Trojan

Trojan:Win32/Pikabot.ZY!MTB information

Malware Removal

The Trojan:Win32/Pikabot.ZY!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Pikabot.ZY!MTB virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Pikabot.ZY!MTB?


File Info:

name: 898854477243E8B9B431.mlw
path: /opt/CAPEv2/storage/binaries/a352b9eb373fe914888128f3e6e72cab5a5193cbe491af45304ed7985c9dff8f
crc32: 96FC0B43
md5: 898854477243e8b9b431e73e31246ab4
sha1: 803ffa5b263aad9c4f24d92fe340a656af80e9ca
sha256: a352b9eb373fe914888128f3e6e72cab5a5193cbe491af45304ed7985c9dff8f
sha512: 4c86ab3368fe446a5f14f7629fd8f5ede96bab6cde25db931ad0a778b1fbaa622298fb2ecd91c40cbcf394b685318c065645925c3fe31cbb1996dfd34023438a
ssdeep: 24576:EtrcFS3D0x4f8FJbA8dE/D3A6y2smW8ZWTgHSbK6SjcpEtWL+ol9FS+EIZmNQ2:q4S3q08FlA8cD3ZFsR8UTgHThjULT7ma
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1F345F122B750C032C44F0139F85AD7F895B9BA709D799917B3E84B2D1F703929B29F92
sha3_384: 7b6ab17789d388afd314fa1f4132c95652add9ccb212728213ab0f1da7e269ff448d454e44c6ca1ae81b793094a7c091
ep_bytes: b801000000c20c00017505e8d8af0000
timestamp: 2015-01-19 14:52:54

Version Info:

CompanyName: Yandex LLC
FileDescription: Yandex updater (CU)
FileVersion: 1.2.0.1831
InternalName: dllyupdate
LegalCopyright: Copyright (C) 2014 Yandex LLC
OriginalFilename: dllyupdate.dll
ProductName: Yandex updater
ProductVersion: 1.2.0.1831
Translation: 0x0419 0x04b0

Trojan:Win32/Pikabot.ZY!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Pikabot.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Generic.35225610
FireEyeTrojan.Generic.35225610
SkyhighBehavesLike.Win32.PinkSbot.tc
McAfeeArtemis!898854477243
MalwarebytesTrojan.Agent
SangforTrojan.Win32.Pikabot.Vr3q
K7AntiVirusBackdoor ( 005ada2b1 )
AlibabaTrojan:Win32/Pikabot.6e0bc72a
K7GWBackdoor ( 005ada2b1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Genus.UBF
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/PikaBot.J
KasperskyHEUR:Trojan.Win32.Agentb.pef
BitDefenderTrojan.Generic.35225610
AvastWin32:Malware-gen
TencentWin32.Trojan.Agentb.Fflw
EmsisoftTrojan.Generic.35225610 (B)
GoogleDetected
F-SecureHeuristic.HEUR/AGEN.1364518
DrWebBackDoor.Pikabot.7
VIPRETrojan.Generic.35225610
SophosMal/Generic-S
JiangminTrojan.Agentb.oes
VaristW32/Qbot.QQ.gen!Eldorado
AviraHEUR/AGEN.1364518
Antiy-AVLTrojan/Win32.Qbot
KingsoftWin32.Troj.Generic.v
MicrosoftTrojan:Win32/Pikabot.ZY!MTB
ArcabitTrojan.Generic.D219800A
ZoneAlarmHEUR:Trojan.Win32.Agentb.pef
GDataTrojan.Generic.35225610
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C5537792
VBA32Trojan.Pikabot
ALYacTrojan.Generic.35225610
MAXmalware (ai score=88)
Cylanceunsafe
PandaTrj/Chgt.AD
RisingTrojan.Agent!8.B1E (TFE:6:xnGbr2Hs2eJ)
YandexTrojan.Agentb!lxGHkU52ZRU
IkarusBackdoor.QBot
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Qbot.ET!tr
AVGWin32:Malware-gen
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Agentb.lhsa

How to remove Trojan:Win32/Pikabot.ZY!MTB?

Trojan:Win32/Pikabot.ZY!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment