Malware

Win32:Zbot-UOU [Trj] removal

Malware Removal

The Win32:Zbot-UOU [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Zbot-UOU [Trj] virus can do?

  • Executable code extraction
  • Compression (or decompression)
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32:Zbot-UOU [Trj]?


File Info:

crc32: CD0BA26A
md5: d44229dd74489a75f615471d6112e002
name: D44229DD74489A75F615471D6112E002.mlw
sha1: fed6d42d6dda8ed7addcf2743980758d5eea3f2f
sha256: 09a589c57f0b48bca832ce52108079b74dc3b0b9666f31725e40045b5b9f9372
sha512: 38cda99461eb8c333d1451bfef0dd9918dfa2ec11cd4246ef0c423d690d355609352168499fea5f98f5a836b11e59743a22809d4ff8d50bfed582944c90cb586
ssdeep: 3072:O/fBZrZtmSZS+YI4jxtfiHLCSemf8fY8xH7qhLkP2YVAeAFWfbLZl0yJE0Cl:O/fBZ9qtI4jxjmEfYw7EmVAecWzLZjE
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2014 ABCDevelop Software
InternalName: MSR Except Utility
FileVersion: 1.3.4.1
CompanyName: ABCDevelop Software
ProductName: MSR Exception Diagnostic Utility
ProductVersion: 1.3.4.1
FileDescription: MSR Exception Diagnostic Utility
OriginalFilename: msrexceptdiagutil
Translation: 0x1809 0x04b0

Win32:Zbot-UOU [Trj] also known as:

K7AntiVirusTrojan ( 0055e4091 )
DrWebTrojan.PWS.Panda.5181
CynetMalicious (score: 100)
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.d6dda8
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.APR
APEXMalicious
AvastWin32:Zbot-UOU [Trj]
KasperskyTrojan-Ransom.Win32.Foreign.nfft
TencentWin32.Trojan.Foreign.Wpiw
ComodoMalware@#3vowmbu7b9118
BitDefenderThetaGen:NN.ZexaF.34088.iu0@aysSG9li
VIPRETrojan.Win32.Fareit.ba (v)
TrendMicroTROJ_SPNR.3AL213
McAfee-GW-EditionBehavesLike.Win32.Trojan.ch
FireEyeGeneric.mg.d44229dd74489a75
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Foreign.bij
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1107983
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.61A264
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftRansom:Win32/Urausy.C
AhnLab-V3Spyware/Win32.Zbot.R88938
McAfeePWS-Zbot-FBFN!D44229DD7448
VBA32Hoax.Foreign
MalwarebytesSpyware.Zbot.VXGen
PandaGeneric Malware
TrendMicro-HouseCallTROJ_SPNR.3AL213
IkarusTrojan.Crypt2
FortinetW32/Zbot.PKDP!tr
AVGWin32:Zbot-UOU [Trj]
Qihoo-360Win32/Ransom.Urausy.HwoCEpsA

How to remove Win32:Zbot-UOU [Trj]?

Win32:Zbot-UOU [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment