Malware

How to remove “Zbot.118”?

Malware Removal

The Zbot.118 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zbot.118 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Mimics the system’s user agent string for its own requests
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Starts servers listening on 0.0.0.0:35844, :0, 127.0.0.1:39376
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Created a process from a suspicious location
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Performs a large number of encryption calls using the same key possibly indicative of ransomware file encryption behavior
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

How to determine Zbot.118?


File Info:

name: EE93BDB809B9A9ED5B60.mlw
path: /opt/CAPEv2/storage/binaries/ca24b1be9bdaedccf518a9fb231eed073574e5cfec9193dd0c1246befac587e1
crc32: 7E86ABD5
md5: ee93bdb809b9a9ed5b60140dadf31e44
sha1: 81a68c6b122ab510d5f463d41b5d0aa3a89f4b38
sha256: ca24b1be9bdaedccf518a9fb231eed073574e5cfec9193dd0c1246befac587e1
sha512: 1eeac3f511110150626a715a20afdeeba5dea34bf5b8c9cec0006204e5becbe10022ff2c5ccbe31325e0b117206c44de9d1e3e90a0bddccf7ab34db3e1e2b8f8
ssdeep: 24576:4IhNpKJGXKOMRxZUJIX+OQEDhFiw5JRlu5Ix1i:4IhqJGXK7RWIu4DbTsIx1i
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F535221AE4B9E0F6C83351340A71F6C5115979721B39E68B3BCCAEAB9F60C4057673B2
sha3_384: cf3045ec3b02474e3334a0059b5774cbef9ace1f879267b803943e074a65dba2642647ef7a92f60999764bbb7c9a5162
ep_bytes: e8781d0000e995feffff3b0d50d04000
timestamp: 2013-10-26 14:56:27

Version Info:

0: [No Data]

Zbot.118 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.ZBot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.547
CynetMalicious (score: 99)
FireEyeGeneric.mg.ee93bdb809b9a9ed
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacGen:Variant.Zbot.118
CylanceUnsafe
VIPRETrojan.Win32.Zbot.aauf (v)
SangforTrojan.Win32.ZBot.qolu
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojanSpy:Win32/Lethic.9207ccac
K7GWTrojan ( 0040f6901 )
K7AntiVirusTrojan ( 0040f6901 )
BitDefenderThetaGen:NN.ZexaF.34212.crZ@a4Bxtjli
VirITTrojan.Win32.Inject2.FX
CyrenW32/Agent.XH.gen!Eldorado
SymantecTrojan.Zbot!gen43
ESET-NOD32a variant of Win32/Injector.ALAO
TrendMicro-HouseCallTROJ_SPNR.35KD13
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-62891
KasperskyTrojan-Spy.Win32.ZBot.qolu
BitDefenderGen:Variant.Zbot.118
NANO-AntivirusTrojan.Win32.ZBot.crkvak
MicroWorld-eScanGen:Variant.Zbot.118
AvastWin32:Zbot-UKJ [Trj]
TencentMalware.Win32.Gencirc.10b50020
Ad-AwareGen:Variant.Zbot.118
SophosTroj/Zbot-GTB
ComodoTrojWare.Win32.Injector.ASGC@53s1mh
ZillyaTrojan.Zbot.Win32.143803
TrendMicroTROJ_SPNR.35KD13
McAfee-GW-EditionBehavesLike.Win32.Generic.tc
EmsisoftGen:Variant.Zbot.118 (B)
GDataGen:Variant.Zbot.118
JiangminTrojanSpy.Zbot.dxlv
WebrootW32.Rogue.Gen
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.55A59C
KingsoftWin32.Troj.Zbot.qo.(kcloud)
ArcabitTrojan.Zbot.118
ZoneAlarmTrojan-Spy.Win32.ZBot.qolu
MicrosoftTrojan:Win32/Lethic.B
SentinelOneStatic AI – Suspicious PE
AhnLab-V3Spyware/Win32.Zbot.R86751
McAfeePWSZbot-FDR!EE93BDB809B9
VBA32TrojanSpy.Zbot
MalwarebytesGeneric.Malware/Suspicious
APEXMalicious
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!7bs9lRjxj80
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.6611670.susgen
FortinetW32/Injector.AJAR!tr
AVGWin32:Zbot-UKJ [Trj]
PandaTrj/Genetic.gen

How to remove Zbot.118?

Zbot.118 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment