Spy Trojan

Trojan.Spy.Zbot.FCQ (B) removal guide

Malware Removal

The Trojan.Spy.Zbot.FCQ (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Zbot.FCQ (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Presents an Authenticode digital signature
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial binary language: Russian
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Deletes executed files from disk
  • Collects information to fingerprint the system

How to determine Trojan.Spy.Zbot.FCQ (B)?


File Info:

name: 0644661EF70C6FA23084.mlw
path: /opt/CAPEv2/storage/binaries/5fd8297fcc21c0407cf9c5027728ebfd3aa1be98ece1575224c2f9f516edef33
crc32: B22D3B78
md5: 0644661ef70c6fa23084aceb87bee6e7
sha1: 14641962b2c475b59eed415403458e9a8a5909d2
sha256: 5fd8297fcc21c0407cf9c5027728ebfd3aa1be98ece1575224c2f9f516edef33
sha512: 35db884f293f595db49a46abb72c9aadc1deaa7e3656dbeddb90455456e924f42ee27c7bd795bb1d905e355a8e16f03ef88bae479070a9e881dc555d36e2f3df
ssdeep: 6144:nWGz3ndCM8GHAXlGCe9hIViUHOo3J6ukp5u90MYq+ZdN1uP3bf:Wg3kBwA14hechu+ncPz
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A474E05B9EBCFE07DCFD963589F3A4FA0120BE403725657622BBFB186831990E461346
sha3_384: 88a18b0c1ba152d3b0065061b250af0ee177fefffb3744ae645e3cf481a595e19092c625934806c063156cf094d59f88
ep_bytes: 558bec68007f00006a00ff158cd04000
timestamp: 2013-01-10 02:03:02

Version Info:

CompanyName: Корпорация Майкрософт
FileDescription: Звукозапись
FileVersion: 5.1.2600.5512 (xpsp.080413-0845)
InternalName: soundrec.exe
LegalCopyright: © Корпорация Майкрософт. Все права защищены.
OriginalFilename: sndrec32.exe
ProductName: Операционная система Microsoft® Windows®
ProductVersion: 5.1.2600.5512
Translation: 0x0419 0x04b0

Trojan.Spy.Zbot.FCQ (B) also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.lIty
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.Spy.Zbot.FCQ
FireEyeGeneric.mg.0644661ef70c6fa2
CAT-QuickHealTrojanPWS.Zbot.Gen
ALYacTrojan.Spy.Zbot.FCQ
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.118226
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f0ce1 )
AlibabaTrojanPSW:Win32/Karagany.54ec6e4e
K7GWTrojan-Downloader ( 0040f0ce1 )
CrowdStrikewin/malicious_confidence_100% (W)
VirITTrojan.Win32.Banker.QF
CyrenW32/Zbot.GX.gen!Eldorado
SymantecTrojan.Zbot
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Zbot-9946248-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Spy.Zbot.FCQ
NANO-AntivirusTrojan.Win32.ZBot.bfzyve
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Agent-AQST [Trj]
TencentMalware.Win32.Gencirc.10b65a85
Ad-AwareTrojan.Spy.Zbot.FCQ
TACHYONTrojan-Spy/W32.ZBot.346888
EmsisoftTrojan.Spy.Zbot.FCQ (B)
ComodoTrojWare.Win32.Kryptik.ARUU@4t6sac
DrWebTrojan.Packed.23728
VIPRETrojan.Spy.Zbot.FCQ
TrendMicroTROJ_SIGEKAF.SM
McAfee-GW-EditionPWS-Zbot.gen.aua
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/Zbot-DMQ
SentinelOneStatic AI – Malicious PE
GDataTrojan.Spy.Zbot.FCQ
JiangminTrojan/PSW.Tepfer.aelq
WebrootW32.Rogue.Gen
GoogleDetected
AviraTR/Spy.Zbot.3468897
Antiy-AVLTrojan/Generic.ASMalwS.31
KingsoftWin32.Troj.Zbot.ia.(kcloud)
ArcabitTrojan.Spy.Zbot.FCQ
MicrosoftPWS:Win32/Zbot!GO
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R47869
McAfeePWS-Zbot.gen.aua
MAXmalware (ai score=100)
VBA32BScope.Trojan.Packed
MalwarebytesTrojan.Zbot
TrendMicro-HouseCallTROJ_SIGEKAF.SM
RisingTrojan.Suuware!1.663F (CLASSIC)
YandexTrojan.GenAsa!qY7z1ltO4HI
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/ZBOT.QT!tr
BitDefenderThetaGen:NN.ZexaF.34698.v82@ayhMAjyc
AVGWin32:Agent-AQST [Trj]
Cybereasonmalicious.ef70c6
PandaTrj/Hexas.HEU

How to remove Trojan.Spy.Zbot.FCQ (B)?

Trojan.Spy.Zbot.FCQ (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment