Trojan

What is “Trojan:Win32/Zbot.AO!MTB”?

Malware Removal

The Trojan:Win32/Zbot.AO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.AO!MTB virus can do?

  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Network activity detected but not expressed in API logs
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zbot.AO!MTB?


File Info:

crc32: 51957134
md5: 0fac2acc1d3d8769c1bb26107f717a27
name: 0FAC2ACC1D3D8769C1BB26107F717A27.mlw
sha1: 5c7797d754217608dbcce7faf34f2d4dfbf11064
sha256: c5dacc8a0c758ce15b2bd2ec98a246352128312fe9e20f137b528f35b69ee359
sha512: 4d14f95f2cf9c07231721a79476c1a3543fb112ef340f2b12906078850b9563423c9242f9ad9dd2baea0e0fdb6182c3b686c7f5255230bc5dfaf201432433486
ssdeep: 192:lHFwFITiXzJ5rn9uyhrdlKucmuGt03cZ/IO7xUjTAr:llwFITiXDZu+mmRtVZzxgTi
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Zbot.AO!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 0050fef41 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.28507
ClamAVWin.Malware.Sdld-7131932-0
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacTrojan.Ppatre.Gen.1
CylanceUnsafe
ZillyaDownloader.Small.Win32.76252
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 004eadfb1 )
Cybereasonmalicious.c1d3d8
BaiduWin32.Trojan-Downloader.Waski.k
CyrenW32/S-79ee1585!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Small.PRL
APEXMalicious
AvastWin32:Downloader-WID [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.cjerhf
MicroWorld-eScanTrojan.Ppatre.Gen.1
TencentMalware.Win32.Gencirc.10b0cd7a
Ad-AwareTrojan.Ppatre.Gen.1
SophosML/PE-A + Troj/Upatre-XO
ComodoTrojWare.Win32.TrojanDownloader.Upatre.ACC@56yhj8
BitDefenderThetaGen:NN.ZexaF.34236.amY@aqldP@c
VIPRETrojan-Downloader.Win32.Upatre.a (v)
TrendMicroTROJ_DLOADER.SM3
McAfee-GW-EditionBehavesLike.Win32.Upatre.lz
FireEyeGeneric.mg.0fac2acc1d3d8769
EmsisoftTrojan.Ppatre.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.acusk
AviraTR/Dropper.Gen
eGambitUnsafe.AI_Score_95%
Antiy-AVLTrojan/Generic.ASMalwS.CA98B9
MicrosoftTrojan:Win32/Zbot.AO!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Downloader.Upatre.BJ
AhnLab-V3Trojan/Win32.Zbot.R83549
McAfeeUpatre-FAAI!0FAC2ACC1D3D
MAXmalware (ai score=83)
VBA32Trojan.Download
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_DLOADER.SM3
RisingTrojan.Generic@ML.100 (RDML:R1sSX92IVf3lwksyobbw0w)
YandexTrojan.GenAsa!xjw/xZS1BKE
IkarusTrojan-Downloader.Win32.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Tiny.NIV!tr
AVGWin32:Downloader-WID [Trj]

How to remove Trojan:Win32/Zbot.AO!MTB?

Trojan:Win32/Zbot.AO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment