Spy

Win32/Spy.Zbot.UT information

Malware Removal

The Win32/Spy.Zbot.UT is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Zbot.UT virus can do?

  • Sample contains Overlay data
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Win32/Spy.Zbot.UT?


File Info:

name: 900B85611F7C36CD566A.mlw
path: /opt/CAPEv2/storage/binaries/804cfc2460c3b2650dc802869d7c460aef3ba14dd541875d8370f8f7825a3772
crc32: CA401F1A
md5: 900b85611f7c36cd566aef110184f19c
sha1: b07596160401c5f391de7303810dcde6ad6b8a48
sha256: 804cfc2460c3b2650dc802869d7c460aef3ba14dd541875d8370f8f7825a3772
sha512: 43ca8fec595f6bdb3d629c8c05fad9c22562879b660a0595477a7ffccb1c0ee1564121810fd5654b05bfb9e3e69e3271dc198e51c56489a8e989fea80a0708ff
ssdeep: 3072:nzkGs0BmhGldVRSNAQG1dG0oZ+w5cNSIsqJOyG+9:zw6dVgoddACSIsv29
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11BE312B43A38F9B5C8076B7C07495D088F8DA5AB73996E12F6DB1CB586EA25301C7730
sha3_384: 6e7a5e17fe2bb343c4e0f5ccff3570bc3bd4fc442147d6fd2b338e559b14daaa7b627a083779a68dd723d45bf0361a11
ep_bytes: 605589e58bdb8bfa668bfa908bcb668b
timestamp: 1970-09-27 17:33:50

Version Info:

0: [No Data]

Win32/Spy.Zbot.UT also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.BZub.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Crypt.IU
FireEyeGeneric.mg.900b85611f7c36cd
SkyhighBehavesLike.Win32.VirRansom.cc
McAfeeArtemis!900B85611F7C
Cylanceunsafe
ZillyaTrojan.BZub.Win32.724
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 00071a9a1 )
AlibabaVirTool:Win32/Obfuscator.47ab166a
K7GWTrojan ( 00071a9a1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.E5CBBE741E
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Spy.Zbot.UT
APEXMalicious
TrendMicro-HouseCallTSPY_ZBOT.SMF
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Crypt.IU
NANO-AntivirusTrojan.Win32.BZub.crooba
AvastWin32:MalOb-U [Cryp]
TencentWin32.Trojan.Generic.Eajl
SophosMal/EncPk-KI
F-SecureTrojan.TR/Dropper.Gen
DrWebTrojan.PWS.Webmonier.178
VIPRETrojan.Crypt.IU
TrendMicroTSPY_ZBOT.SMF
Trapminemalicious.high.ml.score
EmsisoftTrojan.Crypt.IU (B)
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojanSpy.BZub.frx
GoogleDetected
AviraTR/Dropper.Gen
VaristW32/Trojan.EUJN-6321
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Trojan.Generic.a
MicrosoftVirTool:Win32/Obfuscator.HM
XcitiumTrojWare.Win32.Spy.Zbot.AAZ@1p8hml
ArcabitTrojan.Crypt.IU
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.Crypt.IU
CynetMalicious (score: 99)
VBA32BScope.TrojanSpy.Zbot
ALYacTrojan.Crypt.IU
MAXmalware (ai score=99)
MalwarebytesMalware.Heuristic.2090
PandaTrj/Genetic.gen
RisingSpyware.Zbot!1.684E (CLASSIC)
YandexTrojan.Malagent!4CcKeWDdqIo
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.4618224.susgen
FortinetW32/Zbot.SOO!tr
AVGWin32:MalOb-U [Cryp]
Cybereasonmalicious.11f7c3
DeepInstinctMALICIOUS
alibabacloudTrojan[spy]:Win/Zbot.UT

How to remove Win32/Spy.Zbot.UT?

Win32/Spy.Zbot.UT removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment