Spy Trojan

Should I remove “UDS:Trojan-Spy.Win32.Zbot”?

Malware Removal

The UDS:Trojan-Spy.Win32.Zbot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Spy.Win32.Zbot virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Anomalous binary characteristics

Related domains:

img.neko.airforce

How to determine UDS:Trojan-Spy.Win32.Zbot?


File Info:

crc32: 0AB5A17E
md5: 1ad28c768524311e68f7db00b34e9c29
name: 1AD28C768524311E68F7DB00B34E9C29.mlw
sha1: 03ef357f3d573431117fc4cc4efdd31463f56207
sha256: c5a4fcf0ba36f533f586ae631aa678f081c50b170d7f9def6ee19b131d12b0d0
sha512: a9333d828d7078010dce0e672fb39b063105e8a43a90ce0106ab852a713b4d0ad6f371ab2c080b980c3724a969bfa9994fdf23e1d04ceee8c0f8b27e9301db7e
ssdeep: 96:54ucy0IBducy0IB7lGucy0IBwucy0IB7l2hfE9+ucy0IB7l2lygnCsvb2warVjm:xH0JH08lBH0yH08lg0pH08lmnSm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

UDS:Trojan-Spy.Win32.Zbot also known as:

LionicTrojan.Win32.Convagent.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader42.27899
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaTrojanDownloader:Win32/AgentTesla.0fa18b41
K7GWTrojan-Downloader ( 00581eff1 )
CyrenW32/Agent.DJF.gen!Eldorado
ESET-NOD32a variant of Win32/TrojanDownloader.Agent.FVU
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyUDS:Trojan-Spy.Win32.Zbot
BitDefenderGen:Variant.Razy.920134
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Razy.920134
Ad-AwareGen:Variant.Razy.920134
BitDefenderThetaGen:NN.ZexaF.34126.auW@a05O@rai
VIPRELookslike.Win32.Sirefef.c!ag (v)
FireEyeGeneric.mg.1ad28c768524311e
EmsisoftGen:Variant.Razy.920134 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/AgentTesla.BLK!MTB
GDataGen:Variant.Razy.920134
AhnLab-V3Trojan/Win.MalwareX-gen.R440360
McAfeeGenericRXPX-TH!1AD28C768524
MAXmalware (ai score=82)
VBA32BScope.Trojan.Injects
RisingTrojan.Generic@ML.88 (RDML:jPZdi1CGbiAOp4e+nWK+bg)
IkarusTrojan-Downloader.Win32.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.DJF!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove UDS:Trojan-Spy.Win32.Zbot?

UDS:Trojan-Spy.Win32.Zbot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment