Spy

Should I remove “Win32/Spy.Zbot.AAQ”?

Malware Removal

The Win32/Spy.Zbot.AAQ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Zbot.AAQ virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX

How to determine Win32/Spy.Zbot.AAQ?


File Info:

crc32: 0F8FEA67
md5: ef0b6bf3e8752d4b6e98bf22c6fb8ef0
name: EF0B6BF3E8752D4B6E98BF22C6FB8EF0.mlw
sha1: c0b336f3b6906ebaee05882d10f3ace637577d17
sha256: a27d044e91265ce26613cb97c36c5bf4915f0eed1ec8f438e2cf65052ac347ea
sha512: 686aaaef8c593a9d2dcca7abd48b760e5a2e4e6439b30fcfb738f655fa6fb2a4d25e313e85e21d764a83c3f64b055af18298eacd97333db4da186c8a8ee17cc4
ssdeep: 6144:pli24QyC/EsVnP52yI1EG6wTUGxsZGgeuuD08AxAyLR:peCdVnPfI/X+EZvvyLR
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Win32/Spy.Zbot.AAQ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusSpyware ( 0055e3db1 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.2401
CynetMalicious (score: 100)
ALYacGen:Variant.ClipBanker.216
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.120855
SangforTrojan.Win32.Save.a
AlibabaTrojanSpy:Win32/Generic.cf04d691
K7GWSpyware ( 0055e3db1 )
Cybereasonmalicious.3e8752
CyrenW32/A-afae04fd!Eldorado
SymantecPacked.Generic.453
ESET-NOD32Win32/Spy.Zbot.AAQ
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Dropper.Gh0stRAT-7775521-0
KasperskyTrojan-Spy.Win32.Zbot.mdsq
BitDefenderGen:Variant.ClipBanker.216
NANO-AntivirusTrojan.Win32.Zbot.bxoyps
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
MicroWorld-eScanGen:Variant.ClipBanker.216
TencentWin32.Trojan-spy.Zbot.Akyt
Ad-AwareGen:Variant.ClipBanker.216
SophosMal/Generic-S
ComodoMalware@#fetia2w010r3
BitDefenderThetaGen:NN.ZexaF.34692.rmGfaOYGVlei
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.ef0b6bf3e8752d4b
EmsisoftGen:Variant.ClipBanker.216 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan-Dropper.VB.a
WebrootW32.Rogue.Gen
AviraTR/PSW.Zbot.AJ.4
Antiy-AVLTrojan/Generic.ASMalwS.2426AF
KingsoftWin32.Troj.Zbot.a.(kcloud)
MicrosoftPWS:Win32/Zbot
ArcabitTrojan.ClipBanker.216
AegisLabTrojan.Win32.Zbot.l!c
GDataGen:Variant.ClipBanker.216
TACHYONTrojan-Spy/W32.ZBot.417792.AE
AhnLab-V3Worm/Win32.Luder.R70421
McAfeeArtemis!EF0B6BF3E875
MAXmalware (ai score=99)
VBA32TrojanSpy.Zbot
PandaTrj/Dtcontx.E
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojanSpy.Zbot!hkmlVNKn3gc
IkarusBackdoor.Win32.Shiz
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.RQII!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Win32/Spy.Zbot.AAQ?

Win32/Spy.Zbot.AAQ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment