Malware

About “Troj/Zbot-NY” infection

Malware Removal

The Troj/Zbot-NY is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Zbot-NY virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify proxy settings
  • Attempts to modify Explorer settings to prevent hidden files from being displayed
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Troj/Zbot-NY?


File Info:

name: FB20E79EB0009E1D0906.mlw
path: /opt/CAPEv2/storage/binaries/d7862200d1eb34d7e80125a8a6dc872c24b45474cdbd3fe8dfb2cd5eb3e499fa
crc32: 1BB552F3
md5: fb20e79eb0009e1d09069a8a878e6ef6
sha1: fb02506ba6f607a94f39531048467c9ed3da8f08
sha256: d7862200d1eb34d7e80125a8a6dc872c24b45474cdbd3fe8dfb2cd5eb3e499fa
sha512: c53c55da168c383852afcfd23c1c353014a8dab88779fb753292269877ae905564d115603f1e1f1b6ab920342b8295e44a7b7c6e232f21b3d471bfad1057044c
ssdeep: 768:EoIrCKHw0KM+xOF4/i/BEYkp7P6lweQDhDmpU5GFrrEzWsdSE0d8pUHIkI0IFG:EFW0uxO+2G40OIkaFG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T14373B57DB8C3184AE594427E339BCBDA51233A4CAF1FA185619C3FBD4D24D904A7A633
sha3_384: a1333f70676605f2f996de5dd5bde68d5473bc19d35782d8c4e23eba12d8b15c8b46665143312645beddbdd2fe2d1dfa
ep_bytes: 53565755fc648b15300000008b520c8b
timestamp: 2009-12-10 13:38:26

Version Info:

Translation: 0x0409 0x04b0
CompanyName: yVSbsxWE
ProductName: yVSbsxWE
FileVersion: 1.24
ProductVersion: 1.24
InternalName: yVSbsxWE
OriginalFilename: yVSbsxWE.exe

Troj/Zbot-NY also known as:

AVGWin32:Zbodo [Inf]
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKDZ.87868
FireEyeGeneric.mg.fb20e79eb0009e1d
CAT-QuickHealTrojan.Patched.AM
ALYacTrojan.GenericKDZ.87868
Cylanceunsafe
VIPRETrojan.GenericKDZ.87868
SangforSuspicious.Win32.Save.vb
K7AntiVirusTrojan ( 00133ee01 )
BitDefenderTrojan.GenericKDZ.87868
K7GWTrojan ( 00133ee01 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.A21F941C1F
VirITWin32.Patched.J
CyrenW32/Zbot.T.gen!Eldorado
SymantecW32.Changeup
Elasticmalicious (high confidence)
ESET-NOD32Win32/TrojanDownloader.Small.OUC
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.VB-1207
KasperskyTrojan.Win32.ZbotPatched.a
NANO-AntivirusVirus.Win32.Dlder.lbyd
ViRobotWin32.PatchedZBot.A
AvastWin32:Zbodo [Inf]
RisingTrojan.Autorun!1.DA78 (CLASSIC)
SophosTroj/Zbot-NY
BaiduWin32.Worm.Autorun.z
F-SecureTrojan:W32/Hutpic.gen!B
DrWebTrojan.Siggen.34201
ZillyaVirus.Starter.Win32.1
TrendMicroPE_ZBOT.A
McAfee-GW-EditionBehavesLike.Win32.VBObfus.lm
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKDZ.87868 (B)
SentinelOneStatic AI – Malicious PE
GDataTrojan.GenericKDZ.87868
JiangminTrojanDownloader.Genome.ghl
AviraTR/Patched.ZB
MAXmalware (ai score=80)
Antiy-AVLWorm/Win32.Vobfus
XcitiumTrojWare.Win32.Patched.O@1mj32s
ArcabitTrojan.Generic.D1573C
SUPERAntiSpywareTrojan.Agent/Gen-Vobfus
ZoneAlarmTrojan.Win32.ZbotPatched.a
MicrosoftVirus:Win32/Zbot.A
GoogleDetected
AhnLab-V3Win-Trojan/Patched.AE
Acronissuspicious
McAfeeVBObfus.b
TACHYONTrojan/W32.ZbotPatched.77824.B
VBA32Trojan.ZbotPatched
MalwarebytesSmall.Trojan.Downloader.DDS
TrendMicro-HouseCallPE_ZBOT.A
TencentTrojan.Win32.Patched.k
YandexTrojan.GenAsa!BuQA6xuGzUk
IkarusVirus.Worm
FortinetW32/VBObfus.BDBD!tr
Cybereasonmalicious.eb0009
PandaW32/Patched.L

How to remove Troj/Zbot-NY?

Troj/Zbot-NY removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment