Trojan

Dropped:Trojan.Zbot.IVF removal guide

Malware Removal

The Dropped:Trojan.Zbot.IVF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Dropped:Trojan.Zbot.IVF virus can do?

  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to connect to a dead IP:Port (6 unique times)
  • ‘Dropbox’ in HTML Title but connection is not HTTPS. Possibly indicative of phishing.
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Turkish
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
xred.mooo.com
freedns.afraid.org
ocsp.pki.goog
doc-14-14-docs.googleusercontent.com
www.dropbox.com
ocsp.digicert.com
xred.site50.net
www.000webhost.com
ocsp.comodoca.com
ocsp.usertrust.com

How to determine Dropped:Trojan.Zbot.IVF?


File Info:

crc32: 9ACDAFEA
md5: 7bdadc39495885ad59a1fcf8b96982fb
name: 7BDADC39495885AD59A1FCF8B96982FB.mlw
sha1: 2c6f5fa1c64386b7eb64b55949d84ac61b2aa36e
sha256: 18ebeb72f570de64c880540d98e9043fd6fca061732f92793349f9083669a682
sha512: b62f4663c7b3875ea73d4cdd8e653a454952655e86a960613f44280fe23f2df30cbdbb3ddd48a6a93d0f158cc272ceaaafafa50e4c0e16a906ef51b6c22546ab
ssdeep: 12288:6MSApJVYG5lDLyjsb0eOzkv4R7QnvUUilQ35+6G75V9P8kvoj:6nsJ39LyjbJkQFMhmC+6GD9HI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
InternalName:
FileVersion: 1.0.0.4
CompanyName: Synaptics
LegalTrademarks:
Comments:
ProductName: Synaptics Pointing Device Driver
ProductVersion: 1.0.0.0
FileDescription: Synaptics Pointing Device Driver
OriginalFilename:
Translation: 0x041f 0x04e6

Dropped:Trojan.Zbot.IVF also known as:

BkavW32.FamVT.GaionLTK.Trojan
K7AntiVirusVirus ( 0055903c1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader22.9658
CynetMalicious (score: 100)
CAT-QuickHealSus.Nocivo.E0011
ALYacDropped:Trojan.Zbot.IVF
CylanceUnsafe
ZillyaTrojan.Delf.Win32.76144
SangforWin.Malware.Delf-6899401-0
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0056a6201 )
Cybereasonmalicious.949588
BaiduWin32.Trojan.Ramnit.e
CyrenW32/Backdoor.OAZM-5661
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Delf.NBX
ZonerTrojan.Win32.88102
APEXMalicious
AvastWin32:GenMalicious-GOW [Trj]
ClamAVWin.Trojan.Generic-53
KasperskyBackdoor.Win32.DarkKomet.hqxy
BitDefenderDropped:Trojan.Zbot.IVF
NANO-AntivirusTrojan.Win32.DarkKomet.fazbwq
ViRobotWin32.Zorex.A
SUPERAntiSpywareAdware.FileTour/Variant
MicroWorld-eScanDropped:Trojan.Zbot.IVF
TencentVirus.Win32.DarkKomet.a
Ad-AwareDropped:Trojan.Zbot.IVF
SophosTroj/DocDl-JJH
ComodoVirus.Win32.Agent.DE@74b38h
BitDefenderThetaAI:Packer.F5AF03D517
VIPREWorm.Win32.AutoRun
TrendMicroVirus.Win32.NAPWHICH.B
McAfee-GW-EditionBehavesLike.Win32.Generic.ch
FireEyeGeneric.mg.7bdadc39495885ad
EmsisoftDropped:Trojan.Zbot.IVF (B)
SentinelOneStatic AI – Malicious PE
JiangminWin32/Synaptics.Gen
AviraTR/Crypt.XPACK.AB.1
eGambitUnsafe.AI_Score_100%
Antiy-AVLTrojan/Generic.ASMalwS.73E9E
MicrosoftWorm:Win32/AutoRun!atmn
GridinsoftMalware.Win32.Gen.sm!s1
ArcabitHEUR.VBA.Trojan.d
ZoneAlarmHEUR:Trojan-Downloader.Script.Generic
GDataWin32.Backdoor.Agent.AXS
TACHYONBackdoor/W32.DP-DarkKomet.827904.B
AhnLab-V3Win32/Zorex.X1799
Acronissuspicious
McAfeeGenericRXMS-UK!7BDADC394958
MAXmalware (ai score=82)
VBA32TScope.Trojan.Delf
MalwarebytesLamer.Virus.FileInfector.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallVirus.Win32.NAPWHICH.B
RisingBackdoor.Agent!1.BF3D (RDMK:cmRtazpQnSIvXTgdYNOq+Oh4GmQD)
YandexTrojan.GenAsa!ETONJRQzPLk
IkarusTrojan-Downloader.VBA.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/CoinMiner.NBX!tr
AVGWin32:GenMalicious-GOW [Trj]

How to remove Dropped:Trojan.Zbot.IVF?

Dropped:Trojan.Zbot.IVF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment