Malware

Zbot.35 removal tips

Malware Removal

The Zbot.35 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zbot.35 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • A process attempted to delay the analysis task by a long amount of time.

How to determine Zbot.35?


File Info:

name: 0F88006478031E9D0AD2.mlw
path: /opt/CAPEv2/storage/binaries/fa31d2d4bed3a27465b842a6ca3fad341438081f9f2e0144f1a454d5034393da
crc32: 31B716A8
md5: 0f88006478031e9d0ad2397b16fafb87
sha1: b0fbe1aa9d5c5a92df57c35dccec5482e68483ab
sha256: fa31d2d4bed3a27465b842a6ca3fad341438081f9f2e0144f1a454d5034393da
sha512: 3fbf53d1c345da9e26711ab86d9d12bb1cda39e7e2d47681af50e0067a8f7fee810f95fee4fafea0df1b44b6e077222a90a5c093649a6969f6b9c306c86cbade
ssdeep: 384:mkXFtmIC2CGnPgsRC38cwjkmGdXG0z+//7JoVOozQPJ2w2Bfhwd/BBB0eIc3N+K:mkXcyId60zU7JocEQPIw2BfhFm
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T147B26D31ABDB311BFDD7953852F213279A23AA20D1F6F8A792111E1333716D5A2C075E
sha3_384: b7a92e1a3420e5f2ca356325b586629b6ab2544ac5adb1a29f634a95c6df91d8fe0092fedee828effe2dda7cbb838201
ep_bytes: 558bec81ec380100008b9574ffffff89
timestamp: 2006-04-16 03:04:32

Version Info:

0: [No Data]

Zbot.35 also known as:

LionicTrojan.Win32.Generic.4!c
tehtrisGeneric.Malware
DrWebTrojan.Packed.1882
MicroWorld-eScanGen:Variant.Zbot.35
ALYacGen:Variant.Zbot.35
CylanceUnsafe
VIPREGen:Variant.Zbot.35
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 002050501 )
AlibabaVirTool:Win32/Obfuscator.7a5ba457
K7GWTrojan-Downloader ( 000ea6831 )
Cybereasonmalicious.478031
CyrenW32/Downloader.CA.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.KMX
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Downloader.131461-1
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zbot.35
NANO-AntivirusTrojan.Win32.Kryptik.fomwui
SUPERAntiSpywareTrojan.Agent/Gen-Kazy
AvastWin32:MalOb-FM [Cryp]
TencentWin32.Trojan-Downloader.Piker.fwy
Ad-AwareGen:Variant.Zbot.35
EmsisoftGen:Variant.Zbot.35 (B)
ZillyaTrojan.Kryptik.Win32.3622279
TrendMicroTROJ_KRYPTK.SMH
McAfee-GW-EditionPWS-Zbot.gen.ia
FireEyeGeneric.mg.0f88006478031e9d
SophosMal/Generic-S + Mal/FakeAV-GQ
GDataGen:Variant.Zbot.35
JiangminTrojanDownloader.Piker.bwn
WebrootW32.Kelihos.B
AviraTR/Crypt.XPACK.Gen2
Antiy-AVLTrojan/Generic.ASMalwS.3303
KingsoftWin32.Malware.Heur_Generic.B.(kcloud)
ArcabitTrojan.Zbot.35
ViRobotTrojan.Win32.A.Downloader.23552.LX
MicrosoftTrojanDownloader:Win32/Waledac.C
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.FakeAV.R2850
McAfeePWS-Zbot.gen.ia
MAXmalware (ai score=100)
VBA32BScope.Trojan.Downloader
TrendMicro-HouseCallTROJ_KRYPTK.SMH
RisingTrojan.Generic@AI.99 (RDML:c2uLR3u00kd2biBq1WigXA)
YandexTrojan.DL.Piker!g2X4zzIE1WI
IkarusTrojan-Downloader.Win32.Piker
FortinetW32/Goolbot.KA!tr.bdr
AVGWin32:MalOb-FM [Cryp]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Zbot.35?

Zbot.35 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment