Malware

Win32:Zbot-LXB [Trj] removal tips

Malware Removal

The Win32:Zbot-LXB [Trj] is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32:Zbot-LXB [Trj] virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs

Related domains:

wpad.local-net

How to determine Win32:Zbot-LXB [Trj]?


File Info:

name: 72E61031C699EE9D53FD.mlw
path: /opt/CAPEv2/storage/binaries/22dd9c93e9c3adc162522657369c51b7a1eac85dd76eb0045881e97ca65119de
crc32: 0D2BBBA3
md5: 72e61031c699ee9d53fde4f7cd631e30
sha1: 459e77d1e556bf2fb2cbe5a7e71890f6160fb3e9
sha256: 22dd9c93e9c3adc162522657369c51b7a1eac85dd76eb0045881e97ca65119de
sha512: d06dc8bc0a8789eb6856ecbc868301127bba8baf65aa6a797dfc4cd49531e99cc166bf6e5db1843793c879ae9de4c58fcb86816dda494ee79ff3ec7d6e389173
ssdeep: 6144:Z0pqlAPM9FURIAw1FzOLDBNpQMI+UN3cE2/762W1T14wi/rVV9oKqzP8Mrwv9Y:ZRCk9gqzcAN3cJ/762q1uBV9oXzDa9Y
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CD94236F3CA49456DF5C1FBE032620C5EBB9CBD74E2676724C6DC38016049AB80AD5FA
sha3_384: 1dc9dc917086ca45a1d140519f45220276b40db3d52f018aa7e084cdf23684c4c838cf4f9730b1e936459c97620fabd3
ep_bytes: be00000000e8090000008b342483c404
timestamp: 2007-10-26 05:20:38

Version Info:

0: [No Data]

Win32:Zbot-LXB [Trj] also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.72e61031c699ee9d
McAfeePWS-Zbot.gen.auz
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.6396
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0054c19a1 )
AlibabaTrojanSpy:Win32/EncPk.518ca8b0
K7GWSpyware ( 0054c19a1 )
Cybereasonmalicious.1c699e
CyrenW32/Trojan.JPXN-7199
SymantecPacked.Generic.232
ESET-NOD32Win32/Spy.Zbot.JF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-47678
KasperskyTrojan-Spy.Win32.Zbot.gen
BitDefenderGen:Trojan.UserStartup.AmZ@ait6Eng
NANO-AntivirusTrojan.Win32.Zbot.coaikj
MicroWorld-eScanGen:Trojan.UserStartup.AmZ@ait6Eng
AvastWin32:Zbot-LXB [Trj]
TencentWin32.Trojan-spy.Zbot.Aisc
Ad-AwareGen:Trojan.UserStartup.AmZ@ait6Eng
SophosML/PE-A + Mal/EncPk-ACO
ComodoTrojWare.Win32.Spy.Zbot.AAK@1oqktf
DrWebTrojan.Webmoner.60957
VIPRETrojan-Spy.Win32.Zbot.gen (v)
TrendMicroTSPY_ZBOT.SMY
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftGen:Trojan.UserStartup.AmZ@ait6Eng (B)
IkarusPWS.Win32
GDataGen:Trojan.UserStartup.AmZ@ait6Eng
JiangminTrojanSpy.Zbot.oii
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.462B1
KingsoftWin32.Troj.Zbot.(kcloud)
GridinsoftRansom.Win32.Zbot.sa
MicrosoftTrojan:Win32/Zbot.SIBC21!MTB
AhnLab-V3Worm/Win32.IRCBot.R21348
Acronissuspicious
BitDefenderThetaAI:Packer.9DCAD7EB1E
ALYacGen:Trojan.UserStartup.AmZ@ait6Eng
MAXmalware (ai score=100)
VBA32Trojan.Buzus
TrendMicro-HouseCallTSPY_ZBOT.SMY
RisingTrojan.Generic@ML.90 (RDML:xAzga1b7hfIuMQKa19H+IA)
YandexTrojanSpy.ZBot.Gen!Pac.8
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.gen!tr
AVGWin32:Zbot-LXB [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Win32:Zbot-LXB [Trj]?

Win32:Zbot-LXB [Trj] removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment