Spy Trojan

Trojan.Spy.Zbot.FHS removal instruction

Malware Removal

The Trojan.Spy.Zbot.FHS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Zbot.FHS virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Spy.Zbot.FHS?


File Info:

name: FC91F2D00D0395A3BF14.mlw
path: /opt/CAPEv2/storage/binaries/fa0727fd979f6f66729fd87e8133954a20bcedffcd1d28d15335b2a1da5c752c
crc32: 2C1C670D
md5: fc91f2d00d0395a3bf14d851261877e7
sha1: 0c028afad43c09644f4b24215b36bd4cb954bf43
sha256: fa0727fd979f6f66729fd87e8133954a20bcedffcd1d28d15335b2a1da5c752c
sha512: ede8896d74da65af174645440e0279ff039901e9769873ea65ddc53b1cd9357ceaf6e0c43db6c4bfa9d1983854cedcdbd312299d0ca6cbebb51383bc7938aeb2
ssdeep: 6144:P7Fv+1AnqWa3mK9pH5nBHV4+GI133udyD:TF+ua5pl9V4+F1Hu4D
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1A224127166CD5798C5F332391E8DBBB24AF577206B82083563F43BE780471E6AA2D21D
sha3_384: f073c2621f1754aa7e31c0a14407876d80dee058e2ed048985a5dadd37ca2c40b61c73df188f6b2e3136f7ffe8c50e0d
ep_bytes: 558bec81ec780100008b0d984f430083
timestamp: 2012-07-23 11:27:49

Version Info:

0: [No Data]

Trojan.Spy.Zbot.FHS also known as:

BkavW32.AIDetect.malware2
tehtrisGeneric.Malware
DrWebTrojan.DownLoader10.59765
MicroWorld-eScanTrojan.Spy.Zbot.FHS
CAT-QuickHealFraudTool.Security
ALYacTrojan.Spy.Zbot.FHS
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.143967
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f8b21 )
K7GWTrojan ( 0040f8b21 )
Cybereasonmalicious.00d039
BitDefenderThetaGen:NN.ZexaF.34698.nuX@aulz4bqS
VirITTrojan.Win32.Generic.AOCF
CyrenW32/Trojan.JEUO-8052
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.ABA
APEXMalicious
ClamAVWin.Trojan.Zbot-60877
KasperskyTrojan.Win32.Yakes.duxk
BitDefenderTrojan.Spy.Zbot.FHS
NANO-AntivirusTrojan.Win32.Yakes.cqqfxz
SUPERAntiSpywareTrojan.Agent/Gen-Zbot
AvastWin32:Kryptik-OEU [Trj]
TencentMalware.Win32.Gencirc.10b283dd
Ad-AwareTrojan.Spy.Zbot.FHS
EmsisoftTrojan.Spy.Zbot.FHS (B)
ComodoTrojWare.Win32.ZPACK.ABA@54zxoz
F-SecureTrojan.TR/PSW.Zbot.AP.18
BaiduWin32.Trojan.Kryptik.v
VIPRETrojan.Spy.Zbot.FHS
TrendMicroTSPY_ZBOT.SMB3
McAfee-GW-EditionBehavesLike.Win32.Packed.dc
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.fc91f2d00d0395a3
SophosML/PE-A + Troj/Agent-AGPI
SentinelOneStatic AI – Malicious PE
GDataTrojan.Spy.Zbot.FHS
JiangminTrojan/Yakes.mmf
WebrootW32.Trojan.Gen
GoogleDetected
AviraTR/PSW.Zbot.AP.18
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Yakes
KingsoftWin32.Troj.Yakes.du.(kcloud)
ArcabitTrojan.Spy.Zbot.FHS
ZoneAlarmTrojan.Win32.Yakes.duxk
MicrosoftTrojan:Win32/Bulta!rfn
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Tepfer.R90491
Acronissuspicious
McAfeeObfuscated-FAFP!hb
TACHYONTrojan/W32.Yakes.221267
VBA32BScope.Malware-Cryptor.Hlux
MalwarebytesBackdoor.Agent.RND
TrendMicro-HouseCallTSPY_ZBOT.SMB3
RisingTrojan.Bulta!8.35D (TFE:2:U0lLS6AwBQU)
YandexTrojan.Yakes!9dYvOtceOIQ
IkarusTrojan-PWS.Win32.Zbot
MaxSecureTrojan.Yakes.DGen
FortinetW32/Kryptik.CAAF!tr
AVGWin32:Kryptik-OEU [Trj]
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.Spy.Zbot.FHS?

Trojan.Spy.Zbot.FHS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment