Trojan

Trojan:Win32/Zbot.VHO!MTB removal

Malware Removal

The Trojan:Win32/Zbot.VHO!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Zbot.VHO!MTB virus can do?

  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan:Win32/Zbot.VHO!MTB?


File Info:

name: F5748250898323BA62D4.mlw
path: /opt/CAPEv2/storage/binaries/b4354cb4328e4b01d461dbb714bc693d3f09df7afdb407f1f07618944e182a5c
crc32: F9D3C1D4
md5: f5748250898323ba62d4c008bdcb6223
sha1: c2b09ae8d872b013602cb8b23fdcd5bb7a26520a
sha256: b4354cb4328e4b01d461dbb714bc693d3f09df7afdb407f1f07618944e182a5c
sha512: e6f1df941c7e79df058040c0c0910f72c329e90885f862bbb33fb90c7a10d621cac822fd184d571d61ba1211b0b918d7d7849c916fca36f84dc92453f51c105a
ssdeep: 192:K5FzRJ0y4SCUSkgb+yaZOvQgck0LqvPnAeUgI6Y4wIrjl/IJggyL7JZjcYFfYIDq:K30y4exyCw/Al3kjlO4rj9p63
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CCA2AC785AE996B6E37BCE75C5FA41C6F831B4233D029D0D40CA43850C63F56EDA1A2E
sha3_384: 47ad69b2a95c3a310dbf6b8392690426161e82242b7788fef65dd93cdd46399630e27229b4d5ae0524e32b0821041cba
ep_bytes: 558d6c248881ecd408000053565733db
timestamp: 2014-01-27 12:19:18

Version Info:

0: [No Data]

Trojan:Win32/Zbot.VHO!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.DownLoad3.33424
MicroWorld-eScanTrojan.Ppatre.Gen.1
FireEyeGeneric.mg.f5748250898323ba
CAT-QuickHealDownloader.Upatre.27298
ALYacTrojan.Ppatre.Gen.1
MalwarebytesTrojan.Downloader
ZillyaDownloader.Waski.Win32.27818
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan-Downloader ( 004e48c71 )
K7AntiVirusTrojan-Downloader ( 004e48c71 )
BitDefenderThetaGen:NN.ZexaF.34114.byY@a0lYGfoi
CyrenW32/Upatre.JY.gen!Eldorado
ESET-NOD32a variant of Win32/TrojanDownloader.Waski.B
ClamAVWin.Malware.Upatre-6997681-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ppatre.Gen.1
NANO-AntivirusTrojan.Win32.DownLoad3.gsbnhl
AvastWin32:Upatre-V [Trj]
TencentMalware.Win32.Gencirc.10b8ac9f
Ad-AwareTrojan.Ppatre.Gen.1
EmsisoftTrojan.Ppatre.Gen.1 (B)
ComodoTrojWare.Win32.TrojanDownloader.Waski.BU@7nmtnf
SophosML/PE-A + Troj/Upatre-YS
IkarusTrojan-Downloader.Win32.Waski
JiangminTrojan.Generic.eminj
AviraHEUR/AGEN.1102633
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.2F62136
MicrosoftTrojan:Win32/Zbot.VHO!MTB
GDataWin32.Trojan-Downloader.Upatre.BJ
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.R98727
Acronissuspicious
McAfeeDownloader-FML!F57482508983
VBA32Trojan.Download
CylanceUnsafe
APEXMalicious
RisingTrojan.Generic@ML.100 (RDML:p7Sg3dz2nNqZSt2hleApfw)
YandexTrojan.GenAsa!FYPjqD2mojE
SentinelOneStatic AI – Malicious PE
FortinetW32/Waski.B!tr
AVGWin32:Upatre-V [Trj]
Cybereasonmalicious.089832
PandaTrj/Genetic.gen

How to remove Trojan:Win32/Zbot.VHO!MTB?

Trojan:Win32/Zbot.VHO!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment