Malware

Mal/Generic-R + Troj/Zbot-DPP malicious file

Malware Removal

The Mal/Generic-R + Troj/Zbot-DPP is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-R + Troj/Zbot-DPP virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Creates a hidden or system file
  • Collects information to fingerprint the system

How to determine Mal/Generic-R + Troj/Zbot-DPP?


File Info:

name: 9F787AB020324F3E97FE.mlw
path: /opt/CAPEv2/storage/binaries/d32c182b04fb728b19b64abebb292d2b2527f776d2f9d0f39d4fceabbb04a5bf
crc32: 82AA80DD
md5: 9f787ab020324f3e97fed1dff945fcb9
sha1: ce24d8214b0172a7e2c7ff92045f48a9d24ef265
sha256: d32c182b04fb728b19b64abebb292d2b2527f776d2f9d0f39d4fceabbb04a5bf
sha512: 039e4dae05f3f82c239123d3996e3796fa8e54305adcdd7459f99d4f47e716b02ef3f55397d45f3827ba9e25e0d4431f66e18606ede127a98dfc3678996dcfda
ssdeep: 6144:POt9muK7K47+46NvC24o3VO7fy9JTb1CFZL4w9rG8FzayScUq:68HK47+M2lmZp9rp3ScUq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17F64F120A4E50DA7EC7EFD7ADAF2D59CAE19D6B31F56408A9071060CDCD360399D22E3
sha3_384: cfefa4b85ab598e5a330463f2ce947f99c20cf23fbcbb75fcc1ddd46cbf315951afdef6922da0d2519e0674e08b0cf5a
ep_bytes: 558bec68007f00006a00ff1550504000
timestamp: 2013-01-17 12:00:13

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Windows Setup Utility
FileVersion: 9.00.00.4503
InternalName: a6ize
LegalCopyright: (C) Microsoft Corporation. All rights reserved.
OriginalFilename: a6ize
ProductName: Microsoft(R) Windows Media Player
ProductVersion: 9.00.00.4503
Translation: 0x0409 0x04b0

Mal/Generic-R + Troj/Zbot-DPP also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lIty
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.3414
CynetMalicious (score: 100)
FireEyeGeneric.mg.9f787ab020324f3e
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Variant.Symmi.15290
CylanceUnsafe
VIPRETrojan.Win32.Agent.akm (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0040f0ce1 )
AlibabaTrojanPSW:Win32/Karagany.3c001f5c
K7GWTrojan-Downloader ( 0040f0ce1 )
Cybereasonmalicious.020324
BitDefenderThetaGen:NN.ZexaF.34212.tm2@aqWJ3yqi
VirITTrojan.Win32.Banker.QL
CyrenW32/Zbot.HS.gen!Eldorado
SymantecTrojan.Zbot!g38
ESET-NOD32Win32/Spy.Zbot.AAU
TrendMicro-HouseCallTROJ_SIGEKAF.SM
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-69637
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.15290
NANO-AntivirusTrojan.Win32.Zbot.covkqz
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
MicroWorld-eScanGen:Variant.Symmi.15290
AvastWin32:DangerousSig [Trj]
TencentMalware.Win32.Gencirc.10b9fe0e
Ad-AwareGen:Variant.Symmi.15290
EmsisoftGen:Variant.Symmi.15290 (B)
ComodoTrojWare.Win32.Spy.ZBot.EB@4uei1b
ZillyaTrojan.Zbot.Win32.97958
TrendMicroTROJ_SIGEKAF.SM
McAfee-GW-EditionPWS-Zbot.gen.aua
SophosMal/Generic-R + Troj/Zbot-DPP
IkarusTrojan.Signed
GDataGen:Variant.Symmi.15290
JiangminTrojanSpy.Zbot.cvuo
WebrootW32.Infostealer.Zeus
AviraTR/PSW.Zbot.fio
Antiy-AVLTrojan/Generic.ASMalwS.13BBEC
KingsoftWin32.Troj.Zbot.ig.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot!GO
AhnLab-V3Win-Trojan/Zbot.316040
Acronissuspicious
McAfeePWS-Zbot.gen.aua
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Shade
APEXMalicious
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!vcCgczD9Bdc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Zbot.AAU!tr
AVGWin32:DangerousSig [Trj]
PandaTrj/Hexas.HEU
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Mal/Generic-R + Troj/Zbot-DPP?

Mal/Generic-R + Troj/Zbot-DPP removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment