Malware

PWS:Win32/Zbot.AF!MTB (file analysis)

Malware Removal

The PWS:Win32/Zbot.AF!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Zbot.AF!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine PWS:Win32/Zbot.AF!MTB?


File Info:

name: 7605671BF33B4B968988.mlw
path: /opt/CAPEv2/storage/binaries/3c2615f6166fba3a54aefee241f48796fd672017619e9b1825b40d7cbe7ab1cd
crc32: 6DDB2659
md5: 7605671bf33b4b9689881003a6701dc8
sha1: 04ed16bb60811d79d7ca2756b918cc8fa822c312
sha256: 3c2615f6166fba3a54aefee241f48796fd672017619e9b1825b40d7cbe7ab1cd
sha512: ff0e0d43fddac5e3eb515098cb801af5b96920f7ea604b646c50148afc14adca83cbe6b20c1194054daa423d1bcf670a6e6b1ff6644518cc6d8717732c811e02
ssdeep: 1536:WZFJTafg3hnfq4yyFB1iRT9bPKzvcOZ70AKK:2FGgRfqIT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F0630F786FEA9532E3B7C6B685F655C6B871B4223C01984E50CF47884C23F17ADE261E
sha3_384: 5ce3741040e8287cc9ce9f044b3fae23c58a6d72a2634825d13127b69f441f54163b0ed63582a264a8d99858ba561c25
ep_bytes: e8da020000e956260000c340683f1800
timestamp: 2013-10-31 06:23:23

Version Info:

0: [No Data]

PWS:Win32/Zbot.AF!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28161
MicroWorld-eScanTrojan.GenericKD.38679867
FireEyeGeneric.mg.7605671bf33b4b96
ALYacTrojan.GenericKD.38679867
CylanceUnsafe
ZillyaTrojan.Generic.Win32.685490
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
AlibabaMalware:Win32/km_24dae4.None
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.bf33b4
BitDefenderThetaGen:NN.ZexaF.34182.eqY@aaxQBUmi
CyrenW32/S-a2a6ca5b!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Small.AAB
TrendMicro-HouseCallTROJ_GEN.R002C0DB122
Paloaltogeneric.ml
ClamAVWin.Downloader.Upatre-5744087-0
KasperskyUDS:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.38679867
NANO-AntivirusTrojan.Win32.Agent.cnfeqb
AvastWin32:Trojan-gen
TencentTrojan-Downloader.Win32.Waski.16000151
EmsisoftTrojan.GenericKD.38679867 (B)
ComodoTrojWare.Win32.TrojanDownloader.Upatre.AAL@5l06uw
VIPRETrojan.Win32.Zbot.gxb (v)
TrendMicroTROJ_GEN.R002C0DB122
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.kt
SophosML/PE-A + Troj/AutoG-AV
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Agent.ekgf
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=88)
Antiy-AVLTrojan[Downloader]/Win32.Agent
GridinsoftTrojan.Win32.Agent.bot!s1
MicrosoftPWS:Win32/Zbot.AF!MTB
ViRobotTrojan.Win32.Z.Zbot.68136
ZoneAlarmUDS:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.C3089037
McAfeePWSZbot-FIT!7605671BF33B
VBA32Trojan.Download
MalwarebytesTrojan.Upatre.Generic
APEXMalicious
RisingDownloader.Small!8.B41 (CLOUD)
YandexTrojan.GenAsa!TLH49nwyrkg
IkarusTrojan-PWS.Win32.Fareit
FortinetW32/Zbot.QMSC!tr
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove PWS:Win32/Zbot.AF!MTB?

PWS:Win32/Zbot.AF!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment