Malware

Zbot.82 removal

Malware Removal

The Zbot.82 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Zbot.82 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Starts servers listening on 0.0.0.0:25221, :0
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Steals private information from local Internet browsers
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • A process sent information about the computer to a remote location.
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Harvests credentials from local FTP client softwares
  • Clears web history

How to determine Zbot.82?


File Info:

name: 8F4CED76B4032DFD3978.mlw
path: /opt/CAPEv2/storage/binaries/c0e785a2f6e717d3f69f15b144d5e06e2bb9934f54e9f3334517fb24881cb0ec
crc32: 87D179C2
md5: 8f4ced76b4032dfd39789622795146b3
sha1: 278d6583555af7f482d40028978556fb9d36163e
sha256: c0e785a2f6e717d3f69f15b144d5e06e2bb9934f54e9f3334517fb24881cb0ec
sha512: ca693af20496fbb17e66ce7e94ced4b163fe0e15cc96617ff29b48de411cd48042ed5d231f8962e33adae0efb8b9a52a3ee83052845a8d11d366d74de06ca9a5
ssdeep: 3072:VQ3LCSB9fx7Egce+6SNAa7L4DVbZfpvBR0D4f5t0:VEekJZS2K78Ffo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T104F3E0D739015275C5AE9772890EF3A3C60B3F7C3AB2713676E31E1B46990248E609BD
sha3_384: d47a4421742ac492fd2cbf595bbe5489ef2757bceb2a9516ed29858de3992a706c47a43291637661191ffadc3adc8672
ep_bytes: 558bec6aff6810ed410068b07a410064
timestamp: 2012-10-21 05:21:22

Version Info:

CompanyName: very
FileVersion: 8.8.769.25
FileDescription: very Get
LegalCopyright: Copyright (C) 2004-2011
InternalName: Get
OriginalFilename: Final.exe
ProductName: very Get
ProductVersion: 8.8.769.25
Translation: 0x0419 0x04b0

Zbot.82 also known as:

LionicTrojan.Win32.Zbot.4!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Panda.1524
MicroWorld-eScanGen:Variant.Zbot.82
FireEyeGeneric.mg.8f4ced76b4032dfd
ALYacGen:Variant.Zbot.82
MalwarebytesMalware.Heuristic.1001
ZillyaTrojan.Zbot.Win32.209492
SangforTrojan.Win32.Zbot.mt
K7AntiVirusPassword-Stealer ( 0040f4e51 )
AlibabaTrojanSpy:Win32/Ramnit.095fdd0c
K7GWPassword-Stealer ( 0040f4e51 )
Cybereasonmalicious.6b4032
BitDefenderThetaGen:NN.ZexaF.34212.jq1@aSnj4Xpc
VirITWin32.Cheburgen.A
CyrenW32/Trojan.HTBJ-8757
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.YW
TrendMicro-HouseCallTSPY_BUBLIK_BL132B49.TOMC
Paloaltogeneric.ml
ClamAVWin.Trojan.Virut-74
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Zbot.82
NANO-AntivirusTrojan.Win32.Panda.bbxbpv
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
TencentWin32.Trojan.Generic.Ecum
Ad-AwareGen:Variant.Zbot.82
TACHYONTrojan/W32.Bublik.160000
SophosMal/Generic-R + Mal/Zbot-IU
ComodoMalware@#2k3zd4zw5zo6d
VIPRETrojan.Win32.Zbot.ata (v)
TrendMicroTSPY_BUBLIK_BL132B49.TOMC
McAfee-GW-EditionBehavesLike.Win32.QLowZones.ch
EmsisoftGen:Variant.Zbot.82 (B)
IkarusVirus.Win32.Ramnit
GDataGen:Variant.Zbot.82
JiangminTrojanSpy.Zbot.ckys
WebrootW32.Infostealer.Zeus
AviraTR/ATRAPS.Gen
Antiy-AVLTrojan/Win32.Unknown
ArcabitTrojan.Zbot.82
ViRobotTrojan.Win32.A.Bublik.159744.G
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot
CynetMalicious (score: 100)
Acronissuspicious
VBA32TrojanSpy.Zbot
MAXmalware (ai score=99)
CylanceUnsafe
APEXMalicious
RisingWin32.Virut.GEN (CLOUD)
YandexTrojan.GenAsa!0V9s3tS6hrw
SentinelOneStatic AI – Malicious PE
FortinetW32/Zbot.PKJO!tr
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Zbot.82?

Zbot.82 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment