Spy

Win32/Spy.Zbot.ACS (file analysis)

Malware Removal

The Win32/Spy.Zbot.ACS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Zbot.ACS virus can do?

  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Win32/Spy.Zbot.ACS?


File Info:

name: F33808EA5100648108C7.mlw
path: /opt/CAPEv2/storage/binaries/7bd22e3147122eb4438f02356e8927f36866efa0cc07cc604f1bff03d76222a6
crc32: 9673A80B
md5: f33808ea5100648108c7d0d6a0d5eb61
sha1: 79908f60571d837924118bd697e5b267a1c5fafa
sha256: 7bd22e3147122eb4438f02356e8927f36866efa0cc07cc604f1bff03d76222a6
sha512: f85ccdece447ca1d16869febd4f0b0db05ebac0e164b7363e95524710e27fcc4d5c183a18c4482c4c7950a1b5f50a61ec4d3604c661d90ebec643e3d25bb9898
ssdeep: 6144:o8NIUR3cseGOSH+JvwpnmYy/7u/CNcCXm8:pIA3dbvHCvYuu/CCCX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB341207FD0749BBE3AF2674D336B3D5177C46297B80CD1AE6468B2471928E0378920A
sha3_384: f838a21f7402fae71647b43466aad0ccdbab0f42fde829b6c2dd6e1e32f650ea38f3e2848dfeeac3e05514aaebb95b45
ep_bytes: 558bec83e4f881ec34060000535657e8
timestamp: 2016-11-15 20:41:06

Version Info:

0: [No Data]

Win32/Spy.Zbot.ACS also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zbot.1e!c
DrWebTrojan.DownLoader23.23205
MicroWorld-eScanTrojan.GenericKDZ.84984
ClamAVWin.Trojan.Flokibot-2
FireEyeGeneric.mg.f33808ea51006481
SkyhighBehavesLike.Win32.Lockbit.dc
McAfeePWSZbot-FAVZ!F33808EA5100
Cylanceunsafe
ZillyaDropper.Injector.Win32.79571
SangforSpyware.Win32.Zbot.Vnjh
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaTrojanSpy:Win32/Injector.09424f69
K7GWSpyware ( 0055e3db1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36744.pqW@a8JNBCk
SymantecTrojan.Gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Zbot.ACS
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Dropper.Win32.Injector.pyze
BitDefenderTrojan.GenericKDZ.84984
NANO-AntivirusVirus.Win32.Gen.ccmw
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10b72bfd
SophosTroj/Floki-A
F-SecureTrojan.TR/Dropper.Gen
VIPRETrojan.GenericKDZ.84984
TrendMicroTSPY_FLOKIBOT.A
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.84984 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.84984
JiangminTrojan.Generic.ancvs
WebrootW32.Malware.Gen
GoogleDetected
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Win32.AGeneric
Kingsoftmalware.kb.a.1000
ArcabitTrojan.Generic.D14BF8
ViRobotTrojan.Win32.Z.Zbot.245760.GZ
ZoneAlarmTrojan-Dropper.Win32.Injector.pyze
MicrosoftPWS:Win32/Zbot
VaristW32/Zbot.AAW.gen!Eldorado
AhnLab-V3Dropper/Win32.Injector.C1595901
ALYacTrojan.Flokibot
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.Panda
MalwarebytesZbot.Spyware.Stealer.DDS
PandaTrj/CI.A
TrendMicro-HouseCallTSPY_FLOKIBOT.A
RisingSpyware.Zbot!8.16B (TFE:3:EZKc7rEx5ZB)
YandexTrojan.GenAsa!ZWRdNsJmcVc
IkarusTrojan.Kazy
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Floki.A!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS

How to remove Win32/Spy.Zbot.ACS?

Win32/Spy.Zbot.ACS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment