Trojan

Trojan:Win32/Zbot.RPN!MTB removal

Malware Removal

The Trojan:Win32/Zbot.RPN!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.RPN!MTB virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Trojan:Win32/Zbot.RPN!MTB?


File Info:

name: 33C3998A76F9B4C13456.mlw
path: /opt/CAPEv2/storage/binaries/81aa984ace113c01334a3a19c0e7c2e39cd73ca87f906034c5d43eefd94cc5ae
crc32: 1A922363
md5: 33c3998a76f9b4c13456b279f040d896
sha1: 097eb3ff31d03ae44fd24f0fc78617b077f2b030
sha256: 81aa984ace113c01334a3a19c0e7c2e39cd73ca87f906034c5d43eefd94cc5ae
sha512: 17740b41ccacf51e0b630f11db987957a2408514c6847c356811892b7dab35a9d8de86b4e63a5bdbb2e8be4ed797ea525b32fb0ca2dfb299e79a219df6e09556
ssdeep: 3072:/ZVMfMIbIaw3J9FQxVSN/+BC3K5eqU+BC3K5eqYroGL2m6zo69t:/kfMmM/QzIK70K70y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CE849E41B3D0DE66E068263194778773067CBD25A26225AB27883F2FDDF02605A77F1B
sha3_384: 967a92c86c4de19823b27f5d7debe800b105c093c7ce5c772b968cd1fdadb41c50d20d50eba6f0bf0f39ffe22cad5fd8
ep_bytes: 00000000000000000000000000000000
timestamp: 2013-04-19 14:29:12

Version Info:

0: [No Data]

Trojan:Win32/Zbot.RPN!MTB also known as:

BkavW32.AIDetectMalware
CynetMalicious (score: 100)
FireEyeGeneric.mg.33c3998a76f9b4c1
CAT-QuickHealTrojanDropper.Gepys.A
ALYacTrojan.GenericKDZ.95808
MalwarebytesCrypt.Trojan.Malicious.DDS
VIPRETrojan.GenericKDZ.95808
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
CyrenW32/Gepys.BI.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Malware.Gepys-9770177-0
AvastWin32:Gepys-B [Trj]
TACHYONTrojan/W32.Agent.401408.AHA
SophosML/PE-A
BaiduWin32.Trojan.Kryptik.ed
F-SecureTrojan.TR/Crypt.XPACK.Gen7
DrWebTrojan.Mods.146
McAfee-GW-EditionBehavesLike.Win32.Generic.fz
Trapminemalicious.moderate.ml.score
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Win32.Wacatac
XcitiumTrojWare.Win32.Kryptik.AZD@4x83ou
MicrosoftTrojan:Win32/Zbot.RPN!MTB
GoogleDetected
AhnLab-V3Trojan/Win.ZBot.R588680
Acronissuspicious
VBA32Trojan.Redirect
Cylanceunsafe
RisingTrojan.Generic@AI.100 (RDML:MibdAKaEw1XJdOfZjFL6Bg)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Gepys.AOUM!tr
AVGWin32:Gepys-B [Trj]
DeepInstinctMALICIOUS

How to remove Trojan:Win32/Zbot.RPN!MTB?

Trojan:Win32/Zbot.RPN!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment