Malware

Win32:Zeus-N [Trj] removal

Malware Removal

The Win32:Zeus-N [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Zeus-N [Trj] virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32:Zeus-N [Trj]?


File Info:

crc32: 53D131F3
md5: 987c5600b03fed13eb2a58f326e2a54d
name: 987C5600B03FED13EB2A58F326E2A54D.mlw
sha1: 48c4dfe75eaa7cbcfcda7f459ebe163a797f2d82
sha256: 11c239b58aab6ffc0e7121abef05c3cddcc04a612a5930e58f1d4c61d6c3bdbf
sha512: 3f0f0939e1307cb13dafe41a32c35dda3436be232de5c4551078bffda241a0dfb5046393b1c26d18cec963cc6e753bb476376d0ed15cbe34a820e2ea49041bf0
ssdeep: 3072:XdOZxQ6p+GNhUxr2JO6Di85vFoEwMCnd88NTUrNNG0dKNFZti/yINQ6JdU:XsZxQq+tN2JO6DnZTsq8WNoNBkd3
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2020
Assembly Version: 0.0.0.0
InternalName: h8yhdfgdfere5frwfwjdh8yhd.exe
FileVersion: 0.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: ZagreuS
ProductVersion: 0.0.0.0
FileDescription: ZagreuS
OriginalFilename: h8yhdfgdfere5frwfwjdh8yhd.exe

Win32:Zeus-N [Trj] also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36138418
Qihoo-360HEUR/QVM03.0.AFAF.Malware.Gen
ALYacTrojan.GenericKD.36138418
MalwarebytesRansom.FileCryptor
SangforMalware
BitDefenderTrojan.GenericKD.36138418
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.75eaa7
ArcabitTrojan.Generic.D2276DB2
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.MSIL.DelShad.gen
AlibabaTrojan:Win32/Genasom.89bbaeb2
ViRobotTrojan.Win32.Z.Zbot.239104.CS
Ad-AwareTrojan.GenericKD.36138418
SophosML/PE-A + Mal/Genasom-A
F-SecureTrojan.TR/Dropper.Gen7
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.987c5600b03fed13
EmsisoftTrojan.GenericKD.36138418 (B)
IkarusConstructor.Win32.Zbot
AviraTR/Dropper.Gen7
GridinsoftTrojan.Heur!.03012281
MicrosoftRansom:Win32/Genasom
AegisLabTrojan.Win32.Malicious.4!c
ZoneAlarmHEUR:Trojan.MSIL.DelShad.gen
GDataWin32.Trojan-Ransom.Filecoder.V1J8Y4@gen
CynetMalicious (score: 100)
McAfeeArtemis!987C5600B03F
MAXmalware (ai score=88)
CylanceUnsafe
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H0CAG21
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.OVF!tr
BitDefenderThetaGen:NN.ZemsilF.34760.ou0@aaYRiw
AVGWin32:Zeus-N [Trj]
AvastWin32:Zeus-N [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Win32:Zeus-N [Trj]?

Win32:Zeus-N [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment