Trojan

What is “Trojan.Zboter.3”?

Malware Removal

The Trojan.Zboter.3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Zboter.3 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.Zboter.3?


File Info:

crc32: EDF837E2
md5: a1ed2656401801ec4a6dc91fe1caf56e
name: A1ED2656401801EC4A6DC91FE1CAF56E.mlw
sha1: cc148fceab15cd9e8a5e94217a691ab4a6f14ba5
sha256: be3c6f36e942a484a4e7dde73ea96e361362bc99d6770f06e3e9a3d55f5ec1d7
sha512: 7b9dc44a6511df0f91fdcb2c219f74e55a7f55edb4210b05702780580ce241b3a6445d6754eb66c23ceb7b3c29c7abb94a71afd04195a9d4419db4ae8d9ef75f
ssdeep: 24576:J2UekJgrI7TSCVstgaBytKEeNclXr9+y7gBBbJ1y:J2dh07O5jByCY7POm
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan.Zboter.3 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004b8aa51 )
Elasticmalicious (high confidence)
ALYacGen:Trojan.Zboter.3
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
K7GWTrojan ( 004b8aa51 )
Cybereasonmalicious.640180
ESET-NOD32a variant of Win32/Injector.DMNR
APEXMalicious
AvastWin32:Trojan-gen
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Shade.ofy
BitDefenderGen:Trojan.Zboter.3
NANO-AntivirusTrojan.Win32.Shade.emlmaj
MicroWorld-eScanGen:Trojan.Zboter.3
TencentMalware.Win32.Gencirc.10b588a1
Ad-AwareGen:Trojan.Zboter.3
SophosMal/Generic-S
DrWebTrojan.PWS.Panda.11620
ZillyaTrojan.Shade.Win32.459
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.a1ed2656401801ec
EmsisoftGen:Trojan.Zboter.3 (B)
SentinelOneStatic AI – Malicious PE
JiangminBackdoor.Androm.ntf
AviraHEUR/AGEN.1108567
eGambitUnsafe.AI_Score_100%
MicrosoftRansom:Win32/Troldesh.A
ArcabitTrojan.Zboter.3
ZoneAlarmTrojan-Ransom.Win32.Shade.ofy
GDataGen:Trojan.Zboter.3
TACHYONRansom/W32.Shade.958464
AhnLab-V3Malware/Win32.Generic.C1862296
McAfeeTrojan-FLSY!A1ED26564018
MAXmalware (ai score=100)
VBA32OScope.Malware-Cryptor.Hlux
MalwarebytesMalware.AI.4079421888
PandaTrj/CI.A
RisingTrojan.Generic@ML.100 (RDML:BacSPfoS6kBtYYHWTHEzJg)
YandexTrojan.GenAsa!ZoOrbfOb/pA
IkarusTrojan.Win32.Injector
FortinetW32/Generic.AC.3E0645!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Shade.HwcBEpsA

How to remove Trojan.Zboter.3?

Trojan.Zboter.3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment