Trojan

Trojan:Win32/Zbot.RB!MTB (file analysis)

Malware Removal

The Trojan:Win32/Zbot.RB!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.RB!MTB virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • The binary likely contains encrypted or compressed data.
  • Exhibits behavior characteristic of iSpy Keylogger
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan:Win32/Zbot.RB!MTB?


File Info:

crc32: EB123A4E
md5: ac5eb6172c287cbb954954b56586653f
name: AC5EB6172C287CBB954954B56586653F.mlw
sha1: 3bb19910b89a39274957959dec593964bcf12ee4
sha256: da23b9268823cc4bcc82fdc74b6bd9c5d8493347507f111de7c387cbe215b264
sha512: 55f33dc500a7c5ebac4efe9cc8399ec638afe6f9306cb18779825b7b82b5926a5c14f8f04ef8e9967640b3ea810dcf13587c9c15c064ab79ea1719e74620da89
ssdeep: 12288:3oNmzNhvQsYo9skrJouKDudlPRhirRCb8yyWHpd8Z8WQdQScE+G41AFQixYmw8Y:4NWNhxi6JoDkirQHLC
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) Scanderbeg 2018
InternalName: biosterin.exe
FileVersion: 8.6.1.1
CompanyName: supertension
ProductName: tend
ProductVersion: 4.4.2.6
FileDescription: generously
OriginalFilename: Skivvies.exe
Translation: 0x0409 0x04b0

Trojan:Win32/Zbot.RB!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Spy.21159
MicroWorld-eScanGen:Trojan.Heur.Py0@I5uk9!mi
FireEyeGeneric.mg.ac5eb6172c287cbb
CylanceUnsafe
SangforMalware
Cybereasonmalicious.72c287
InvinceaML/PE-A
BitDefenderThetaAI:Packer.CD69724E1C
CyrenW32/NanoBot.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:KeyloggerX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Trojan.Heur.Py0@I5uk9!mi
NANO-AntivirusTrojan.Win32.Packed2.fnnfdr
RisingTrojan.Generic@ML.100 (RDML:eL/0jWqni7hwLWwoVqxNMg)
Ad-AwareGen:Trojan.Heur.Py0@I5uk9!mi
EmsisoftGen:Trojan.Heur.Py0@I5uk9!mi (B)
F-SecureTrojan.TR/Dropper.Gen
TrendMicroBackdoor.Win32.ANDROM.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
JiangminBackdoor.MSIL.azdv
AviraTR/Dropper.Gen
MAXmalware (ai score=88)
MicrosoftTrojan:Win32/Zbot.RB!MTB
ArcabitTrojan.Heur.ED9D31
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Trojan.Heur.Py0@I5uk9!mi
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C3052201
Acronissuspicious
McAfeeGenericR-PBA!AC5EB6172C28
TACHYONTrojan-Exploit/W32.Shellcode.686592
MalwarebytesSpyware.HawkEyeKeyLogger
ZonerTrojan.Win32.75366
ESET-NOD32a variant of Win32/Kryptik.GQCW
TrendMicro-HouseCallBackdoor.Win32.ANDROM.SM.hp
YandexTrojan.GenAsa!P3GcQpdSRmQ
SentinelOneStatic AI – Malicious PE
AVGWin32:KeyloggerX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Zbot.RB!MTB?

Trojan:Win32/Zbot.RB!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment