Malware

Zbot.111 information

Malware Removal

The Zbot.111 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zbot.111 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Zbot.111?


File Info:

name: D671FD3AC826EB00F062.mlw
path: /opt/CAPEv2/storage/binaries/d08984a46879cdc52926f3790cfdf2331f29d0632ad6b1f2bf1770ae51015af5
crc32: 040A9834
md5: d671fd3ac826eb00f0620b24ca3cfa02
sha1: 016b75007725773c1921f4a32cd789b823b18254
sha256: d08984a46879cdc52926f3790cfdf2331f29d0632ad6b1f2bf1770ae51015af5
sha512: 3d3ffe860bf4b062cdb280144496242f538dcf19428db6021f9f813027be189e1ed7fc19364dd519b896cfd496854f17218931d11ef1a782bd1ec697da5e26ab
ssdeep: 6144:iKRrwhDzkZ3MJkVwSyFoHLWEBeHu/egptOtsT7:iK+GZ35VBHheObpcOT7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D4541211B7518601E8C08977E6C3DA2BCBAD6E64D9267DCB814C3DF4A7F42F0EA35261
sha3_384: 583524d8e1c1980d4cfb2c41a90e8cb80ef87e6ec1af560c701940ce98489cbc4d8e64d1bc9c0a1d9d193cbbee5eeb16
ep_bytes: 558bec6aff6820314400688412440064
timestamp: 2013-07-05 16:00:02

Version Info:

CompanyName: The OpenSSL Project, http://www.openssl.org/
FileDescription: OpenSSL Shared Library
FileVersion: 0.9.8g
InternalName: ssleay32
OriginalFilename: ssleay32.dll
ProductName: The OpenSSL Toolkit
ProductVersion: 0.9.8g
LegalCopyright: Copyright В© 1998-2005 The OpenSSL Project. Copyright В© 1995-1998 Eric A. Young, Tim J. Hudson. All rights reserved.
Translation: 0x0409 0x04b0

Zbot.111 also known as:

LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Zbot.111
FireEyeGeneric.mg.d671fd3ac826eb00
ALYacGen:Variant.Zbot.111
SangforTrojan.Win32.Kryptik.BFEI
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004bb7d31 )
K7AntiVirusTrojan ( 004bb7d31 )
BitDefenderThetaGen:NN.ZexaF.34182.rq0@aq4afjdi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.BFEI
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zbot.111
NANO-AntivirusTrojan.Win32.Zbot.crsico
APEXMalicious
EmsisoftGen:Variant.Zbot.111 (B)
ComodoMalware@#3fkpuo29ftrlv
DrWebTrojan.PWS.Panda.2401
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionPWS-Zbot-FBBP!D671FD3AC826
SophosML/PE-A + Mal/Zbot-NP
IkarusVirus.Win32.Virut
AviraHEUR/AGEN.1241518
MAXmalware (ai score=84)
Antiy-AVLTrojan[Spy]/Win32.Zbot
MicrosoftPWS:Win32/Zbot
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Zbot.111
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R73474
McAfeePWS-Zbot-FBBP!D671FD3AC826
VBA32Malware-Cryptor.InstallCore.gen
CylanceUnsafe
AvastWin32:Agent-AYHX [Trj]
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojanSpy.Zbot!7HF+gwldyAU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.ATGL!tr
AVGWin32:Agent-AYHX [Trj]
Cybereasonmalicious.ac826e
PandaTrj/Dtcontx.F

How to remove Zbot.111?

Zbot.111 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment