Trojan

Trojan:Win32/Zbot.DSK!MTB information

Malware Removal

The Trojan:Win32/Zbot.DSK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.DSK!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Executable file is packed/obfuscated with MPRESS
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Trojan:Win32/Zbot.DSK!MTB?


File Info:

name: C474987E3798FCA4F66F.mlw
path: /opt/CAPEv2/storage/binaries/97a7ec028cbbef8a2c4fc7505f32230bdfe64b36b4e6701906837448e5390302
crc32: C9FAE064
md5: c474987e3798fca4f66f8a67974315df
sha1: 3c7d0dc9758827f1900db9eab69bc81df68b301c
sha256: 97a7ec028cbbef8a2c4fc7505f32230bdfe64b36b4e6701906837448e5390302
sha512: a45fa691891359e79677a588197dc2d54d8958a58751e706173c052ef91b663080621c59164a03f72111811c088eb7e13ea1b59f5fe97d3d4aa68127185e2ba5
ssdeep: 1536:dxDDnd1RaqOrsdSCM+qvNYF++28kJDriKV:dxDDd/VOrInM+e
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B6B36038AAE45532D3B7CA7589F651C2BC35B9223E15984F41DA13490C23F92EDB1F2E
sha3_384: 78a25b4b3bdcd3f5e036d7634b0b6e4b49bb0aab38992537f4882835c545c926844c28088581a5838b2bc4c149057066
ep_bytes: e8db130000e989feffff8bff558bec8b
timestamp: 2013-08-27 16:13:37

Version Info:

0: [No Data]

Trojan:Win32/Zbot.DSK!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.Downloader.JQAP
FireEyeGeneric.mg.c474987e3798fca4
McAfeePWSZbot-FEV!C474987E3798
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0052964f1 )
AlibabaMalware:Win32/km_24ae3.None
K7GWTrojan ( 0052964f1 )
Cybereasonmalicious.e3798f
BitDefenderThetaGen:NN.ZexaF.34182.gqZ@aulO9rkk
VirITTrojan.Win32.DownLoad3.BPRD
CyrenW32/Upatre.IS.gen!Eldorado
SymantecSMG.Heur!gen
ESET-NOD32a variant of Win32/Kryptik.BIYN
BaiduWin32.Trojan-Spy.Zbot.a
TrendMicro-HouseCallTROJ_GEN.R002C0CB222
Paloaltogeneric.ml
ClamAVWin.Downloader.Upatre-5744087-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Downloader.JQAP
NANO-AntivirusTrojan.Win32.DownLoad3.cjdyni
AvastWin32:Malware-gen
TencentTrojan-Downloader.Win32.Waski.16000151
EmsisoftTrojan.Downloader.JQAP (B)
ComodoTrojWare.Win32.TrojanDownloader.Small.PR@5276zr
DrWebTrojan.DownLoad3.28161
ZillyaTrojan.Kryptik.Win32.3685627
TrendMicroTROJ_GEN.R002C0CB222
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.ct
SophosMal/Generic-S
APEXMalicious
JiangminTrojan/Buzus.bnwn
AviraTR/Crypt.Agent.xdqlq
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.3C0964
GridinsoftRansom.Win32.Zbot.sa
MicrosoftTrojan:Win32/Zbot.DSK!MTB
ViRobotTrojan.Win32.Upatre.51256
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Upatre.R284255
VBA32Trojan.Fareit.2883
ALYacTrojan.Downloader.JQAP
MalwarebytesTrojan.Upatre.Generic
IkarusTrojan-Spy.Win32.Zbot
RisingDropper.Generic!8.35E (TFE:dGZlOgVMxIOC84dlUQ)
YandexTrojan.GenAsa!dUSBw1EZjpA
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Upatre.Gen
FortinetW32/Kryptik.BIYN!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Zbot.DSK!MTB?

Trojan:Win32/Zbot.DSK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment