Malware

About “PWS:Win32/Zbot.MU!MTB” infection

Malware Removal

The PWS:Win32/Zbot.MU!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/Zbot.MU!MTB virus can do?

  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Installs itself for autorun at Windows startup
  • Likely virus infection of existing system binary
  • Creates Zeus (Banking Trojan) mutexes

How to determine PWS:Win32/Zbot.MU!MTB?


File Info:

name: 87C61152B49C3B0D5AB8.mlw
path: /opt/CAPEv2/storage/binaries/3e38823885c09f085157c389675f5002776bafa2c732bf3dead11951c0824009
crc32: 5BDB82B9
md5: 87c61152b49c3b0d5ab85c89d5173b34
sha1: bac106e2f98f50cb1d91cd6eb3550811ccdb818f
sha256: 3e38823885c09f085157c389675f5002776bafa2c732bf3dead11951c0824009
sha512: 946cf4be33d435548f80f2f7db226fa58f3d0ecbb06c4fe5230f10001cc194e6e3293b767be0da936463b17d39d495847f2049391a0e6ea178d470a1b21d79ce
ssdeep: 1536:nBTtb6GpgRG/HP/CAutm4uwqdTVSXk0+ql3Lu:nBTtbhpgRG/vqAuHSxn0pK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T15B934BC2E2E28171F4BB56320571573FCA767D222637C05D67318A9E1F33754AA263A3
sha3_384: 7afa519e455c6ad02786637247ae729cc513790b9dbd67849ee256b2bc8f7fd061b776ac4ebd682a98311002dc54fbea
ep_bytes: 558bec81ec380400005356576a01e840
timestamp: 2007-06-09 04:42:04

Version Info:

0: [No Data]

PWS:Win32/Zbot.MU!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebDLOADER.Trojan
MicroWorld-eScanDropped:Generic.Malware.GJSFM6g.43C54843
FireEyeGeneric.mg.87c61152b49c3b0d
CAT-QuickHealTrojanpws.Zbot.29195
ALYacDropped:Generic.Malware.GJSFM6g.43C54843
MalwarebytesGeneric.Trojan.Obfuscator.DDS
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
BitDefenderThetaAI:Packer.EF179F771F
CyrenW32/Zbot.BS.gen!Eldorado
ESET-NOD32a variant of Win32/Spy.Agent.PZ
TrendMicro-HouseCallTROJ_ZBOT.SMUC
ClamAVWin.Malware.Zbot-6732674-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDropped:Generic.Malware.GJSFM6g.43C54843
NANO-AntivirusTrojan.Win32.Agent.ohkd
Ad-AwareDropped:Generic.Malware.GJSFM6g.43C54843
EmsisoftDropped:Generic.Malware.GJSFM6g.43C54843 (B)
TrendMicroTROJ_ZBOT.SMUC
McAfee-GW-EditionBehavesLike.Win32.Downloader.mh
Trapminemalicious.moderate.ml.score
SophosML/PE-A + Mal/Behav-010
IkarusTrojan-Spy.Win32.Zbot
AviraBDS/Backdoor.Gen
MicrosoftPWS:Win32/Zbot.MU!MTB
GDataDropped:Generic.Malware.GJSFM6g.43C54843
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Hupe.Gen
McAfeeGenericRXTA-TZ!87C61152B49C
MAXmalware (ai score=86)
VBA32Trojan.Inject.01376
APEXMalicious
RisingTrojan.Generic@AI.89 (RDML:SvpgEOwEU9kIjTV6E6yyDg)
SentinelOneStatic AI – Suspicious PE
FortinetW32/Zbot.PZ!tr.spy
Cybereasonmalicious.2b49c3
PandaGeneric Malware

How to remove PWS:Win32/Zbot.MU!MTB?

PWS:Win32/Zbot.MU!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment