Trojan

Should I remove “Trojan:Win32/Zbot.RPG!MTB”?

Malware Removal

The Trojan:Win32/Zbot.RPG!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.RPG!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Collects information to fingerprint the system

How to determine Trojan:Win32/Zbot.RPG!MTB?


File Info:

name: 6A1E28142B3C565A57DA.mlw
path: /opt/CAPEv2/storage/binaries/49c353dfba821edfdd84ebec7903e52b9ef52f5c1f82b6e2f57f3031e7be8a12
crc32: BB1B3496
md5: 6a1e28142b3c565a57da7141f9760faf
sha1: 4b07932f39ff86f3bbe866e521534c8175a33dd0
sha256: 49c353dfba821edfdd84ebec7903e52b9ef52f5c1f82b6e2f57f3031e7be8a12
sha512: aca6b43b0bb0c68a77efce2bef8b95b60edae5e6e1a1cdaa7be05b34fccf81ed19b53867b225b1ddf35731c15d7c24fd077a4b005a002456bf61e5a35bc1ee59
ssdeep: 3072:L9s4j1DcPQLFtr/SzSdQJSz3pRM5warpRap:Hj1oIn/SzSbzU5warpW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19B849CCE7E908C43E811793FA857CFF80A71BC398965425332F5EA5FECB2250D92A611
sha3_384: 4fe55800b2a1d0bd53a522830f89a975e488961d6f2f857edb8d81d80dd28a0544be7e954bb6316b34e5af99c9fbd056
ep_bytes: 535152c8800000c7458001000000eb23
timestamp: 2010-10-18 02:47:44

Version Info:

0: [No Data]

Trojan:Win32/Zbot.RPG!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.lUUy
MicroWorld-eScanTrojan.GenericKD.62402152
ClamAVWin.Trojan.Agent-1311818
FireEyeGeneric.mg.6a1e28142b3c565a
McAfeeDropper-FGD!6A1E28142B3C
CylanceUnsafe
VIPRETrojan.GenericKD.62402152
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f4c81 )
AlibabaTrojan:Win32/Kryptik.b7e387c0
K7GWTrojan ( 0040f4c81 )
Cybereasonmalicious.42b3c5
VirITTrojan.Win32.Generic.AVHZ
CyrenW32/GenTroj.BW.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BDIA
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.GenericKD.62402152
NANO-AntivirusVirus.Win32.Virut-Gen.bwpxnc
AvastWin32:Kryptik-MBL [Trj]
TencentWin32.Trojan.Generic.Dnhl
Ad-AwareTrojan.GenericKD.62402152
EmsisoftTrojan.GenericKD.62402152 (B)
ComodoTrojWare.Win32.ShipUp.CJB@4yle00
DrWebTrojan.Mods.1
ZillyaTrojan.Kryptik.Win32.3919456
TrendMicroPAK_Xed-21
McAfee-GW-EditionBehavesLike.Win32.PinkSbot.fz
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Gepys-A
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.E9CWI8
JiangminTrojan/ShipUp.qq
AviraTR/Crypt.ZPACK.Gen2
MAXmalware (ai score=80)
Antiy-AVLTrojan/Generic.ASMalwS.50E8
MicrosoftTrojan:Win32/Zbot.RPG!MTB
GoogleDetected
AhnLab-V3Win-Trojan/Dofoil.Gen
BitDefenderThetaGen:NN.ZexaF.34698.yuX@aCbUpZl
ALYacTrojan.GenericKD.62402152
VBA32BScope.Trojan.Mods
MalwarebytesMalware.AI.332859870
TrendMicro-HouseCallPAK_Xed-21
RisingDropper.Gepys!8.15D (TFE:5:TkUUJAYEv2G)
YandexTrojan.Agent!nKZwcinwxz0
IkarusTrojan-Downloader.Win32.Dofoil
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.BCX!tr
AVGWin32:Kryptik-MBL [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Zbot.RPG!MTB?

Trojan:Win32/Zbot.RPG!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment