Malware

About “Troj/Zbot-HGR” infection

Malware Removal

The Troj/Zbot-HGR is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Zbot-HGR virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Turkish
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Troj/Zbot-HGR?


File Info:

name: FE01EB19A1E52D4838E9.mlw
path: /opt/CAPEv2/storage/binaries/45f18ca7749ad75dafeacce1d1ac7203eb2b494036029a4675a60de469acd465
crc32: 76090C38
md5: fe01eb19a1e52d4838e968d88d2d25f4
sha1: 971fce315e8f5b842d72775ce7ea65b14d203554
sha256: 45f18ca7749ad75dafeacce1d1ac7203eb2b494036029a4675a60de469acd465
sha512: 73c2b55f1ad976e45af4cf1e4e440e759d799eb58143d92dd3e3a535f2e49013ac64d618fe625b075fb6cabcf009b3f21c462c02a02c798047335fb18d56f8c2
ssdeep: 6144:WR/bxfYNuX1Ed5hZ9UxhX4O498sfti2QBm1v6:WRzx+uedXrQ4984HQB66
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14C241324C6E25C21F76B43BA27743E3463F62F206F4514EBDA9A2EB492B47970406637
sha3_384: a7eab28d90cc4b7e7468f4bee9666ee6b74b9d8e3ca9edc632c89304de73afffa4c9a406adbf900760256a2d09dbea6d
ep_bytes: e9d32c0500000000006ac76a216800f8
timestamp: 2011-10-02 06:40:09

Version Info:

CompanyName: BitMefender S.R.L.
FileDescription: BitMefender Antivirus Scanner
FileVersion: 13,0,21,1
InternalName: GUIScanner
LegalCopyright: Copyright (C) 2010
OriginalFilename: uiscan.exe
ProductName: BitMefender 2016
ProductVersion: 13,0,18,344
Translation: 0x0409 0x04b0

Troj/Zbot-HGR also known as:

BkavW32.AIDetectMalware
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Symmi.38368
ALYacGen:Variant.Symmi.38368
MalwarebytesGeneric.Malware.AI.DDS
VIPREGen:Variant.Symmi.38368
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005a60f61 )
K7GWTrojan ( 005a60f61 )
Cybereasonmalicious.9a1e52
VirITTrojan.Win32.Generic.BDPN
CyrenW32/Zbot.OQ.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BSIW
APEXMalicious
ClamAVWin.Trojan.Yakes-1870
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.38368
AvastWin32:Evo-gen [Trj]
TencentMalware.Win32.Gencirc.10bee3cb
EmsisoftGen:Variant.Symmi.38368 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen9
DrWebTrojan.DownLoader9.8340
TrendMicroTSPY_ZBOT.SM3R
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.fe01eb19a1e52d48
SophosTroj/Zbot-HGR
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.38368
GoogleDetected
AviraTR/Crypt.ZPACK.Gen9
MAXmalware (ai score=85)
Antiy-AVLTrojan/Win32.Yakes
ArcabitTrojan.Symmi.D95E0
SUPERAntiSpywareTrojan.Agent/Gen-Falcomp
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Yakes.R582244
McAfeeGenericRXWB-BJ!FE01EB19A1E5
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ZBOT.SM3R
RisingSpyware.Zbot!1.A1BA (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Yakes.dwzw
FortinetW32/Wacatac.B!tr
AVGWin32:Evo-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Troj/Zbot-HGR?

Troj/Zbot-HGR removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment