Trojan

What is “Trojan:Win32/Zbot.RPT!MTB”?

Malware Removal

The Trojan:Win32/Zbot.RPT!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.RPT!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Attempts to modify proxy settings
  • Mimics icon used for popular non-executable file format
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zbot.RPT!MTB?


File Info:

name: D5C540AF67C8DC28BCFD.mlw
path: /opt/CAPEv2/storage/binaries/c0ab6e13944534853cf123e1ddeae1f5fc416c2ce7abb9cf3ca3d42810ef3924
crc32: FDA8A67F
md5: d5c540af67c8dc28bcfdc083f908a7cb
sha1: 9b291b7766f0cba6e5038487df6a86b560f0766a
sha256: c0ab6e13944534853cf123e1ddeae1f5fc416c2ce7abb9cf3ca3d42810ef3924
sha512: 63e278e0600aaed85d4b83c7f96c1633cd33b8b8dd9b03ff1568f6a6e1ec09029c6d902b4d57bd0c4fcc40379f8885dd4df716087acd2fd87846bb2782846ad6
ssdeep: 384:nXnpUoFA6/QkSxGJwlFYs3xMR5WYKZseH5P:XpUoFfSxGqHXBQFKVP
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F0383F0F582BD61E042043535BAF84C099D1E062B9D59EF7D99B22D46B13C170F9BAE
sha3_384: 85c28e7c1740b7ca5db1d44dac04d2eb5dae821b12025776632509bbbcb6a20632720b79324188e077582fa16ce57d7c
ep_bytes: 6a00ff1504305300a300405300e8cefe
timestamp: 2013-09-05 15:20:12

Version Info:

0: [No Data]

Trojan:Win32/Zbot.RPT!MTB also known as:

BkavW32.AIDetectMalware
MicroWorld-eScanGen:Trojan.Ipatre.1
ClamAVWin.Malware.Upatre-9956408-0
CAT-QuickHealTrojanDownloader.Upatre.A5
ALYacGen:Trojan.Ipatre.1
MalwarebytesMalware.AI.93090898
K7AntiVirusTrojan ( 005982871 )
K7GWTrojan ( 005982871 )
Cybereasonmalicious.f67c8d
BitDefenderThetaGen:NN.ZexaF.36164.cuX@aqmAEfji
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BNEA
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan.Win32.Bublik.flsx
BitDefenderGen:Trojan.Ipatre.1
SUPERAntiSpywareTrojan.Agent/Gen-Ipatre
AvastWin32:TrojanX-gen [Trj]
TencentTrojan.Win32.Kryptik.xm
SophosMal/Generic-S
BaiduWin32.Trojan-Spy.Zbot.a
F-SecureHeuristic.HEUR/AGEN.1315817
DrWebTrojan.DownLoad4.15729
VIPREGen:Trojan.Ipatre.1
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.Downloader.pt
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.d5c540af67c8dc28
EmsisoftGen:Trojan.Ipatre.1 (B)
IkarusTrojan.Crypt2
GDataGen:Trojan.Ipatre.1
JiangminTrojanDownloader.Agent.ejzn
AviraHEUR/AGEN.1315817
Antiy-AVLTrojan/Win32.Waski.a
XcitiumTrojWare.Win32.Xpack.AL@52f59j
ArcabitTrojan.Ipatre.1
ZoneAlarmTrojan.Win32.Bublik.flsx
MicrosoftTrojan:Win32/Zbot.RPT!MTB
GoogleDetected
AhnLab-V3Trojan/Win32.Bublik.C192078
McAfeeDownloader-FRZ
MAXmalware (ai score=80)
VBA32BScope.Malware-Cryptor.Ponik
Cylanceunsafe
PandaGeneric Malware
TrendMicro-HouseCallTROJ_UPATRE.SM37
RisingTrojan.DL.Win32.Upatre.agk (CLASSIC)
YandexTrojan.GenAsa!jYTZBwHjums
SentinelOneStatic AI – Suspicious PE
FortinetW32/Small.AABB!tr
AVGWin32:TrojanX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan:Win32/Zbot.RPT!MTB?

Trojan:Win32/Zbot.RPT!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment