Trojan

Trojan:Win32/Zbot.DSA!MTB (file analysis)

Malware Removal

The Trojan:Win32/Zbot.DSA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.DSA!MTB virus can do?

  • Sample contains Overlay data
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Trojan:Win32/Zbot.DSA!MTB?


File Info:

name: B2CC7D0483A89F903E70.mlw
path: /opt/CAPEv2/storage/binaries/316cba5bca1408f13acc337ccc59c79db1115330ecb2eb3dee3decee14811ca4
crc32: A6FA1D98
md5: b2cc7d0483a89f903e7015f71ae7ab03
sha1: 770f610441e8ef30c857e7f6df77c12e2dacd4bf
sha256: 316cba5bca1408f13acc337ccc59c79db1115330ecb2eb3dee3decee14811ca4
sha512: 1cc6616fcd7d6d3269e0a0ea2ee0e69df9d45f855862107556eb4971a867976a64eec9a880734a4ca93dca2466c1181c8a2e8df5ea8479bc45b3d7237d6d8028
ssdeep: 3072:BfUaDdXWWusQymdFdapGhf0RyR1qPF/njjC6tQV1xVyLZ+UJdUhKxorMG56tpSo1:B/dmWcdRhf2yR1YxY1ryLgUJqhKirith
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10004019FB59DB42AC5F2D17C0D1106BB763B208EF739890A091DBE293DDEA76C699001
sha3_384: f5ac9fb3c03178bcabd2660f5316fab859a3c376f81a633b757ba285817adb57674b2488a30436261a0a4c02e50e223d
ep_bytes: 60be00b044008dbe0060fbff5783cdff
timestamp: 2005-12-19 17:55:50

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Мастер переноса файлов и параметров
FileVersion: 5.1.2600.5512 (xpsp.080413-2105)
InternalName: MigWiz
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: MigWiz.Exe
ProductName: Операционная система Microsoft® Windows®
ProductVersion: 5.1.2600.5512
Translation: 0x0419 0x04b0

Trojan:Win32/Zbot.DSA!MTB also known as:

BkavW32.MosquitoQKB.Fam.Trojan
MicroWorld-eScanGen:Heur.VIZ.2
ALYacGen:Heur.VIZ.2
MalwarebytesCrypt.Trojan.Malicious.DDS
ZillyaTrojan.Generic.Win32.216697
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( f1000f011 )
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.483a89
BaiduWin32.Worm.Autorun.h
CyrenW32/S-a84f9024!Eldorado
SymantecSMG.Heur!gen
Elasticmalicious (moderate confidence)
APEXMalicious
ClamAVWin.Trojan.Ramnit-5401
KasperskyBackdoor.Win32.Shiz.kkff
BitDefenderGen:Heur.VIZ.2
NANO-AntivirusTrojan.Win32.AutoRun.cxytjh
SUPERAntiSpywareHeur.Agent/Gen-StaticIcon
TencentTrojan.Win32.Lebag.bhv
SophosTroj/Kryptik-RR
F-SecureHeuristic.HEUR/AGEN.1340728
DrWebTrojan.MulDrop1.64009
VIPREGen:Heur.VIZ.2
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.b2cc7d0483a89f90
EmsisoftGen:Heur.VIZ.2 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Heur.VIZ.2
JiangminTrojan/Generic.bdhix
WebrootW32.Rogue.Gen
GoogleDetected
AviraHEUR/AGEN.1340728
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Lebag
XcitiumTrojWare.Win32.Lebeg.WJOD@5csyki
ArcabitTrojan.VIZ.2
ZoneAlarmBackdoor.Win32.Shiz.kkff
MicrosoftTrojan:Win32/Zbot.DSA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R2835
Acronissuspicious
McAfeeGenericRXAA-AA!B2CC7D0483A8
TACHYONWorm/W32.AutoRun.188825
DeepInstinctMALICIOUS
Cylanceunsafe
PandaTrj/Genetic.gen
ZonerTrojan.Win32.36680
RisingTrojan.Win32.Generic.135CF92F (C64:YzY0Ohk78vU2prbV)
YandexTrojan.Kryptik!sco37wss+x4
IkarusVirus.Win32.Virtob
MaxSecureTrojan.Malware.7735513.susgen
FortinetW32/Generic.AC.1B437!tr
BitDefenderThetaGen:NN.ZexaF.36196.lm1@amvbDdgc
AVGWin32:Evo-gen [Trj]
AvastWin32:Evo-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Zbot.DSA!MTB?

Trojan:Win32/Zbot.DSA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment