Trojan

Trojan.Zbot.IMK (B) information

Malware Removal

The Trojan.Zbot.IMK (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Zbot.IMK (B) virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid

How to determine Trojan.Zbot.IMK (B)?


File Info:

name: B169A258E604BE7EBBAD.mlw
path: /opt/CAPEv2/storage/binaries/9f82ddd266989528657f940c313a5de71ad1394f7607b3c20a8469b7f0dc293c
crc32: 60564651
md5: b169a258e604be7ebbad5a63dcef702d
sha1: 47a9f13115f06d3aeb1780c96d121e07e5dda22e
sha256: 9f82ddd266989528657f940c313a5de71ad1394f7607b3c20a8469b7f0dc293c
sha512: a2290aee803df355163221f6de2fa4c26d5e66d3f9669ce601ebf6cc058befb255d9a41866dd12833f042fb39bf57e99e0c2240f4bc7b02b497227de8d8d09a0
ssdeep: 6144:nCK9TBqYXxyUhyr5lBA28PTdxZwkq6JZcB2:nCK9TIxf+2IxbJZcc
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12644AE57B78C84F3EFA323B4486E771B9BFEA51543184AD3A3A02EC51815593A52C3CB
sha3_384: e39181884dbdbd99e22921b6e3d08f5d63a1093e1f9406d5e08573734d40c2744e2a6eb17459da8a2ff65758f7fbcd78
ep_bytes: 558bec51535633f633c946e816f5ffff
timestamp: 2014-08-21 09:33:03

Version Info:

0: [No Data]

Trojan.Zbot.IMK (B) also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanTrojan.Zbot.IMK
FireEyeGeneric.mg.b169a258e604be7e
CAT-QuickHealTrojan.Generic.5080
McAfeePWS-Zbot.gen.apr
CylanceUnsafe
VIPRETrojan.Zbot.IMK
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004aea031 )
K7GWTrojan ( 004aea031 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34754.qqW@aCXOvWc
VirITTrojan.Win32.Generic.ATRH
CyrenW32/FakeAlert.FY.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.DCD
TrendMicro-HouseCallCryp_Xin1
ClamAVWin.Trojan.Zbot-64722
KasperskyHEUR:Exploit.Win32.ShellCode.vho
BitDefenderTrojan.Zbot.IMK
CynetMalicious (score: 100)
AvastSf:Injector-G [Trj]
TencentTrojan.Win32.ShellCode.16000495
Ad-AwareTrojan.Zbot.IMK
SophosML/PE-A + Mal/Behav-010
DrWebTrojan.PWS.Panda.5676
TrendMicroCryp_Xin1
McAfee-GW-EditionBehavesLike.Win32.ZBot.dh
SentinelOneStatic AI – Malicious PE
Trapminemalicious.high.ml.score
EmsisoftTrojan.Zbot.IMK (B)
APEXMalicious
GDataWin32.Trojan-Spy.Zbot.CL
AviraTR/Spy.Gen
MAXmalware (ai score=89)
ArcabitTrojan.Zbot.IMK
MicrosoftPWS:Win32/Zbot!GOA
GoogleDetected
AhnLab-V3Backdoor/Win32.Necurs.R121059
ALYacTrojan.Zbot.IMK
TACHYONTrojan/W32.ZBot.270336.D
MalwarebytesMalware.AI.1559019732
RisingRansom.Satan!1.AEB7 (CLASSIC)
YandexTrojan.GenAsa!wbBez+nKmyk
IkarusVirus.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AAU!tr
AVGSf:Injector-G [Trj]
Cybereasonmalicious.8e604b
PandaTrj/Genetic.gen

How to remove Trojan.Zbot.IMK (B)?

Trojan.Zbot.IMK (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment