Trojan

Should I remove “Trojan:Win32/Zbot.AMAD!MTB”?

Malware Removal

The Trojan:Win32/Zbot.AMAD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.AMAD!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan:Win32/Zbot.AMAD!MTB?


File Info:

name: 7BA7F9970FDA31F1E9CB.mlw
path: /opt/CAPEv2/storage/binaries/c245d48a9a601bce56841d9f6dcf94a9ee0e4524022a2dad1e9ac85eac291e55
crc32: 6BCB02A7
md5: 7ba7f9970fda31f1e9cb9681eeacb312
sha1: 2013de7aaa8c9a5b0428074d46ae521f96312331
sha256: c245d48a9a601bce56841d9f6dcf94a9ee0e4524022a2dad1e9ac85eac291e55
sha512: af90ed30f68d392c0bf36c8570bf671c714145c00177eae0442f2202b02aca4ed429dc96ec0836b0c8c4a5051077d1a815ad438630a6cac69d88d37a73f02d94
ssdeep: 3072:j86HR+ZEneNTu89aAqzi0qAxT3PrAxT3P386HR+ZEneNTu89aAqzi0a:l4NThMziaxT3cxT354NThMzi
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C7F35A5535D1D8B2CAE3807137587F3776BFE9318E299C43C32009C9A7A4CA2D52AE5B
sha3_384: f7b7889acef79553b7afc01b6eb8be8602c6330c7d86c0543ef9e290a866a6f9991a5cd77e7cc9574b2d89d6366b1a42
ep_bytes: 00000000003c10400010204100701241
timestamp: 2002-07-08 16:12:40

Version Info:

0: [No Data]

Trojan:Win32/Zbot.AMAD!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Generic.4!c
AVGSf:Zbot-JD [Trj]
MicroWorld-eScanTrojan.Wsnpoem.N
FireEyeGeneric.mg.7ba7f9970fda31f1
SkyhighBehavesLike.Win32.Generic.ch
ALYacTrojan.Wsnpoem.N
MalwarebytesMalware.Heuristic.2006
ZillyaTrojan.Zbot.Win32.6690
K7AntiVirusSpyware ( 000c714c1 )
AlibabaTrojanPSW:Win32/Generic.1f974204
K7GWSpyware ( 000c714c1 )
Cybereasonmalicious.70fda3
VirITTrojan.Win32.Generic.BIDW
SymantecBackdoor.Paproxy
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Zbot.JF
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Zbot-9951823-0
KasperskyHEUR:Trojan.Win32.Panda.gen
BitDefenderTrojan.Wsnpoem.N
AvastSf:Zbot-JD [Trj]
RisingStealer.Zbot!8.109D7 (TFE:1:g1FcfwN2BwB)
TACHYONTrojan-Spy/W32.ZBot.163840
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Proxy.27229
VIPRETrojan.Wsnpoem.N
Trapminesuspicious.low.ml.score
EmsisoftTrojan.Wsnpoem.N (B)
IkarusTrojan-Spy.Zbot
JiangminTrojanSpy.Zbot.gjk
WebrootW32.InfoStealer.Zeus
VaristW32/Trojan.EROA-8131
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Win32.AGeneric
KingsoftWin32.Trojan.Panda.gen
MicrosoftTrojan:Win32/Zbot.AMAD!MTB
XcitiumTrojWare.Win32.Spy.Zbot.ABA@1pe611
ArcabitTrojan.Wsnpoem.N
ZoneAlarmHEUR:Trojan.Win32.Panda.gen
GDataTrojan.Wsnpoem.N
GoogleDetected
AhnLab-V3Trojan/Win32.Zbot.R134642
McAfeeArtemis!7BA7F9970FDA
MAXmalware (ai score=100)
Cylanceunsafe
PandaGeneric Malware
YandexTrojanSpy.Zbot!urT48q1E6ik
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Wsnpoem.EL!tr
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)
alibabacloudTrojan[spy]:Win/Zbot.JF

How to remove Trojan:Win32/Zbot.AMAD!MTB?

Trojan:Win32/Zbot.AMAD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment