Trojan

Trojan:Win32/NativeZone.B!dha malicious file

Malware Removal

The Trojan:Win32/NativeZone.B!dha is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/NativeZone.B!dha virus can do?

  • Creates RWX memory
  • Unconventionial language used in binary resources: Ukrainian
  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Trojan:Win32/NativeZone.B!dha?


File Info:

crc32: A3D023D9
md5: 66534e53d8751a24a767221fed01268d
name: 66534E53D8751A24A767221FED01268D.mlw
sha1: fc781887fd0579044bbf783e6c408eb0eea43485
sha256: 3b94cc71c325f9068105b9e7d5c9667b1de2bde85b7abc5b29ff649fd54715c4
sha512: 1f1b784b280bc34761ae93893ae7d95ebc6e5515542f153df7c91b00adfa796b3b2bee1a5857e0bb07d13c93b4df0eec3e1fd85911c79153b2d6c824a3a79369
ssdeep: 6144:qLH2gY7rrs52ACS+ToF3dxmTZysKwlVAl519k7nm9OQ4nFI:qj9U9ovI1V819k7nNFI
type: PE32 executable (DLL) (console) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) x410x422 "x406x406x422"
InternalName: x406x406x422 x411x456x431x43bx456x43ex442x435x43ax430 x440x43ex431x43ex442x438 x437 x41dx41ax406 x442x438x43fx443: "x444x430x439x43bx43ex432x430 x441x438x441x442x435x43cx430"
FileVersion: 1.0.1.3
CompanyName: x410x422 "x406x406x422"
ProductName: x406x406x422 x411x456x431x43bx456x43ex442x435x43ax430 x440x43ex431x43ex442x438 x437 x41dx41ax406 x442x438x43fx443: "x444x430x439x43bx43ex432x430 x441x438x441x442x435x43cx430"
ProductVersion: 1.0.1
FileDescription: x406x406x422 x411x456x431x43bx456x43ex442x435x43ax430 x440x43ex431x43ex442x438 x437 x41dx41ax406 x442x438x43fx443: "x444x430x439x43bx43ex432x430 x441x438x441x442x435x43cx430"
OriginalFilename: KM.FileSystem.dll
Translation: 0x0409 0x04e4

Trojan:Win32/NativeZone.B!dha also known as:

CynetMalicious (score: 99)
CAT-QuickHealTrojan.Multi
ALYacTrojan.Agent.NativeZone
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2100279
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Generic.04c3e8d1
K7GWTrojan ( 0057cf1f1 )
K7AntiVirusTrojan ( 0057cf1f1 )
CyrenW32/Trojan.QLIU-8209
SymantecTrojan.Gen.2
ESET-NOD32a variant of Win32/Agent.ADCK
APEXMalicious
AvastWin32:Trojan-gen
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderGen:Variant.NativeZone.8
ViRobotTrojan.Win32.S.Agent.288768.FB
MicroWorld-eScanGen:Variant.NativeZone.8
Ad-AwareGen:Variant.NativeZone.8
SophosMal/Generic-R + Troj/Agent-BHDJ
BitDefenderThetaGen:NN.ZedlaF.34692.ru8@aKdu9Snk
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.COBEACON.BD
McAfee-GW-EditionRDN/Generic.dx
FireEyeGeneric.mg.66534e53d8751a24
EmsisoftTrojan.GenericKD.36928994 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Multi.aqj
AviraTR/Agent.ffbhc
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/NativeZone.B!dha
ArcabitTrojan.Generic.D2337DE2
AegisLabTrojan.Multi.GenericML.4!c
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataTrojan.GenericKD.36928994
AhnLab-V3Trojan/Win.Agent.C4501931
McAfeeRDN/Generic.dx
MAXmalware (ai score=100)
VBA32Trojan.NativeZone
TrendMicro-HouseCallTrojan.Win32.COBEACON.BD
IkarusTrojan.Win32.Agent
MaxSecureTrojan.Malware.82199810.susgen
FortinetW32/Agent.ADCK!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan:Win32/NativeZone.B!dha?

Trojan:Win32/NativeZone.B!dha removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment