Trojan

Trojan:Win32/Zbot.Q!MTB removal instruction

Malware Removal

The Trojan:Win32/Zbot.Q!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.Q!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zbot.Q!MTB?


File Info:

name: C59D873FD0B447DF02A9.mlw
path: /opt/CAPEv2/storage/binaries/a6f1f5cc8c17c749dc636a8d3de6ea0abd2fd6bb0d3b1bce59ff3b70ddc3ba51
crc32: 84DA044C
md5: c59d873fd0b447df02a9ae999f8b5506
sha1: 6d1b2c88e0291d991204be4f426924893e42acb8
sha256: a6f1f5cc8c17c749dc636a8d3de6ea0abd2fd6bb0d3b1bce59ff3b70ddc3ba51
sha512: e790903e3335cd462aaa48f56717861c5c8a44f924ad8e0291bfbd9992eb1b597877d8f42600688ab5719f60360c0e5fe319d2cd233569edda6cbbf041b7a180
ssdeep: 3072:UOQdvPIiA6IM2RpqWMl/S8Zfx/1DuoupjPUeaHcHc:JaPT2t5cfxNDuoNeAU
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T179C3E1017B75C8A3C162023089ADC6BBED12BFB65674453B73D31D2B2DBA472CE52639
sha3_384: fe56b11905acf7a7d90066e712cc4fd8a8184d2a707da191e374cf07a482552efa1c3399339686787e8d551242adef3e
ep_bytes: 8bff558bec83ec5c56576a00ff150c30
timestamp: 2011-05-23 21:18:45

Version Info:

CompanyName: BitDefender
FileDescription: Platinum Scanner
FileVersion: 4.1.500.3001
InternalName: Ptscan.exe
LegalCopyright: Copyright (c) 2011 ptsd
OriginalFilename: Ptscan.exe
ProductName: Platinum Scanner
ProductVersion: 4.1.500.3001
Translation: 0x041b 0x04b0

Trojan:Win32/Zbot.Q!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.c59d873fd0b447df
ALYacGen:Heur.Conjar.2
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Kryptik.OHK
AlibabaTrojan:Win32/Kryptik.a8aa2ff1
Cybereasonmalicious.fd0b44
VirITTrojan.Win32.Zyx.BH
CyrenW32/Ransom.O.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Kryptik.OHK
APEXMalicious
ClamAVWin.Trojan.Zbot-19524
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Heur.Conjar.2
NANO-AntivirusTrojan.Win32.Panda.chkof
ViRobotTrojan.Win32.Zbot.129536.I
MicroWorld-eScanGen:Heur.Conjar.2
AvastWin32:Kryptik-CTB [Trj]
TencentMalware.Win32.Gencirc.10b9b3ab
Ad-AwareGen:Heur.Conjar.2
EmsisoftGen:Heur.Conjar.2 (B)
ComodoMalware@#3n5nlu39xon8n
DrWebTrojan.PWS.Panda.550
TrendMicroTROJ_ZBOT.SMP1
McAfee-GW-EditionPWS-Zbot.gen.awk
SophosML/PE-A + Mal/FakeAV-LX
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Conjar.2
JiangminTrojanSpy.Zbot.bafs
WebrootW32.Infostealer.Zeus
AviraTR/Spy.Zbot.boux.1
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.2021727
SUPERAntiSpywareHeur.Agent/Gen-StaticIcon
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojan:Win32/Zbot.Q!MTB
AhnLab-V3Trojan/Win32.Zbot.C59433
Acronissuspicious
McAfeePWS-Zbot.gen.awk
VBA32TrojanSpy.Zbot
MalwarebytesMalware.AI.1556638210
TrendMicro-HouseCallTROJ_ZBOT.SMP1
RisingTrojan.Kryptik!8.8 (CLOUD)
IkarusTrojan.SuspectCRC
FortinetW32/Generic.AC.230275!tr
BitDefenderThetaGen:NN.ZexaF.34212.hy0@a4yvEnnk
AVGWin32:Kryptik-CTB [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.2647785.susgen

How to remove Trojan:Win32/Zbot.Q!MTB?

Trojan:Win32/Zbot.Q!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment