Malware

About “Zbot.106 (B)” infection

Malware Removal

The Zbot.106 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zbot.106 (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Transacted Hollowing
  • Detects Bochs through the presence of a registry key
  • Collects information to fingerprint the system

How to determine Zbot.106 (B)?


File Info:

name: 2987C07E62ADDAD955D9.mlw
path: /opt/CAPEv2/storage/binaries/e749d541c6f761b6807fe01282821506b5f4e5f024d5aa946298915ea529529f
crc32: 2F94CB23
md5: 2987c07e62addad955d9bf806ddbf0f0
sha1: 4482c28fbd9c2c38018c801e6893a4a029075610
sha256: e749d541c6f761b6807fe01282821506b5f4e5f024d5aa946298915ea529529f
sha512: 37e6ccf1f215eb127e467754560cf5f4de788b03fe53264e356a2fd695b68e8204c370dda92639559c70a558fd323bd10c490122fcbea3534931241a85d6286a
ssdeep: 3072:ITzaHXmzyNSMFKD4cmPujOgj8+kgZjjnD5iURSVdHlKxsY:IT+HXmFMkccSmpNnRRS7HSsY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T122E3C054818E82D5C076543CD9A2A920A7723D236F19F203B7B3A6E2F4BBC45E674377
sha3_384: 49ad9fd18d4d255d1f55f6d7cdf0437bc0f365de0b7a0569d33690767aff207ee38ec8054351e8dabcf173d5e04d24e2
ep_bytes: 64a1000000005589e56aff681c504000
timestamp: 2013-05-02 10:26:48

Version Info:

0: [No Data]

Zbot.106 (B) also known as:

LionicTrojan.Win32.Generic.lJta
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Zbot.106
FireEyeGeneric.mg.2987c07e62addad9
CAT-QuickHealTrojanDropper.Gepys.A
McAfeeDropper-FEU!2987C07E62AD
CylanceUnsafe
VIPREGen:Variant.Zbot.106
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 005450b41 )
BitDefenderGen:Variant.Zbot.106
K7GWTrojan ( 005450b41 )
Cybereasonmalicious.e62add
BaiduWin32.Trojan.Injector.jn
VirITTrojan.Win32.Mods.AP
CyrenW32/Gepys.AR.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.BACR
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Malware.Zbot-6840966-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Gepys.bad40134
NANO-AntivirusVirus.Win32.Gen.ccmw
RisingDropper.Gepys!8.15D (TFE:1:onvE3BvEksL)
Ad-AwareGen:Variant.Zbot.106
SophosMal/Generic-S + Troj/AutoG-AC
ComodoTrojWare.Win32.Kryptik.BAC@4x91az
DrWebTrojan.Mods.1
ZillyaTrojan.Kryptik.Win32.375422
TrendMicroTROJ_KRYPTO.SMAX
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Zbot.106 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen7
Antiy-AVLTrojan/Generic.ASMalwS.217
MicrosoftTrojan:Win32/Gepys.A!MTB
SUPERAntiSpywareTrojan.Agent/Gen-Kryptik
GDataWin32.Trojan.PSE.1V9D15H
GoogleDetected
AhnLab-V3Trojan/Win32.Shipup.R66583
BitDefenderThetaGen:NN.ZexaF.34606.iyX@aebPYnni
ALYacGen:Variant.Zbot.106
VBA32SScope.Malware-Cryptor.Carberp.2313
MalwarebytesMalware.AI.384707121
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_KRYPTO.SMAX
TencentMalware.Win32.Gencirc.10b0d148
YandexTrojan.Kryptik!dRAQ0Vn4Nrc
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Kryptik.AYTT!tr
AVGWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zbot.106 (B)?

Zbot.106 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment