Trojan

About “Trojan:Win32/Zbot.BAE!MTB” infection

Malware Removal

The Trojan:Win32/Zbot.BAE!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.BAE!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • CAPE detected the embedded win api malware family
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Trojan:Win32/Zbot.BAE!MTB?


File Info:

name: 2D034FB608490DA2774C.mlw
path: /opt/CAPEv2/storage/binaries/196632cdf578941ddd174b6fe511e3d03dd9d56765032525b1b24ca814d354b1
crc32: 4575501C
md5: 2d034fb608490da2774cf531178f1da5
sha1: 48bbb3eab5bc986830d03afc951897f281439dbd
sha256: 196632cdf578941ddd174b6fe511e3d03dd9d56765032525b1b24ca814d354b1
sha512: 41afd1f225b78b66ed2490c7ba0114e045583052cc5beec3fd3857cedb6482c78bc9cfd2c33b9b079aa82e385d1d09d9cb482b6d9846ff72f873d26a88b0a013
ssdeep: 6144:TYUTxSfmI9HkzI6I9hmliFIsp4E8gb2QxmJQ:TYxfbE06Jli3BnSQUy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1AB74DFB08080513ED8D842F15C82BD2A8D2DFCA61A946DDB51497DD63FB31C09BEE96F
sha3_384: ef6384d7d872bfdb08e7ca1d1e1b304ff2b2a0fadb35298d442d53729d720b998c4b198bb1ff9f76b1d17f20320dbf9a
ep_bytes: 558bec51558f0510884300ff35108843
timestamp: 2013-03-21 06:55:43

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft DirectPlay Voice Test
FileVersion: 5.03.2600.5512 (xpsp.080413-0845)
InternalName: dpvsetup.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFilename: dpvsetup.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.03.2600.5512
Translation: 0x0409 0x04b0

Trojan:Win32/Zbot.BAE!MTB also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.ShipUp.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Mods.146
MicroWorld-eScanGen:Variant.Zusy.536429
ClamAVWin.Packed.Shipup-6840400-0
FireEyeGeneric.mg.2d034fb608490da2
SkyhighBehavesLike.Win32.Generic.fh
ALYacGen:Variant.Zusy.536429
Cylanceunsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaTrojan:Win32/Kryptik.b2171757
K7GWTrojan ( 00557ff21 )
K7AntiVirusTrojan ( 00557ff21 )
BitDefenderThetaAI:Packer.233A3AE01F
VirITTrojan.Win32.Generic.NSE
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Kryptik.AXBQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.ShipUp.boi
BitDefenderGen:Variant.Zusy.536429
AvastWin32:Gepys-J [Trj]
TencentTrojan.Win32.Shipup.xf
TACHYONTrojan/W32.Shipup.361504
EmsisoftGen:Variant.Zusy.536429 (B)
F-SecureTrojan.TR/Crypt.EPACK.Gen2
BaiduWin32.Trojan.Agent.eq
ZillyaTrojan.ShipUp.Win32.16058
TrendMicroPAK_Xed-21
Trapminemalicious.high.ml.score
SophosMal/ZAccess-CG
IkarusTrojan.Win32.ShipUp
GDataWin32.Trojan.PSE.1BGK51T
GoogleDetected
AviraTR/Crypt.EPACK.Gen2
Antiy-AVLVirus/Win32.Expiro.ropf
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.AYQE@4wlbfl
ArcabitTrojan.Zusy.D82F6D
ZoneAlarmTrojan.Win32.ShipUp.boi
MicrosoftTrojan:Win32/Zbot.BAE!MTB
VaristW32/S-b8dd3281!Eldorado
AhnLab-V3Trojan/Win32.Kuluoz.C257070
Acronissuspicious
McAfeeArtemis!2D034FB60849
MAXmalware (ai score=88)
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesCrypt.Trojan.Malicious.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallPAK_Xed-21
RisingDropper.Win32.Gepys.l (CLASSIC)
YandexTrojan.GenAsa!AMMn/QkpyGQ
SentinelOneStatic AI – Malicious PE
FortinetW32/Wacatac.B!tr
AVGWin32:Gepys-J [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zbot.BAE!MTB?

Trojan:Win32/Zbot.BAE!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment