Malware

Mal/Generic-R + Troj/Zbot-DGC removal tips

Malware Removal

The Mal/Generic-R + Troj/Zbot-DGC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Zbot-DGC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Mal/Generic-R + Troj/Zbot-DGC?


File Info:

name: BC505E6A179EE8DE453B.mlw
path: /opt/CAPEv2/storage/binaries/f13dfefbd7ac3dd2da8d1d9e9d78791c5c0b8ee6940a1e22ca22dad2f7e00ad9
crc32: A0AFB48E
md5: bc505e6a179ee8de453b060c7ede0732
sha1: 7c52cf10fad0e9ce555bb185eee5ce1d122c5daf
sha256: f13dfefbd7ac3dd2da8d1d9e9d78791c5c0b8ee6940a1e22ca22dad2f7e00ad9
sha512: 843bf92a9432b968ede5394b6f384dffeb9bb1508c6eb494fb1fe7655e0728b8b48dbac25d190dc0cb4d49982fa22f6c086a36bb55c76ab3a116d3fe1db4613a
ssdeep: 12288:wykqwlzm+C5IxJ845HYV5sxOH/ccccccce7liPX:wvl2av84a5sxH
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D2A4CF42EC176823FC9B55FF1022549A0D3BEEA65638C4F674C4971E67FC06B39A027A
sha3_384: 4d1f8966d0ddccf57527916bd22f58fdb6e46d4dc9c547d7fd30fa5d34fbd3cae23a24634271dd329e7824a7268d87bc
ep_bytes: 558bec892dd8384600e8e2fcffff5dc3
timestamp: 2012-12-11 12:09:49

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Мастер создания общих ресурсов
FileVersion: 5.1.2600.5512 (xpsp.080413-2108)
InternalName: SHRWIZ
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: shrpubw.exe
ProductName: Операционная система Microsoft® Windows®
ProductVersion: 5.1.2600.5512
Translation: 0x0419 0x04b0

Mal/Generic-R + Troj/Zbot-DGC also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.FakeAlert.DBZ
FireEyeGeneric.mg.bc505e6a179ee8de
CAT-QuickHealTrojanPWS.Zbot.Gen
McAfeePWS-Zbot.gen.asq
CylanceUnsafe
VIPRETrojan.Win32.Zbot.ak (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f02a1 )
AlibabaTrojanPSW:Win32/Kryptik.e742dd22
K7GWTrojan ( 0040d0431 )
Cybereasonmalicious.a179ee
ArcabitTrojan.FakeAlert.DBZ
VirITTrojan.Win32.Banker.PP
CyrenW32/Zbot.GQ.gen!Eldorado
SymantecPacked.Generic.406
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
ClamAVWin.Virus.Zeus-9816753-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.FakeAlert.DBZ
NANO-AntivirusTrojan.Win32.Zbot.crsvzi
SUPERAntiSpywareTrojan.Agent/Gen-Zeus
AvastWin32:Agent-AQQL [Trj]
TencentMalware.Win32.Gencirc.10b3ec0a
Ad-AwareTrojan.FakeAlert.DBZ
TACHYONTrojan-Spy/W32.ZBot.456272
EmsisoftTrojan.FakeAlert.DBZ (B)
ComodoTrojWare.Win32.PWS.ZBot.ASY@4sonv8
DrWebTrojan.Packed.23728
ZillyaTrojan.Zbot.Win32.93737
TrendMicroTSPY_ZBOT.SM18
McAfee-GW-EditionPWS-Zbot.gen.asq
SophosMal/Generic-R + Troj/Zbot-DGC
IkarusTrojan-PWS.Win32.Zbot
JiangminTrojan/Generic.aqlon
WebrootW32.Infostealer.Zeus
AviraTR/Spy.Zbot.wweqra
Antiy-AVLTrojan[Spy]/Win32.Zbot
MicrosoftPWS:Win32/Zbot!GO
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataTrojan.FakeAlert.DBZ
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R44064
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.Bu2@aWZnQxmc
ALYacTrojan.FakeAlert.DBZ
MAXmalware (ai score=100)
VBA32BScope.Trojan.Cloxer
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTSPY_ZBOT.SM18
RisingSpyware.Zbot!8.16B (TFE:dGZlOgO0KqrHMCKr/g)
YandexTrojan.GenAsa!NPGa3cNv2ao
SentinelOneStatic AI – Malicious PE
FortinetW32/ZBOT.QT!tr
AVGWin32:Agent-AQQL [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Mal/Generic-R + Troj/Zbot-DGC?

Mal/Generic-R + Troj/Zbot-DGC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment