Malware

Mal/ZAccess-BL removal tips

Malware Removal

The Mal/ZAccess-BL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/ZAccess-BL virus can do?

  • At least one process apparently crashed during execution
  • Dynamic (imported) function loading detected
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Mal/ZAccess-BL?


File Info:

name: 880CFB61DFD7533036EF.mlw
path: /opt/CAPEv2/storage/binaries/7d95be33a32293ae07469366ca21be0f503ae10cc0f36fde211ec457e83ca208
crc32: 8C69236D
md5: 880cfb61dfd7533036ef458232f4e79b
sha1: f1a9e10759767838d93620e74312d8ff5a60fd23
sha256: 7d95be33a32293ae07469366ca21be0f503ae10cc0f36fde211ec457e83ca208
sha512: 5b6472341825cf51848cedaf0d270bf85c41571b760d5fda320f0eed550c928957e1630553595d83470078995867706e025d07e99360d23a7c073f314184eaa5
ssdeep: 3072:gk1Rfi9mSCzym/hdby7eK4v61ZBtRUC3:PRqQSEy2E661Z/e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4B312AFD1AC1206D1643470D902BCCED964BF293368B653DE3451162E3A188D7A3FBB
sha3_384: 5b4827961da66efb8c1cb5d455b890843a24a14ad8b57358acf9071440dd3c79f8743a51980487448ae55b4ce26cb33a
ep_bytes: 60be003043008dbe00e0fcff57eb0b90
timestamp: 2014-06-06 09:15:37

Version Info:

Comments:
CompanyName: CdD
FileDescription: DHL
FileVersion: 1, 0, 0, 1
InternalName: DHLa
LegalCopyright: Ccjaoij
LegalTrademarks:
OriginalFilename: DHLA.dll
PrivateBuild:
ProductName: wdq
ProductVersion: 1, 0, 0, 1
SpecialBuild:
Translation: 0x0406 0x04b0

Mal/ZAccess-BL also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47514193
McAfeeRDN/Generic BackDoor
CylanceUnsafe
K7AntiVirusRiskware ( 00584baa1 )
AlibabaBackdoor:Win32/ZAccess.2188c3eb
K7GWRiskware ( 00584baa1 )
SymantecML.Attribute.HighConfidence
APEXMalicious
BitDefenderTrojan.GenericKD.47514193
AvastWin32:Malware-gen
Ad-AwareTrojan.GenericKD.47514193
SophosMal/ZAccess-BL
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRDN/Generic BackDoor
FireEyeGeneric.mg.880cfb61dfd75330
EmsisoftTrojan.GenericKD.47514193 (B)
IkarusTrojan-Clicker.Win32.NetBuie.H
GDataTrojan.GenericKD.47514193
JiangminBackdoor/Farfli.hh
WebrootW32.Malware.Gen
AviraHEUR/AGEN.1104806
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Generic.D2D50251
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 99)
AhnLab-V3Backdoor/Win32.Zegost.C409744
ALYacTrojan.GenericKD.47514193
MAXmalware (ai score=80)
YandexTrojan.GenAsa!2bH2k548rLM
SentinelOneStatic AI – Suspicious PE
eGambitUnsafe.AI_Score_99%
BitDefenderThetaGen:NN.ZexaF.34084.gm0@a0i1criH
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_60% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Mal/ZAccess-BL?

Mal/ZAccess-BL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment