Malware

W32.Zombie.A4 information

Malware Removal

The W32.Zombie.A4 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What W32.Zombie.A4 virus can do?

  • Anomalous file deletion behavior detected (10+)
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior

How to determine W32.Zombie.A4?


File Info:

name: A8B21F99A0CBFF445A1C.mlw
path: /opt/CAPEv2/storage/binaries/1626b0bcb8a8b0d7516c4533a0eeca6de307ebf46fcc6d65a8f2f88881a10729
crc32: 8EA0337E
md5: a8b21f99a0cbff445a1cb1339efdd3b8
sha1: a64f15941e9bebfbcb8d588c58b946ae5b521633
sha256: 1626b0bcb8a8b0d7516c4533a0eeca6de307ebf46fcc6d65a8f2f88881a10729
sha512: 3475c00aba598a049a7384477f14ce7db2e0b26a1153d40cca018dc74a5fdc4e305eae8b988e8941c8acc452424a76f63701a20f4fcab567f9ae2de1af0683c9
ssdeep: 12288:+h9Nf72TRLOf+pKWebwXNtS9B4QOolf7zGwWut/+:+h9Nf729LC+pKWebwXjS9B4QOoljznWL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1679408A1C91AD88CFF8768F747A6B01EA17CE4082CF615EF5863DA2C3A8186575350F7
sha3_384: ee289e70346e61722edb0b06eb98ed4b90f7dc03bfafec02e8c2cbbf0d6b532220143be3a91cb7b815f20036b8b21c97
ep_bytes: 558bec6aff684031400068b022400064
timestamp: 2011-03-15 04:06:07

Version Info:

0: [No Data]

W32.Zombie.A4 also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Encoder.185
CynetMalicious (score: 100)
FireEyeGeneric.mg.a8b21f99a0cbff44
CAT-QuickHealW32.Zombie.A4
McAfeeGenericRXNR-SA!A8B21F99A0CB
CylanceUnsafe
ZillyaTrojan.Cosmu.Win32.12187
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0055e3dd1 )
K7GWTrojan ( 0055e3dd1 )
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaF.34182.yqZ@aGBV9uib
CyrenW32/Cosmu.H.gen!Eldorado
ESET-NOD32Win32/Agent.NBJ
APEXMalicious
ClamAVWin.Trojan.Cosmu-1058
KasperskyTrojan.Win32.Cosmu.bwts
BitDefenderTrojan.GenericKD.34110279
NANO-AntivirusTrojan.Win32.Cosmu.bgzaxj
MicroWorld-eScanTrojan.GenericKD.34110279
AvastWin64:Malware-gen
TencentVirus.Win32.Cosmu.a
Ad-AwareTrojan.GenericKD.34110279
SophosMal/Behav-112
ComodoTrojWare.Win32.Agent.NBJ@4xjtww
VIPRETrojan.Win32.Cosmu.bwts (v)
TrendMicroTROJ_SPNR.15CC13
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.fm
EmsisoftTrojan.GenericKD.34110279 (B)
GDataTrojan.GenericKD.34110279
JiangminHoax.NSIS.d
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASMalwS.13CA44
KingsoftHeur.SSC.2787082.0010.(kcloud)
ArcabitTrojan.Generic.D2087B47
ZoneAlarmTrojan.Win32.Cosmu.bwts
MicrosoftTrojan:Win32/Zombie.A
AhnLab-V3Trojan/Win32.Cosmu.R51515
VBA32Trojan.Cosmu
ALYacTrojan.GenericKD.34110279
MAXmalware (ai score=88)
TrendMicro-HouseCallTROJ_SPNR.15CC13
RisingTrojan.Zombie!8.2DA5 (RDMK:cmRtazqZA6YRCTDRdADX/kB5jVbL)
IkarusTrojan.Win32.Cosmu
MaxSecureTrojan.Cosmu.bwts
FortinetW32/Agent.NBJ!tr
AVGWin64:Malware-gen
Cybereasonmalicious.9a0cbf
PandaTrj/Genetic.gen

How to remove W32.Zombie.A4?

W32.Zombie.A4 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment