Trojan

Trojan.Zbot.4323 removal

Malware Removal

The Trojan.Zbot.4323 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Zbot.4323 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Checks for the presence of known windows from debuggers and forensic tools
  • Creates a copy of itself

How to determine Trojan.Zbot.4323?


File Info:

name: 7D04E47D48373CD1D74E.mlw
path: /opt/CAPEv2/storage/binaries/a2df07926abfd9fd0a0421ea13ea3ac4488dcc171b751474e2470d70ad9f2c31
crc32: 3B5459B8
md5: 7d04e47d48373cd1d74e8886472795dd
sha1: 09fd7283f06302864455ce73735a7e7fdfe7de21
sha256: a2df07926abfd9fd0a0421ea13ea3ac4488dcc171b751474e2470d70ad9f2c31
sha512: 3e56c0715d6dc476981cc1518b8c3d2c684e456f6d7fe688f7ace7bd2ff7c9da8d77cbd344ec1d569e8ed8c2e239480caa4521301f498f826bf62bf7ab1cb986
ssdeep: 768:J3/IwI4gTtUReg/UXssPzfQE6rrDNswNX9pQUnbmhGOOOOOOOaHaJB4VQgvBAfBY:ud4gTtUMgQzfWrrDNhLGKYBuOw
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T188838D715597C260C35EC871F88B493AD422DD62C2EB0269E279F33CFEF061D986AE54
sha3_384: 481b063a353fa5951cdf8464037834cefca79988658aa21a4202d772f951f58ee32f56f9acb1f22443a27fd0f900f4e0
ep_bytes: 6a008b0d2030400049ffd1ff15443040
timestamp: 2007-12-21 03:12:06

Version Info:

0: [No Data]

Trojan.Zbot.4323 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lmka
MicroWorld-eScanTrojan.Zbot.4323
FireEyeGeneric.mg.7d04e47d48373cd1
CAT-QuickHealTrojan.Lethic.B
ALYacTrojan.Zbot.4323
CylanceUnsafe
VIPRETrojan.Zbot.4323
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 005042e61 )
K7GWTrojan ( 005042e61 )
Cybereasonmalicious.d48373
BaiduWin32.Trojan.Kryptik.hc
VirITTrojan.Win32.Cryptor.A
CyrenW32/FakeAlert.UN.gen!Eldorado
SymantecSecShieldFraud!gen7
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AGAI
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Fareit-9943205-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Zbot.4323
NANO-AntivirusTrojan.Win32.Lime.ctkclx
SUPERAntiSpywareTrojan.Agent/Gen-Fakeav
AvastWin32:Virtu-F [Inf]
TencentTrojan.Win32.Dofoil.a
Ad-AwareTrojan.Zbot.4323
SophosML/PE-A + Mal/FakeAV-RQ
ComodoTrojWare.Win32.Kryptik.AFXC@4pe64l
DrWebWin32.HLLW.Lime.18
ZillyaTrojan.FakeAV.Win32.201944
TrendMicroTROJ_KRYPTIK.SM10
McAfee-GW-EditionPWS-Zbot.gen.acl
Trapminemalicious.high.ml.score
EmsisoftTrojan.Zbot.4323 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Fakeav.baem
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Generic.ASMalwS.224
MicrosoftTrojan:Win32/Lethic.B
ViRobotTrojan.Win32.A.FakeAV.88064.A
GDataTrojan.Zbot.4323
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tepfer.R26936
Acronissuspicious
McAfeePWS-Zbot.gen.acl
MAXmalware (ai score=88)
VBA32Trojan.FakeAV.01657
MalwarebytesTrojan.Agent
TrendMicro-HouseCallTROJ_KRYPTIK.SM10
RisingMalware.XPACK!1.64E8 (CLASSIC)
IkarusTrojan.Win32.FakeAV
MaxSecureTrojan.SmartFortress.A
FortinetW32/CoinMiner.F
BitDefenderThetaGen:NN.ZexaF.34592.fuW@aOd6zSoi
AVGWin32:Virtu-F [Inf]
PandaAdware/SystemTool
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Zbot.4323?

Trojan.Zbot.4323 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment