Trojan

About “Trojan:Win32/Zombie!pz” infection

Malware Removal

The Trojan:Win32/Zombie!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zombie!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zombie!pz?


File Info:

name: 0A70240A2F1D09EB5FB1.mlw
path: /opt/CAPEv2/storage/binaries/09bb0dec73784930f1362824473ba029c6007e88316cc5961afa4808a66099b6
crc32: ED75CA6B
md5: 0a70240a2f1d09eb5fb1eb2a44787b3a
sha1: 7515ea48ac41ad9a1ec8b5392ff6da1b70e4d486
sha256: 09bb0dec73784930f1362824473ba029c6007e88316cc5961afa4808a66099b6
sha512: 544b7f399c7b13c3500f5145ed722eb31b2bc97cafc9fdace235ca134d0583dd71a9fbc9784055d172dcfc2ec41f39276ece71c8d1e051ac15d08eeee2c149b1
ssdeep: 1536:6X0aX09rDVMFDwU5LenTpnDr5LenTpnDRSfu9:mlCK9
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15C34E60F9EE0B186D36543FE2885B2CC2C96FF82B7EFDD79694278269010D3458C526B
sha3_384: 387ffc321d971390fc1e8739607bde594ef9f09f596a4947d51bc343f5f480c1c808c189a85295bd68598713ebd96c82
ep_bytes: 00000000000000000000136000000000
timestamp: 2014-04-29 18:27:40

Version Info:

0: [No Data]

Trojan:Win32/Zombie!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
MicroWorld-eScanTrojan.GenericKDZ.92970
ClamAVWin.Malware.Lazy-9954277-0
FireEyeTrojan.GenericKDZ.92970
SkyhighBehavesLike.Win32.Generic.dz
ALYacTrojan.GenericKDZ.92970
ZillyaTrojan.Cosmu.Win32.152467
SangforSuspicious.Win32.Save.a
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
BitDefenderTrojan.GenericKDZ.92970
EmsisoftTrojan.GenericKDZ.92970 (B)
VIPRETrojan.GenericKDZ.92970
SophosGeneric ML PUA (PUA)
IkarusTrojan.Crypt
GDataTrojan.GenericKDZ.92970
JiangminTrojan.Cosmu.atj
GoogleDetected
Antiy-AVLGrayWare/Win32.Tampering.27230
ArcabitTrojan.Generic.D16B2A
MicrosoftTrojan:Win32/Zombie!pz
VaristW32/S-5a8d2096!Eldorado
McAfeeArtemis!0A70240A2F1D
MAXmalware (ai score=87)
DeepInstinctMALICIOUS
RisingTrojan.Generic@AI.100 (RDML:PL0Y2dIk8EfkamQXGXMDjg)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Shohdi.B!tr

How to remove Trojan:Win32/Zombie!pz?

Trojan:Win32/Zombie!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment