Spy

Win32/Spy.Zbot.ABA removal instruction

Malware Removal

The Win32/Spy.Zbot.ABA is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Zbot.ABA virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Win32/Spy.Zbot.ABA?


File Info:

name: C840087495A8326060BC.mlw
path: /opt/CAPEv2/storage/binaries/7b9cadc773897ac9532da8c3480968be43b865d0a61d0414782b771de33781b7
crc32: D03DC2D1
md5: c840087495a8326060bc8762dbe55420
sha1: 1369527a0827d7b3e9a8e75b73a639d1b5770c97
sha256: 7b9cadc773897ac9532da8c3480968be43b865d0a61d0414782b771de33781b7
sha512: e4fc37806dd99178d9d21f077adbeeb988f34b4343ad7316518a73d7c2c84fc04ceea8e3839b2be1bf4c738b3106fd47e5ad1f1de4cd1bdcadccf90319a4ac36
ssdeep: 3072:OiFRf6xBN/9S4YsIxqVAmDzNsyhNrlZPITUNya9Uyg5bL1E31Qa8w7vOuR1UQOEQ:fKxrEonRbjrllIT5mqQ31JnRuB
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11724126A16BB4BE4E8B700FAE1E5C9C808FDCA5523C5179B96C60CF41D35E434BB4B1A
sha3_384: aba7438e6f2bb829f44dad3ff2f39502af517878975eb731c1fff459a93e9920a87eae291ad8749cd8d91b777ce029b8
ep_bytes: 558bec81ec00010000b961260000894d
timestamp: 2012-11-29 19:19:46

Version Info:

ProductVersion: 185.242.61788
Translation: 0x0409 0x04b0

Win32/Spy.Zbot.ABA also known as:

BkavW32.FamVT.Yakes.003.Worm
LionicTrojan.Win32.Zbot.lVDm
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zusy.77094
FireEyeGeneric.mg.c840087495a83260
CAT-QuickHealFraudTool.Security
McAfeePWSZbot-FLM!C840087495A8
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.144314
SangforTrojan.Win32.Bulta.rfn
K7AntiVirusTrojan ( 0040f8b21 )
AlibabaTrojanSpy:Win32/Bulta.14205a02
K7GWTrojan ( 0040f8b21 )
Cybereasonmalicious.495a83
BaiduWin32.Trojan.Kryptik.dk
VirITTrojan.Win32.Generic.TDJ
CyrenW32/Zbot.OL.gen!Eldorado
SymantecTrojan.FakeAV!gen115
ESET-NOD32Win32/Spy.Zbot.ABA
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-57948
KasperskyTrojan-Spy.Win32.Zbot.raov
BitDefenderGen:Variant.Zusy.77094
NANO-AntivirusTrojan.Win32.Zbot.crvczw
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Kryptik-OEU [Trj]
TencentTrojan.Win32.Zbot.d
Ad-AwareGen:Variant.Zusy.77094
EmsisoftGen:Variant.Zusy.77094 (B)
ComodoTrojWare.Win32.Kryptik.BQD@55o2q6
DrWebTrojan.DownLoader9.5204
VIPRETrojan-Spy.Win32.Zbot.gen
TrendMicroTSPY_ZBOT.SMODN
McAfee-GW-EditionPWSZbot-FLM!C840087495A8
SophosMal/Generic-R + Troj/Zbot-HGR
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Zusy.77094
JiangminTrojanSpy.Zbot.eahg
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.69F3C6
KingsoftHeur.SSC.2803915.1216.(kcloud)
GridinsoftRansom.Win32.Zbot.sa
ViRobotTrojan.Win32.Z.Zbot.214209.A
MicrosoftPWS:Win32/Zbot!ml
TACHYONTrojan-Spy/W32.ZBot.214209
AhnLab-V3Trojan/Win32.Kazy.R92409
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.nu1@aSIqkRfO
ALYacGen:Variant.Zusy.77094
MAXmalware (ai score=100)
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesBackdoor.Agent.RND
TrendMicro-HouseCallTSPY_ZBOT.SMODN
RisingTrojan.Bulta!8.35D (CLOUD)
YandexTrojan.Agent!qYCBTEteFsc
IkarusTrojan.Win32.Yakes
MaxSecureTrojan.Yakes.DGen
FortinetW32/Kryptik.CAAF!tr
AVGWin32:Kryptik-OEU [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Win32/Spy.Zbot.ABA?

Win32/Spy.Zbot.ABA removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment