Spy Trojan

Trojan-Spy.Win32.Zbot.rhhu malicious file

Malware Removal

The Trojan-Spy.Win32.Zbot.rhhu is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.rhhu virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Arabic
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Zbot.rhhu?


File Info:

name: F5E2ADB6D79EB7BB634F.mlw
path: /opt/CAPEv2/storage/binaries/1e2623c17e4955fae07c6763e1b23f3b1d01a4aaac06d307042f29be8ec5cecc
crc32: 84ECD2B3
md5: f5e2adb6d79eb7bb634f9eed33ff754c
sha1: ae8761b0c155588eca69d58def8e46d2a1060f91
sha256: 1e2623c17e4955fae07c6763e1b23f3b1d01a4aaac06d307042f29be8ec5cecc
sha512: e58c7daca2133292f5b6b672630c3a6fdf1ea7a5dfaee3fe71736e94cd14edb1408970ad700ee6a9b04494be659230a48abda9a0c9671440eb60389ed7287506
ssdeep: 12288:G+ThrE567NIZN5BUIrzJY6Et+3kI7dC3X64P7r9r/+pppppppppppppppppppppt:G4JccI5BUcfEY7hO1qd0B3n1TSZrnBX
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1B725AE52E2904472D9661B389D3BCE749927BE647D34A84D2AED3E0F3F7E2823435193
sha3_384: 11c7a15e76b552a72a49e4aec4d881021efd59726d3c3ed3f795b6795ac3502f7520a347122142f16245f064f70be2ac
ep_bytes: 558bec83c4f0b80c2c4700e84033f9ff
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Trojan-Spy.Win32.Zbot.rhhu also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed.25509
FireEyeGeneric.mg.f5e2adb6d79eb7bb
CAT-QuickHealTrojanPWS.Zbot.A9
McAfeePWS-Zbot-FBGN!F5E2ADB6D79E
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Zbot.rhhu
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanSpy:Win32/Banker.4dec67eb
K7GWTrojan ( 7000000f1 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZelphiF.34212.!KX@au5Ri3eO
VirITTrojan.Win32.Generic.YAG
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.AAO
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.rhhu
BitDefenderTrojan.EmotetU.Gen.!KX@gu5Ri3eO
NANO-AntivirusTrojan.Win32.Zbot.cswryc
MicroWorld-eScanTrojan.EmotetU.Gen.!KX@gu5Ri3eO
TencentWin32.Trojan-atap.201210301199.Oatg
Ad-AwareTrojan.EmotetU.Gen.!KX@gu5Ri3eO
SophosMal/Generic-R + Troj/Delf-FSE
ComodoMalware@#2y09q2hjofgav
ZillyaTrojan.Zbot.Win32.147015
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftTrojan.EmotetU.Gen.!KX@gu5Ri3eO (B)
IkarusTrojan-Spy.Agent
GDataTrojan.EmotetU.Gen.!KX@gu5Ri3eO
JiangminTrojanSpy.Zbot.fgqo
WebrootW32.Trojan.Genkd
AviraDR/Delphi.Gen7
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.Heur.KVM007.a.(kcloud)
ArcabitTrojan.EmotetU.Gen.E02AD8
ZoneAlarmTrojan-Spy.Win32.Zbot.rhhu
MicrosoftPWS:Win32/Zbot
Acronissuspicious
VBA32TScope.Trojan.Delf
ALYacTrojan.EmotetU.Gen.!KX@gu5Ri3eO
MAXmalware (ai score=100)
MalwarebytesMalware.Heuristic.1001
APEXMalicious
RisingTrojan.Spy.Win32.Zbot.gha (CLOUD)
YandexTrojanSpy.Zbot!z4uN1MK8KQs
SentinelOneStatic AI – Malicious PE
eGambitGeneric.PSW
FortinetW32/Injector.AXAZ!tr
Cybereasonmalicious.6d79eb
PandaTrj/Zbot.M
MaxSecureTrojan.Malware.300983.susgen

How to remove Trojan-Spy.Win32.Zbot.rhhu?

Trojan-Spy.Win32.Zbot.rhhu removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment