Trojan

What is “Trojan:Win32/Zombie!pz”?

Malware Removal

The Trojan:Win32/Zombie!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zombie!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zombie!pz?


File Info:

name: 6BEC1A9885108FBEF540.mlw
path: /opt/CAPEv2/storage/binaries/9d470fda769cec50ea8b437c1025a2db2b7f8fb5c3e0edcdc4ea7c2e01ab7ff6
crc32: 7454ADEE
md5: 6bec1a9885108fbef540a9ca1e83ec60
sha1: 8e508d5fff8a8c403725761a96fa2749490d3b5f
sha256: 9d470fda769cec50ea8b437c1025a2db2b7f8fb5c3e0edcdc4ea7c2e01ab7ff6
sha512: 82972d2eff2509edd54d1f7fa16be5af96ff8b558b9638582cd72bc383b6daacc450b49a8cbff335a376bd95e7fc3ddc5df9885f048dca8a4e2b9b6b63eb23b1
ssdeep: 6144:mlL5lqo52kDzMYDJSi7+Ni2ER9Vh98+1PrEVhkQf0huIDaLOjm:0MqzBDJkk2ERvT8MPAf/O6
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4B46C127FF4E47AC74301328B497BE0A5F993A969218D7327C0192CAA31DB6D275F1B
sha3_384: 5245eb896f5b83e40bd05e73c34368495a3dadec1f97c9b18ff57f35fdc75bd04655a2a390a91e3f47f346df68242193
ep_bytes: 00000000000000000000136000000000
timestamp: 2014-04-29 18:27:40

Version Info:

0: [No Data]

Trojan:Win32/Zombie!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKDZ.92970
SkyhighBehavesLike.Win32.Generic.hm
McAfeeArtemis!6BEC1A988510
MalwarebytesGeneric.Malware/Suspicious
ZillyaTrojan.Cosmu.Win32.152467
SangforTrojan.Win32.Zombie.V4ku
AlibabaTrojan:Win32/Zombie.11ff148c
CrowdStrikewin/malicious_confidence_90% (W)
ArcabitTrojan.Generic.D16B2A
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Lazy-9954277-0
BitDefenderTrojan.GenericKDZ.92970
AvastWin32:Malware-gen
EmsisoftTrojan.GenericKDZ.92970 (B)
VIPRETrojan.GenericKDZ.92970
TrendMicroTROJ_GEN.R002C0DL423
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Cosmu.atj
VaristW32/S-5a8d2096!Eldorado
Antiy-AVLGrayWare/Win32.Tampering.27230
MicrosoftTrojan:Win32/Zombie!pz
GDataTrojan.GenericKDZ.92970
GoogleDetected
MAXmalware (ai score=84)
Cylanceunsafe
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002C0DL423
RisingTrojan.Generic@AI.100 (RDML:sKKYEoVp0T/4EnqeZN5IiA)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Shohdi.B!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zombie!pz?

Trojan:Win32/Zombie!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment