Trojan

Trojan:Win32/Zbot.DC!MTB removal tips

Malware Removal

The Trojan:Win32/Zbot.DC!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.DC!MTB virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to modify proxy settings
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

huyontop.com
ocsp.comodoca.com

How to determine Trojan:Win32/Zbot.DC!MTB?


File Info:

crc32: 76CB7D1A
md5: 4bb4037cfd0f4071116093f3d364c76f
name: 4BB4037CFD0F4071116093F3D364C76F.mlw
sha1: c26c72ca7dfcba691357e4ca8bfe978c78d96368
sha256: 110a46a43f0542ad4a14552acd7ec48c4b95ef613fef3f404fd6534a08c7f89d
sha512: b3d79d48d5b0ae699bf1e19a36ddd8c2ab151d1060e9a2308a0ca1756383ec30efb64a1eecb6765a9b960304a9580d8f913518ae2d8ddc71150d368c9597f29c
ssdeep: 384:QLcTQvmFzKbE+QwuC6WREiHQqYBkUn/8yIYNMBAfGr:QqQmFL+QMC9B1QYuAa
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Zbot.DC!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan-Downloader ( 0053178a1 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader10.8528
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Upatre.S3228852
ALYacTrojan.Ppatre.Gen.1
CylanceUnsafe
ZillyaDownloader.Waski.Win32.8646
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 0053178a1 )
Cybereasonmalicious.cfd0f4
CyrenW32/Upatre.LR.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrojanDownloader.Waski.AJ
ZonerProbably Heur.ExeHeaderH
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Downloader.Upatre-9854858-0
KasperskyVHO:Trojan-Banker.Win32.Convagent.gen
BitDefenderTrojan.Ppatre.Gen.1
MicroWorld-eScanTrojan.Ppatre.Gen.1
TencentMalware.Win32.Gencirc.10b0cec3
Ad-AwareTrojan.Ppatre.Gen.1
SophosML/PE-A + Troj/Upatre-XO
ComodoTrojWare.Win32.TrojanDownloader.Upatre.AX@7t0ehr
BitDefenderThetaAI:Packer.5313985C1D
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Generic.mz
FireEyeGeneric.mg.4bb4037cfd0f4071
EmsisoftTrojan.Ppatre.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cdnmu
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.2616CE8
MicrosoftTrojan:Win32/Zbot.DC!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
ZoneAlarmTrojan-Downloader.Win32.Small.gen
GDataWin32.Trojan-Downloader.Upatre.BJ
AhnLab-V3Trojan/Win32.Upatre.R256307
Acronissuspicious
McAfeeGenericRXLV-NU!4BB4037CFD0F
MAXmalware (ai score=83)
VBA32Trojan.Downloader
MalwarebytesTrojan.Upatre
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingTrojan.Generic@ML.100 (RDML:mzUq52APr0uFYhFsETMlwA)
YandexTrojan.GenAsa!w6f6bF9mr2E
IkarusTrojan-Downloader.Upatre
MaxSecureTrojan.Upatre.Gen
FortinetW32/Tiny.NIV!tr
AVGWin32:TrojanX-gen [Trj]

How to remove Trojan:Win32/Zbot.DC!MTB?

Trojan:Win32/Zbot.DC!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment