKVeIuKVeIaCgx+qsaCgx+qs9lRlCawokbl:6X0aX09r5wD
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11004D45B8FE5E996D367A2FF265A3A443C66A2C7B743FEB81D0171624420F3469D3023
sha3_384: 1d69baf2ad34f6a0dd5704eef9554f35ff5e1e0d7d20b3df773078393709bdfc800e14cfa29a25e21236de29dde92c1d
ep_bytes: 00000000000000000000136000000000
timestamp: 2014-04-29 18:27:40

Version Info:

0: [No Data]

Trojan:Win32/Zombie!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKDZ.92970
FireEyeTrojan.GenericKDZ.92970
SkyhighArtemis
McAfeeArtemis!E193BCAD859E
VIPRETrojan.GenericKDZ.92970
SangforSuspicious.Win32.Save.a
BitDefenderTrojan.GenericKDZ.92970
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ClamAVWin.Malware.Lazy-9954277-0
AlibabaTrojan:Win32/Zombie.e5ad384f
EmsisoftTrojan.GenericKDZ.92970 (B)
ZillyaTrojan.Cosmu.Win32.152467
SophosGeneric ML PUA (PUA)
IkarusTrojan.Crypt
JiangminTrojan.Cosmu.atj
VaristW32/S-5a8d2096!Eldorado
MAXmalware (ai score=82)
Antiy-AVLGrayWare/Win32.Tampering.27230
MicrosoftTrojan:Win32/Zombie!pz
ArcabitTrojan.Generic.D16B2A
GDataTrojan.GenericKDZ.92970
GoogleDetected
ALYacTrojan.GenericKDZ.92970
DeepInstinctMALICIOUS
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R03BH01K923
RisingTrojan.Generic@AI.100 (RDML:CXICLhauzVrTj3gNoCKu6A)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Shohdi.B!tr

How to remove Trojan:Win32/Zombie!pz?

Trojan:Win32/Zombie!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment