Categories: Spy

Zbot.Spyware.Stealer.DDS removal guide

The Zbot.Spyware.Stealer.DDS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zbot.Spyware.Stealer.DDS virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid

How to determine Zbot.Spyware.Stealer.DDS?


File Info:

name: E707B4AC794EFD28023A.mlwpath: /opt/CAPEv2/storage/binaries/1c2241058dc64383bf6374cbcaf8e4f202405a6631d7eb587db8a29c54577321crc32: BF315916md5: e707b4ac794efd28023a1bafe62b9b8esha1: 87b6593e06113e34012ade66dad2d77527ffd91bsha256: 1c2241058dc64383bf6374cbcaf8e4f202405a6631d7eb587db8a29c54577321sha512: 5fd475099a756744a86402f258d012c63228a39a9946dce8a6df75a52739bbee1f4baee38c326114b94cadf1056a0602d6829138b6b68bf22181a8de559a4c74ssdeep: 1536:6wHCFl/MZqoWoCJ6Io4t2oOHHf3nrD/zIa6THxr5sjozWr/:Ty/MZ3e6Io4AJHHfb7zIa6Lxr5+4Wrtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T159A3A066B440A4B7C4992675FE59FF2653FD8924303A8DC3F3584E0A28619E3E32E743sha3_384: 7f3141673ac6ff277e8aa35abd3a77fcb0fb1c49c8f57eae99494eaf5dfbe543424b780f35335899e92781d7de480ca6ep_bytes: 558bec83ec0c536a0032dbe8e0f0fffftimestamp: 2011-03-11 22:39:06

Version Info:

0: [No Data]

Zbot.Spyware.Stealer.DDS also known as:

Bkav W32.AIDetect.malware1
Lionic Trojan.Win32.Generic.4!c
MicroWorld-eScan Backdoor.Zbot.D
CAT-QuickHeal Trojan.Necurs.MUE.A3
ALYac Backdoor.Zbot.D
Cylance Unsafe
VIPRE Backdoor.Zbot.D
Sangfor Trojan.Win32.Save.a
K7AntiVirus Spyware ( 002891031 )
BitDefender Backdoor.Zbot.D
K7GW Spyware ( 002891031 )
CrowdStrike win/malicious_confidence_100% (D)
Arcabit Backdoor.Zbot.D
BitDefenderTheta Gen:NN.ZexaF.34796.gmW@ai5xVdg
VirIT Trojan.Win32.Generic.BBWC
Cyren W32/Zbot.BR.gen!Eldorado
Symantec ML.Attribute.HighConfidence
Elastic malicious (high confidence)
ESET-NOD32 a variant of Generik.JUJLPJZ
APEX Malicious
ClamAV Win.Spyware.Zbot-1275
Kaspersky HEUR:Trojan.Win32.Generic
Alibaba Malware:Win32/km_2874.None
Rising Spyware.Zbot!1.648A (CLASSIC)
Ad-Aware Backdoor.Zbot.D
Emsisoft Backdoor.Zbot.D (B)
Comodo TrojWare.Win32.Kazy.MKE@4qchom
TrendMicro Cryp_Xin1
McAfee-GW-Edition BehavesLike.Win32.ZBot.ch
Trapmine malicious.high.ml.score
FireEye Generic.mg.e707b4ac794efd28
Sophos ML/PE-A + Mal/Behav-010
Jiangmin TrojanSpy.Zbot.awjg
Google Detected
Avira TR/Kazy.MK
Kingsoft Win32.Troj.Undef.(kcloud)
Microsoft PWS:Win32/Zbot!CI
GData Win32.Trojan-Spy.Zbot.DB
Cynet Malicious (score: 100)
AhnLab-V3 Trojan/Win32.Zbot.R50196
Acronis suspicious
McAfee PWS-Zbot.gen.aov
MAX malware (ai score=86)
Malwarebytes Zbot.Spyware.Stealer.DDS
Panda Trj/Genetic.gen
Zoner Trojan.Win32.18323
TrendMicro-HouseCall Cryp_Xin1
Tencent Win32.Trojan.Generic.Xmhl
Yandex Trojan.GenAsa!u34NaRSOngc
SentinelOne Static AI – Malicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet W32/Zbot.AAU!tr
AVG Sf:Crypt-BT [Trj]
Cybereason malicious.c794ef
Avast Sf:Crypt-BT [Trj]

How to remove Zbot.Spyware.Stealer.DDS?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Malware.AI.4198593862 removal instruction

The Malware.AI.4198593862 is considered dangerous by lots of security experts. When this infection is active,…

1 min ago

Should I remove “Trojan.Generic.35772264”?

The Trojan.Generic.35772264 is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Malware.AI.988235226 malicious file

The Malware.AI.988235226 is considered dangerous by lots of security experts. When this infection is active,…

17 mins ago

Malware.AI.2099319323 information

The Malware.AI.2099319323 is considered dangerous by lots of security experts. When this infection is active,…

22 mins ago

Backdoor.GenericFC.S20328115 removal guide

The Backdoor.GenericFC.S20328115 is considered dangerous by lots of security experts. When this infection is active,…

28 mins ago

How to remove “PWS:Win32/Lmir.JJ”?

The PWS:Win32/Lmir.JJ is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago