Malware

Should I remove “Mal/Zbot-MX”?

Malware Removal

The Mal/Zbot-MX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Zbot-MX virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Spanish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Collects information to fingerprint the system
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Mal/Zbot-MX?


File Info:

name: 8AE53FF6C949669FA50E.mlw
path: /opt/CAPEv2/storage/binaries/481fe537a9a054facb12a0b3dd76ffcade51527d5f4ba800d1e269499896aed8
crc32: A990B4A8
md5: 8ae53ff6c949669fa50e5a6da79301c7
sha1: db8eb778bfae62d234b4d97a98cb4412d6798da0
sha256: 481fe537a9a054facb12a0b3dd76ffcade51527d5f4ba800d1e269499896aed8
sha512: 7bd04b107ba28b2e67b69811b488070f29543a56b83039477e3e19128d9727caa51b0b37e544e4812b2c3c1ee9cdfdfe498acb768e472dc3971e250989fc33e6
ssdeep: 6144:i5+2BxAWURf/HNdJcUeDiI27zzl7FCSbGqJB:iE5WURf/HNjcTDX8zzl7FCSx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D0847A0D063788F2CCF5BCB089A27AB125390FDE5A0FA66B95517F3CDB791E29184346
sha3_384: cdce46282ce8f588a034d5f8c9a7d91c17d296d223556f4eb473bf6e50dd94155c0435ab2fc21ff1031f1340e28e6562
ep_bytes: 558bec83ec2856e844ffffff05151605
timestamp: 2013-07-25 18:02:41

Version Info:

CompanyName: Hilgraeve, Inc.
FileDescription: HyperTerminal Applet
FileVersion: 5.1.2600.0
Translation: 0x0409 0x0000

Mal/Zbot-MX also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Mods.1
MicroWorld-eScanTrojan.GenericKDZ.95265
ClamAVWin.Trojan.Agent-1362910
FireEyeGeneric.mg.8ae53ff6c949669f
ALYacTrojan.GenericKDZ.95265
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.Kryptik.Win32.3984739
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005110401 )
AlibabaMalware:Win32/km_2eafa.None
K7GWTrojan ( 005110401 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.36132.w41@aaWERIJi
CyrenW32/Zaccess.BD.gen!Eldorado
SymantecPacked.Generic.459
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.BCJR
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKDZ.95265
NANO-AntivirusTrojan.Win32.Mods.cqjowu
SUPERAntiSpywareAdware.Graftor/Variant
AvastWin32:Kryptik-MMY [Trj]
RisingTrojan.Kryptik!1.AB59 (CLASSIC)
EmsisoftTrojan.GenericKDZ.95265 (B)
F-SecureHeuristic.HEUR/AGEN.1324349
BaiduWin32.Trojan.Kryptik.as
VIPRETrojan.GenericKDZ.95265
TrendMicroTROJ_KRYPTK.SML3
McAfee-GW-EditionBehavesLike.Win32.Infected.fm
Trapminemalicious.high.ml.score
SophosMal/Zbot-MX
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKDZ.95265
JiangminTrojan/Generic.bbvdn
Webroot
AviraHEUR/AGEN.1324349
Antiy-AVLTrojan/Win32.ShipUp
XcitiumTrojWare.Win32.Kryptik.BFIV@5013ii
ArcabitTrojan.Generic.D17421
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Emotet.KDS!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Shipup.R73526
McAfeeZeroAccess-FBI!8AE53FF6C949
MAXmalware (ai score=86)
VBA32Malware-Cryptor.Bambarbiya
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTK.SML3
TencentMalware.Win32.Gencirc.10bdb94d
YandexTrojan.GenAsa!6KsMq3TTGsc
IkarusTrojan.Win32.Reveton
MaxSecureTrojan.ShipUp.gen
FortinetW32/Lockscreen.LOA!tr
AVGWin32:Kryptik-MMY [Trj]
DeepInstinctMALICIOUS

How to remove Mal/Zbot-MX?

Mal/Zbot-MX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment