Trojan

Trojan.Zbot.1149 removal

Malware Removal

The Trojan.Zbot.1149 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Zbot.1149 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine Trojan.Zbot.1149?


File Info:

name: 834E236973DD7B131C23.mlw
path: /opt/CAPEv2/storage/binaries/05e29d11c2549596dd5bf2510c9ad6c9529cf75d22da1bab9c9220394fc7d878
crc32: 24D9CF48
md5: 834e236973dd7b131c23e276e3e4f8d3
sha1: c6e4db7fef9f44f5a8c4334292e2eb1e36eb11ab
sha256: 05e29d11c2549596dd5bf2510c9ad6c9529cf75d22da1bab9c9220394fc7d878
sha512: c2723599c912cfb9836fc3394b3f710fffbdaf477107f773764f04f643183b44424478331313acfdf27053e9804ede528d33bd59bb97d2f0c2b1b032b5a61b74
ssdeep: 3072:4leEh28S3G0kcLQyPY0xDv0CXLucxE7nH7tUL+8:4ldheqyQiDvHLd+H7t
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C124C02935435977C2F506F38D873C6EA1BEAB844333072653DA8D1BDAE265A373B610
sha3_384: 36844082853147fe35892dcf32b60d9dd3fa046ec99b0936f82100c388a82eeb6dab5d35940085bf0765a2cd0c9695e4
ep_bytes: 558bec83ec10ff75e88d45e450506843
timestamp: 2005-07-14 12:55:50

Version Info:

0: [No Data]

Trojan.Zbot.1149 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.383
MicroWorld-eScanTrojan.Zbot.1149
FireEyeGeneric.mg.834e236973dd7b13
CAT-QuickHealTrojan.Zbot.Y4
McAfeePWS-Spyeye.fa
CylanceUnsafe
ZillyaTrojan.Kryptik.Win32.879166
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005485311 )
AlibabaTrojanSpy:Win32/Kryptik.7417b7d9
K7GWTrojan ( 005485311 )
Cybereasonmalicious.973dd7
BitDefenderThetaAI:Packer.CFBD9B211F
VirITTrojan.Win32.Panda.OT
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.IPI
TrendMicro-HouseCallTROJ_CRYPTR.SMAX
Paloaltogeneric.ml
ClamAVWin.Spyware.Zbot-1281
KasperskyTrojan-Spy.Win32.Zbot.wsrv
BitDefenderTrojan.Zbot.1149
NANO-AntivirusTrojan.Win32.Zbot.dmmrr
AvastWin32:MalOb-IJ [Cryp]
TencentWin32.Trojan-spy.Zbot.Dygk
Ad-AwareTrojan.Zbot.1149
SophosMal/Generic-R + Mal/EncPk-ACO
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
VIPREVirTool.Win32.Obfuscator.da!j (v)
TrendMicroTROJ_CRYPTR.SMAX
McAfee-GW-EditionBehavesLike.Win32.Generic.dt
EmsisoftTrojan.Zbot.1149 (B)
IkarusTrojan-Spy.Win32.Zbot
GDataTrojan.Zbot.1149
JiangminTrojanSpy.Zbot.asjg
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.F229C0
ZoneAlarmTrojan-Spy.Win32.Zbot.wsrv
MicrosoftPWS:Win32/Zbot.gen!Y
CynetMalicious (score: 100)
Acronissuspicious
VBA32Trojan.Zeus.EA.0999
ALYacTrojan.Zbot.1149
MAXmalware (ai score=100)
APEXMalicious
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.Agent!WrbZxf9e514
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/SpyEye.SK!tr
AVGWin32:MalOb-IJ [Cryp]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Zbot.1149?

Trojan.Zbot.1149 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment