Trojan

What is “Trojan:Win32/Zombie!pz”?

Malware Removal

The Trojan:Win32/Zombie!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zombie!pz virus can do?

  • Sample contains Overlay data
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zombie!pz?


File Info:

name: 85EA3DB64A0BCD9F6CB0.mlw
path: /opt/CAPEv2/storage/binaries/b94bbf300894bc5865916689f4e08b223f79fb26dbff6cd8bcd70ecd52a0228d
crc32: DB607474
md5: 85ea3db64a0bcd9f6cb0a583cf693aef
sha1: 248480f8310a72f23552c5f527792f1b5bb70d2b
sha256: b94bbf300894bc5865916689f4e08b223f79fb26dbff6cd8bcd70ecd52a0228d
sha512: a287cb40dae79c36ae8ea3306a3ce3b15482ceafd33c16a281636bd56719094f971e6891946da9437d7d2be80cbe4e3b4206e5091682fa3dd67f12f20a362423
ssdeep: 1536:6X0aX09rDVMFDwU5LenTpnDr5LenTpnDRSfubQa1Q5IoX:mlCKP1Q5IO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19244F71F9EE1B482D36553FA6882B2CC2C65FF82B7EFDD79694378669010C3458C912B
sha3_384: 97c771bb4b652334108ce5fc15f948f4a3624ae4ea457ba9d9ca278e8088f4b3f5186c4827895597e7b7494991a117d6
ep_bytes: 00000000000000000000136000000000
timestamp: 2014-04-29 18:27:40

Version Info:

0: [No Data]

Trojan:Win32/Zombie!pz also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.92970
FireEyeTrojan.GenericKDZ.92970
SkyhighBehavesLike.Win32.Generic.dz
ALYacTrojan.GenericKDZ.92970
VIPRETrojan.GenericKDZ.92970
SangforSuspicious.Win32.Save.a
BitDefenderTrojan.GenericKDZ.92970
ClamAVWin.Malware.Lazy-9954277-0
SophosGeneric ML PUA (PUA)
ZillyaTrojan.Cosmu.Win32.152467
EmsisoftTrojan.GenericKDZ.92970 (B)
IkarusTrojan.Crypt
JiangminTrojan.Cosmu.atj
VaristW32/S-5a8d2096!Eldorado
Antiy-AVLGrayWare/Win32.Tampering.27230
MicrosoftTrojan:Win32/Zombie!pz
ArcabitTrojan.Generic.D16B2A
GDataTrojan.GenericKDZ.92970
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R531298
McAfeeArtemis!85EA3DB64A0B
MAXmalware (ai score=83)
DeepInstinctMALICIOUS
RisingTrojan.Generic@AI.100 (RDML:67EA83dvGjRu1ErFFsd1ng)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Shohdi.B!tr

How to remove Trojan:Win32/Zombie!pz?

Trojan:Win32/Zombie!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment