Malware

Mal/Generic-S + Mal/Zbot-UU (file analysis)

Malware Removal

The Mal/Generic-S + Mal/Zbot-UU is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Generic-S + Mal/Zbot-UU virus can do?

  • Executable code extraction
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Mal/Generic-S + Mal/Zbot-UU?


File Info:

crc32: C480BE1F
md5: 149c60700ce8c694bd483622a1c37999
name: 149C60700CE8C694BD483622A1C37999.mlw
sha1: 6a6fda0b420afe7af5934ca6a9e6db4b01e70d1a
sha256: 23839deed2b46d545f61e0c527fcf6aac3d90d2a2b2edff9ed4eb408912b7e86
sha512: 3170e2925ff425a4730249737f094c487a46b88878440e904ee7965edcefa2a11ace65571c1bdb3a18f0af6f215b50e7dcaeafc5b1d911251579b5bf3b5e64ab
ssdeep: 6144:72yB9vqp1dVHrpLm3efYzGKupLDoCrhmBDMHf6EhsLqyQJoZ9s7V:w1dVLp63efY4pVQESA
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa92013 LogiGear Brought, Inc. All Rights Reserved
InternalName: Properthird.exe
FileVersion: 1.1.74.74
CompanyName: LogiGear Brought
ProductName: Properthird
ProductVersion: 1.1.74.74
FileDescription: Properthird
Translation: 0x0409 0x04e4

Mal/Generic-S + Mal/Zbot-UU also known as:

K7AntiVirusTrojan ( 0053df611 )
LionicTrojan.Win32.Ursnif.4!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader27.7217
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Agent.S3889117
ALYacTrojan.Agent.DFTP
CylanceUnsafe
ZillyaTrojan.Ursnif.Win32.2523
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojanSpy:Win32/Ursnif.f922f0e1
K7GWTrojan ( 0053df611 )
Cybereasonmalicious.00ce8c
CyrenW32/S-ff0becab!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GLIE
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Dftp-6706182-0
KasperskyTrojan-Spy.Win32.Ursnif.aacs
BitDefenderTrojan.Agent.DFTP
NANO-AntivirusTrojan.Win32.GenKryptik.finhwu
MicroWorld-eScanTrojan.Agent.DFTP
TencentMalware.Win32.Gencirc.10b10d3c
Ad-AwareTrojan.Agent.DFTP
SophosMal/Generic-S + Mal/Zbot-UU
ComodoTrojWare.Win32.Agent.ZDN@7vtnrb
BitDefenderThetaGen:NN.ZexaF.34294.Rq0@aqmeEfoi
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojanSpy.Win32.URSNIF.SMKA0.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
FireEyeGeneric.mg.149c60700ce8c694
EmsisoftTrojan.Agent.DFTP (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanSpy.Ursnif.bor
AviraHEUR/AGEN.1122921
Antiy-AVLTrojan/Generic.ASMalwS.284575B
MicrosoftTrojanSpy:Win32/Ursnif
ArcabitTrojan.Agent.DFTP
GDataTrojan.Agent.DFTP
TACHYONTrojan/W32.Agent.708608.XV
AhnLab-V3Trojan/Win.Emotet.R437444
Acronissuspicious
McAfeeTrojan-FQEW!149C60700CE8
MAXmalware (ai score=100)
VBA32TrojanSpy.Ursnif
MalwarebytesTrojan.MalPack
PandaTrj/Genetic.gen
TrendMicro-HouseCallTrojanSpy.Win32.URSNIF.SMKA0.hp
RisingTrojan.Generic@ML.90 (RDML:wXf5J96luWIidG/aYQE3iw)
YandexTrojan.GenAsa!pJtKp8q+8v8
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GenKryptik.DVLO!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove Mal/Generic-S + Mal/Zbot-UU?

Mal/Generic-S + Mal/Zbot-UU removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment