Trojan

Trojan.Zbot.2137 information

Malware Removal

The Trojan.Zbot.2137 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Zbot.2137 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan.Zbot.2137?


File Info:

name: 03D054C0C979FFDC2336.mlw
path: /opt/CAPEv2/storage/binaries/2d191dcaad348af76bd4583e482741fdc5abededb12e9d2f75a4b253c73189dc
crc32: 6C896CCC
md5: 03d054c0c979ffdc233696edcfae411b
sha1: fc308b6afff1131608ed095469b0cb0e5d5dce20
sha256: 2d191dcaad348af76bd4583e482741fdc5abededb12e9d2f75a4b253c73189dc
sha512: a609ad13577775121953261aba2ede037fa4c97ba8386797f3eead6f6e4479060b57878fe7ffcdb80c770accbc4dc9165ace7b0a9ff36bd6a4da3458d209f680
ssdeep: 6144:yWBGRHJoxlXIZPWHhixMMQ4/yCclvgR2x9OHGGf7yeFQPVjWcaoCWGJFSzlJOYW6:XBqex1IZPWWg6f7TKPTzloyxLQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F774231183E811A5D0340A75906DCA0B90EBE550328BF3DB3B877B5EDDA514A2FEB678
sha3_384: 022b4c47d4cb9e572e7d9045cc83569808730f52da8acb67ba9e3574f1d1cc41f2fe2127228b3cef7b09421851f41539
ep_bytes: 60be007054008dbe00a0ebffc787e44e
timestamp: 2011-02-22 13:21:42

Version Info:

CompanyName: hollow
FileDescription: Wordl
FileVersion: 1.0.2.10
InternalName: hollow.exe
LegalCopyright: Copyright (C) 2011
OriginalFilename: hollow.exe
ProductName: hollow
ProductVersion: 1.0.2.10
Translation: 0x001c 0x04b0

Trojan.Zbot.2137 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Gimemo.j!c
MicroWorld-eScanTrojan.Zbot.2137
FireEyeGeneric.mg.03d054c0c979ffdc
McAfeeArtemis!03D054C0C979
CylanceUnsafe
ZillyaTrojan.Gimemo.Win32.341
SangforTrojan.Win32.Kryptik.LEC
K7AntiVirusTrojan ( 0055dd191 )
AlibabaTrojan:Win32/Kryptik.fddb6978
K7GWTrojan ( 0055dd191 )
Cybereasonmalicious.0c979f
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Kryptik.LEC
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-48109
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Zbot.2137
NANO-AntivirusTrojan.Win32.Kryptik.kzoyw
SUPERAntiSpywareTrojan.Agent/Gen-Dropper
AvastFileRepMalware
TencentWin32.Trojan.Gimemo.Gbo
Ad-AwareTrojan.Zbot.2137
EmsisoftTrojan.Zbot.2137 (B)
ComodoMalware@#2t40hpd5efd53
DrWebTrojan.Fakealert.23744
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_KRAP.SML
McAfee-GW-EditionGenericRXKN-BR!09CA492AE83F
SophosMal/Generic-S
IkarusTrojan.Win32.LockScreen
GDataTrojan.Zbot.2137
JiangminTrojan/Gimemo.uw
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.ZPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.1839B0B
ArcabitTrojan.Zbot.D859
MicrosoftTrojan:Win32/Tiggre!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Gimemo.C154936
BitDefenderThetaAI:Packer.FDF4BC011F
ALYacTrojan.Zbot.2137
MAXmalware (ai score=100)
VBA32Trojan.FakeAlert
TrendMicro-HouseCallTROJ_KRAP.SML
RisingRansom.LockScreen!8.83D (CLOUD)
YandexTrojan.Gimemo!yqSRuKrIkSk
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Kryptik.LEC!tr
AVGFileRepMalware
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.2275326.susgen

How to remove Trojan.Zbot.2137?

Trojan.Zbot.2137 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment