{"id":262,"date":"2014-10-29T09:06:12","date_gmt":"2014-10-29T09:06:12","guid":{"rendered":"http:\/\/www.adlice.com\/?p=262"},"modified":"2022-12-21T10:39:25","modified_gmt":"2022-12-21T10:39:25","slug":"remove-zeus","status":"publish","type":"post","link":"https:\/\/www.adlice.com\/es\/remove-zeus\/","title":{"rendered":"How to Remove Zeus (Guide)"},"content":{"rendered":"\n<h4 class=\"has-accent-color has-text-color wp-block-heading\">EDIT October, 4th 2014<\/h4>\n\n\n\n<p><strong>If the only process detected is your Antivirus, please ignore the detection.<\/strong><br>We are working on this issue, which is not really a bug, but a problem of signature scanner definition VS Antivirus definition. <\/p>\n\n\n\n<p>Some Antivirus scanners load their signature database in clear in memory, and when RogueKiller has the same signature as the AV for a particular malware (this is the case for Zeus), it will find it in the Antivirus memory. The workaround will be to safely whitelist all antiviruses process, and never scan them for signatures, which will be in next release.<\/p>\n\n\n\n<p>In clear: If ONLY your antivirus is detected, ignore it. If more processes are infected (like explorer.exe, etc&#8230;) then you&#8217;re probably infected.<\/p>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\"><br>Analysis<\/h4>\n\n\n\n<p><strong>Zeus is a malware with banking\/stealer features<\/strong>. The payload (malware file) is <strong>injected into several legit processes, even maybe in your antivirus<\/strong>, and loaded at boot time by a RUN key calling the injector. <strong>The Malware is injected into some legit processes (including explorer.exe) within an executable section<\/strong>, outside of any module. It can be found by looking at the sections with E\/X rights, but with no physical DLL.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/processhacker2.png\"><img decoding=\"async\" width=\"1339\" height=\"627\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/processhacker2.png\" alt=\"processhacker2\" class=\"wp-image-267\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/processhacker2.png 1339w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/processhacker2-300x140.png 300w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/processhacker2-1024x479.png 1024w\" sizes=\"(max-width: 1339px) 100vw, 1339px\" \/><\/a><\/figure>\n\n\n\n<p>Once payload loaded in into a process, it behaves differently according to the name of the process. For a lambda process, it will hook several APIs, to <strong>monitor process creation and module loading<\/strong>. When a new process is loaded it attempts to inject it too, so that it becomes really hard to clean the memory. <\/p>\n\n\n\n<p>It also starts a watchdog thread that will rewrite the RUN value every 200ms. It becomes now really hard to remove it from the startup.<\/p>\n\n\n\n<figure class=\"wp-block-image alignnone\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/olly_hook.png\"><img decoding=\"async\" width=\"674\" height=\"420\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/olly_hook.png\" alt=\"inline hook of APIs\" class=\"wp-image-265\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/olly_hook.png 674w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/olly_hook-300x187.png 300w\" sizes=\"(max-width: 674px) 100vw, 674px\" \/><\/a><figcaption class=\"wp-element-caption\">inline hook of APIs<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image alignnone\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/xuetr.png\"><img decoding=\"async\" width=\"794\" height=\"476\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/xuetr.png\" alt=\"inline hooks\" class=\"wp-image-269\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/xuetr.png 794w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/xuetr-300x180.png 300w\" sizes=\"(max-width: 794px) 100vw, 794px\" \/><\/a><figcaption class=\"wp-element-caption\">inline hooks<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image alignnone\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/apimon1-1.png\"><img decoding=\"async\" width=\"1628\" height=\"826\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/apimon1-1.png\" alt=\"Registry watchdog\" class=\"wp-image-263\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/apimon1-1.png 1628w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/apimon1-1-300x152.png 300w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/apimon1-1-1024x520.png 1024w\" sizes=\"(max-width: 1628px) 100vw, 1628px\" \/><\/a><figcaption class=\"wp-element-caption\">Registry watchdog<\/figcaption><\/figure>\n\n\n\n<p>For a web browser process, it will also <strong>hook several Wininet APIs<\/strong> (for Internet Explorer), or some other APIs for Chrome\/Firefox.<\/p>\n\n\n\n<p>Now the malware is able to <strong>filter internet communications<\/strong>, and overall <strong>inject HTML\/Javascript code into the browser (man-in-the-middle attack)<\/strong>, depending on what website you are on (Bank, Paypal, &#8230;), to send your credit card informations or credentials to the attacker. <\/p>\n\n\n\n<p>Some variants are also able to detect and <strong>inject FTP\/Email processes (like FileZilla, Outlook) to steal credentials and propagate on webservers (with FTP) or by email.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-image alignnone\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/BWsUVMcCQAA7_7q.png-large.png\"><img decoding=\"async\" width=\"1023\" height=\"913\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/BWsUVMcCQAA7_7q.png-large.png\" alt=\"Web inject - Courtesy of Xylitol (http:\/\/www.xylibox.com\/)\" class=\"wp-image-264\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/BWsUVMcCQAA7_7q.png-large.png 1023w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/BWsUVMcCQAA7_7q.png-large-300x268.png 300w\" sizes=\"(max-width: 1023px) 100vw, 1023px\" \/><\/a><figcaption class=\"wp-element-caption\">Web inject &#8211; Courtesy of Xylitol (http:\/\/www.xylibox.com\/)<\/figcaption><\/figure>\n\n\n\n<p>The payload contains also several interesting strings, including a blacklist of antiviruses names, and a very famous string <a href=\"http:\/\/krebsonsecurity.com\/tag\/coded-by-brian-krebs-for-personal-use-only-i-love-my-job-and-my-wife\/\">about Brian Krebs (a security researcher)<\/a>.<\/p>\n\n\n\n<figure class=\"wp-block-image alignnone\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/payload_blacklist.png\"><img decoding=\"async\" width=\"535\" height=\"403\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/payload_blacklist.png\" alt=\"antivirus names blacklist\" class=\"wp-image-266\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/payload_blacklist.png 535w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/payload_blacklist-300x226.png 300w\" sizes=\"(max-width: 535px) 100vw, 535px\" \/><\/a><figcaption class=\"wp-element-caption\">antivirus names blacklist<\/figcaption><\/figure>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/fun.png\"><img decoding=\"async\" width=\"525\" height=\"143\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/fun.png\" alt=\"fun\" class=\"wp-image-270\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/fun.png 525w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/fun-300x82.png 300w\" sizes=\"(max-width: 525px) 100vw, 525px\" \/><\/a><\/figure>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\"><br>Removal<\/h4>\n\n\n\n<p><strong>Starting with release 10.0.4, <a href=\"https:\/\/www.adlice.com\/roguekiller\/\">RogueKiller is able to automatically remove<\/a> that trojan.<\/strong> Simply scan your computer and remove infected keys.<\/p>\n\n\n\n<figure class=\"wp-block-image\"><a href=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/rk1-1.png\"><img decoding=\"async\" width=\"811\" height=\"635\" src=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/rk1-1.png\" alt=\"rk1\" class=\"wp-image-268\" srcset=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/rk1-1.png 811w, https:\/\/www.adlice.com\/wp-content\/uploads\/2016\/06\/rk1-1-300x235.png 300w\" sizes=\"(max-width: 811px) 100vw, 811px\" \/><\/a><\/figure>\n\n\n\n<p><strong>Your reports should look like this (with your own language text):<\/strong><\/p>\n\n\n\n<pre class=\"wp-block-code lang:default decode:true\"><code>\u00a4\u00a4\u00a4 Processus : 5 \u00a4\u00a4\u00a4\n&#91;Tr.Zeus] explorer.exe -- C:\\WINDOWS\\Explorer.EXE&#91;7] -&amp;gt; Tu\u00e9(e) &#91;TermProc]\n&#91;Tr.Zeus] VBoxTray.exe -- C:\\WINDOWS\\system32\\VBoxTray.exe&#91;7] -&amp;gt; Tu\u00e9(e) &#91;TermProc]\n&#91;Tr.Zeus] ctfmon.exe -- C:\\WINDOWS\\system32\\ctfmon.exe&#91;7] -&amp;gt; Tu\u00e9(e) &#91;TermProc]\n&#91;Tr.Zeus] procexp.exe -- C:\\Program Files\\ProcessEXP\\procexp.exe&#91;7] -&amp;gt; Tu\u00e9(e) &#91;TermProc]\n&#91;Tr.Zeus] IEXPLORE.EXE -- C:\\Program Files\\Internet Explorer\\IEXPLORE.EXE&#91;7] -&amp;gt; Tu\u00e9(e) &#91;TermProc]\n\n\u00a4\u00a4\u00a4 Registre : 1 \u00a4\u00a4\u00a4\n&#91;Suspicious.Path] HKEY_USERS\\S-1-5-21-823518204-842925246-839522115-1003\\Software\\Microsoft\\Windows\\CurrentVersion\\Run | Dyuwso : \"C:\\Documents and Settings\\tigzy\\Application Data\\Evsi\\qykeu.exe\" &#91;-] -&amp;gt; Supprim\u00e9(e)<\/code><\/pre>\n\n\n\n<p><br><strong>A demo of the removal is available here: <\/strong><\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe title=\"Zeus Citadel removal with RogueKIller\" width=\"1200\" height=\"675\" src=\"https:\/\/www.youtube.com\/embed\/QIx7PD5tpCY?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<h4 class=\"has-accent-color has-text-color wp-block-heading\"><br>Links<\/h4>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a title=\"Citadel analysis\" href=\"http:\/\/www.arbornetworks.com\/threats\/citadel.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">http:\/\/www.arbornetworks.com\/threats\/citadel.pdf<\/a><\/li>\n\n\n\n<li><a href=\"http:\/\/seifreed.es\/docs\/Citadel%20Trojan%20Report_eng.pdf\" target=\"_blank\" rel=\"noopener noreferrer\">http:\/\/seifreed.es\/docs\/Citadel%20Trojan%20Report_eng.pdf<\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Got infected with Zeus (Zbot) Banker? Follow this step by step guide to get rid of it. Our guide also includes a short analysis of the malware.<\/p>\n","protected":false},"author":1,"featured_media":271,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[103],"tags":[124,121,107,150,8,152,48,106,122,123],"class_list":["post-262","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-guide","tag-bank","tag-banker","tag-guide","tag-injection","tag-malware","tag-payload","tag-removal","tag-roguekiller","tag-zbot","tag-zeus","category-103","description-off"],"views":21622,"yoast_score":69,"yoast_readable":30,"featured_image_src":"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg","author_info":{"display_name":"tigzy","author_link":"https:\/\/www.adlice.com\/es\/author\/tigzy\/"},"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>How to Remove Zeus (Guide) | Zbot Banker \u2022 Adlice Software<\/title>\n<meta name=\"description\" content=\"Got infected with Zeus (Zbot) Banker? Follow this step by step guide to get rid of it. Analysis &amp; Removal.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.adlice.com\/remove-zeus\/\" \/>\n<meta property=\"og:locale\" content=\"es_ES\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"How to Remove Zeus (Guide) | Zbot Banker \u2022 Adlice Software\" \/>\n<meta property=\"og:description\" content=\"Got infected with Zeus (Zbot) Banker? Follow this step by step guide to get rid of it. Analysis &amp; Removal.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.adlice.com\/remove-zeus\/\" \/>\n<meta property=\"og:site_name\" content=\"Adlice Software\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/RogueKiller\" \/>\n<meta property=\"article:published_time\" content=\"2014-10-29T09:06:12+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2022-12-21T10:39:25+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1317\" \/>\n\t<meta property=\"og:image:height\" content=\"786\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"tigzy\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@AdliceSoftware\" \/>\n<meta name=\"twitter:site\" content=\"@AdliceSoftware\" \/>\n<meta name=\"twitter:label1\" content=\"Escrito por\" \/>\n\t<meta name=\"twitter:data1\" content=\"tigzy\" \/>\n\t<meta name=\"twitter:label2\" content=\"Tiempo de lectura\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutos\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.adlice.com\/remove-zeus\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.adlice.com\/remove-zeus\/\"},\"author\":{\"name\":\"tigzy\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d\"},\"headline\":\"How to Remove Zeus (Guide)\",\"datePublished\":\"2014-10-29T09:06:12+00:00\",\"dateModified\":\"2022-12-21T10:39:25+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.adlice.com\/remove-zeus\/\"},\"wordCount\":479,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.adlice.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.adlice.com\/remove-zeus\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg\",\"keywords\":[\"bank\",\"banker\",\"guide\",\"injection\",\"malware\",\"payload\",\"removal\",\"roguekiller\",\"zbot\",\"zeus\"],\"articleSection\":[\"Guide\"],\"inLanguage\":\"es\"},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.adlice.com\/remove-zeus\/\",\"url\":\"https:\/\/www.adlice.com\/remove-zeus\/\",\"name\":\"How to Remove Zeus (Guide) | Zbot Banker \u2022 Adlice Software\",\"isPartOf\":{\"@id\":\"https:\/\/www.adlice.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.adlice.com\/remove-zeus\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.adlice.com\/remove-zeus\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg\",\"datePublished\":\"2014-10-29T09:06:12+00:00\",\"dateModified\":\"2022-12-21T10:39:25+00:00\",\"description\":\"Got infected with Zeus (Zbot) Banker? Follow this step by step guide to get rid of it. Analysis & Removal.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.adlice.com\/remove-zeus\/#breadcrumb\"},\"inLanguage\":\"es\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.adlice.com\/remove-zeus\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\/\/www.adlice.com\/remove-zeus\/#primaryimage\",\"url\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg\",\"contentUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg\",\"width\":1317,\"height\":786},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.adlice.com\/remove-zeus\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.adlice.com\/es\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"How to Remove Zeus (Guide)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.adlice.com\/#website\",\"url\":\"https:\/\/www.adlice.com\/\",\"name\":\"Adlice Software\",\"description\":\"Anti-malware and analysis tools\",\"publisher\":{\"@id\":\"https:\/\/www.adlice.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.adlice.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"es\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.adlice.com\/#organization\",\"name\":\"Adlice Software\",\"url\":\"https:\/\/www.adlice.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png\",\"contentUrl\":\"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png\",\"width\":276,\"height\":276,\"caption\":\"Adlice Software\"},\"image\":{\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/RogueKiller\",\"https:\/\/x.com\/AdliceSoftware\",\"https:\/\/fr.linkedin.com\/company\/adlice-software\",\"https:\/\/www.youtube.com\/channel\/UC4CQ-gIZMGWxl-auf0QqYhQ\"]},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d\",\"name\":\"tigzy\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"es\",\"@id\":\"https:\/\/www.adlice.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g\",\"caption\":\"tigzy\"},\"description\":\"Founder and owner of Adlice Software, Tigzy started as lead developer on the popular Anti-malware called RogueKiller. Involved in all the Adlice projects as lead developer, Tigzy is also doing research and reverse engineering as well as writing blog posts.\",\"url\":\"https:\/\/www.adlice.com\/es\/author\/tigzy\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"How to Remove Zeus (Guide) | Zbot Banker \u2022 Adlice Software","description":"Got infected with Zeus (Zbot) Banker? Follow this step by step guide to get rid of it. Analysis & Removal.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.adlice.com\/remove-zeus\/","og_locale":"es_ES","og_type":"article","og_title":"How to Remove Zeus (Guide) | Zbot Banker \u2022 Adlice Software","og_description":"Got infected with Zeus (Zbot) Banker? Follow this step by step guide to get rid of it. Analysis & Removal.","og_url":"https:\/\/www.adlice.com\/remove-zeus\/","og_site_name":"Adlice Software","article_publisher":"https:\/\/www.facebook.com\/RogueKiller","article_published_time":"2014-10-29T09:06:12+00:00","article_modified_time":"2022-12-21T10:39:25+00:00","og_image":[{"width":1317,"height":786,"url":"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg","type":"image\/jpeg"}],"author":"tigzy","twitter_card":"summary_large_image","twitter_creator":"@AdliceSoftware","twitter_site":"@AdliceSoftware","twitter_misc":{"Escrito por":"tigzy","Tiempo de lectura":"4 minutos"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.adlice.com\/remove-zeus\/#article","isPartOf":{"@id":"https:\/\/www.adlice.com\/remove-zeus\/"},"author":{"name":"tigzy","@id":"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d"},"headline":"How to Remove Zeus (Guide)","datePublished":"2014-10-29T09:06:12+00:00","dateModified":"2022-12-21T10:39:25+00:00","mainEntityOfPage":{"@id":"https:\/\/www.adlice.com\/remove-zeus\/"},"wordCount":479,"commentCount":0,"publisher":{"@id":"https:\/\/www.adlice.com\/#organization"},"image":{"@id":"https:\/\/www.adlice.com\/remove-zeus\/#primaryimage"},"thumbnailUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg","keywords":["bank","banker","guide","injection","malware","payload","removal","roguekiller","zbot","zeus"],"articleSection":["Guide"],"inLanguage":"es"},{"@type":"WebPage","@id":"https:\/\/www.adlice.com\/remove-zeus\/","url":"https:\/\/www.adlice.com\/remove-zeus\/","name":"How to Remove Zeus (Guide) | Zbot Banker \u2022 Adlice Software","isPartOf":{"@id":"https:\/\/www.adlice.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.adlice.com\/remove-zeus\/#primaryimage"},"image":{"@id":"https:\/\/www.adlice.com\/remove-zeus\/#primaryimage"},"thumbnailUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg","datePublished":"2014-10-29T09:06:12+00:00","dateModified":"2022-12-21T10:39:25+00:00","description":"Got infected with Zeus (Zbot) Banker? Follow this step by step guide to get rid of it. Analysis & Removal.","breadcrumb":{"@id":"https:\/\/www.adlice.com\/remove-zeus\/#breadcrumb"},"inLanguage":"es","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.adlice.com\/remove-zeus\/"]}]},{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/www.adlice.com\/remove-zeus\/#primaryimage","url":"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg","contentUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2014\/10\/malware.jpg","width":1317,"height":786},{"@type":"BreadcrumbList","@id":"https:\/\/www.adlice.com\/remove-zeus\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.adlice.com\/es\/"},{"@type":"ListItem","position":2,"name":"How to Remove Zeus (Guide)"}]},{"@type":"WebSite","@id":"https:\/\/www.adlice.com\/#website","url":"https:\/\/www.adlice.com\/","name":"Adlice Software","description":"Anti-malware and analysis tools","publisher":{"@id":"https:\/\/www.adlice.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.adlice.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"es"},{"@type":"Organization","@id":"https:\/\/www.adlice.com\/#organization","name":"Adlice Software","url":"https:\/\/www.adlice.com\/","logo":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png","contentUrl":"https:\/\/www.adlice.com\/wp-content\/uploads\/2020\/05\/B1rTNpTG_400x40_10.png","width":276,"height":276,"caption":"Adlice Software"},"image":{"@id":"https:\/\/www.adlice.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/RogueKiller","https:\/\/x.com\/AdliceSoftware","https:\/\/fr.linkedin.com\/company\/adlice-software","https:\/\/www.youtube.com\/channel\/UC4CQ-gIZMGWxl-auf0QqYhQ"]},{"@type":"Person","@id":"https:\/\/www.adlice.com\/#\/schema\/person\/a02b30804320a4059d268dc2567a307d","name":"tigzy","image":{"@type":"ImageObject","inLanguage":"es","@id":"https:\/\/www.adlice.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d81e380961b1b69969fa84994ad1e4cba26afe93a49d8dd3148e9c33ffe4ccac?s=96&d=mm&r=g","caption":"tigzy"},"description":"Founder and owner of Adlice Software, Tigzy started as lead developer on the popular Anti-malware called RogueKiller. Involved in all the Adlice projects as lead developer, Tigzy is also doing research and reverse engineering as well as writing blog posts.","url":"https:\/\/www.adlice.com\/es\/author\/tigzy\/"}]}},"_links":{"self":[{"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/posts\/262","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/comments?post=262"}],"version-history":[{"count":0,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/posts\/262\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/media\/271"}],"wp:attachment":[{"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/media?parent=262"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/categories?post=262"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.adlice.com\/es\/wp-json\/wp\/v2\/tags?post=262"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}