Spy Trojan

Trojan.Spy.Zbot.FJB (B) malicious file

Malware Removal

The Trojan.Spy.Zbot.FJB (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Zbot.FJB (B) virus can do?

  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Starts servers listening on 0.0.0.0:20020, :0
  • Enumerates running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Code injection with CreateRemoteThread in a remote process
  • Behavioural detection: Injection (inter-process)
  • Behavioural detection: Injection with CreateRemoteThread in a remote process
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Trojan.Spy.Zbot.FJB (B)?


File Info:

name: D98EF48ED97C005397A1.mlw
path: /opt/CAPEv2/storage/binaries/0c05226542b96cea487d724756ee93d0433393146dced561567c179e244cab8c
crc32: 84AD4DC6
md5: d98ef48ed97c005397a13ce78c97360f
sha1: c04a418d0a218a7a87a6f79e5589af82af95d75b
sha256: 0c05226542b96cea487d724756ee93d0433393146dced561567c179e244cab8c
sha512: f3922554a4194d57bbb2fdd27ba44590dd10a9dcf96462b775e5dae52ee1f4669b78c71a2deab630a2a9f8818211108e90c38ecfab3a1929705cc7338ed8b99a
ssdeep: 3072:qz91LZQEduEgsW2UPqxUEbqkC0i50/YXiQXT+t/8XIgfUTaXD3kz1QNd:qz91L+QHhUPqxUE5QiQwkXhfUThQ3
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1ECD3AF577480A1F3C9EB1671AA69772563FFC93836388C83E3140E6A3575883A36D74B
sha3_384: 050bf538e3526a714706ce56eefd2d139ff7299fc9374b86387328008a5bb289d56dccb8b052b0b2fdc0cbfc47bb82a4
ep_bytes: 558bec83ec10536a0032dbe86af0ffff
timestamp: 2011-03-24 11:36:23

Version Info:

0: [No Data]

Trojan.Spy.Zbot.FJB (B) also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Necurs.MUE.A3
ALYacTrojan.Spy.Zbot.FJB
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0015e4f11 )
BitDefenderTrojan.Spy.Zbot.FJB
K7GWRiskware ( 0015e4f11 )
Cybereasonmalicious.ed97c0
BaiduWin32.Trojan.Zbot.a
VirITTrojan.Win32.Generic.BFLK
CyrenW32/Zbot.BR.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
ClamAVWin.Spyware.Zbot-1275
KasperskyTrojan-Spy.Win32.Zbot.biwp
NANO-AntivirusTrojan.Win32.Zbot.rhehs
SUPERAntiSpywareTrojan.Agent/Gen-Frauder
MicroWorld-eScanTrojan.Spy.Zbot.FJB
RisingSpyware.Zbot!1.648A (CLASSIC)
EmsisoftTrojan.Spy.Zbot.FJB (B)
ComodoTrojWare.Win32.Kazy.MKD@4qchol
F-SecureTrojan-Spy:W32/Zbot.AVTH
DrWebTrojan.PWS.Panda.4795
TrendMicroTSPY_ZBOT.SMIG
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
FireEyeGeneric.mg.d98ef48ed97c0053
SophosML/PE-A + Troj/PWS-BSF
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.ayai
AviraTR/Spy.Zbot.511005
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASBOL.1162
MicrosoftPWS:Win32/Zbot!CI
ViRobotTrojan.Win32.A.Zbot.141312.B
ZoneAlarmTrojan-Spy.Win32.Zbot.biwp
GDataWin32.Trojan-Spy.Zbot.DB
AhnLab-V3Trojan/Win32.Zbot.R4880
McAfeePWS-Zbot.gen.avh
TACHYONTrojan-Spy/W32.ZBot.141824.EI
VBA32SScope.Trojan.FakeAV.01110
MalwarebytesTrojan.Zbot
PandaTrj/Spy.AB
TrendMicro-HouseCallTSPY_ZBOT.SMIG
TencentTrojan.Win32.Zbot.aaw
YandexTrojan.GenAsa!upgWmf03L4M
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Zbot.AT!tr
BitDefenderThetaGen:NN.ZexaF.34182.imX@aSuL08b
AVGSf:Crypt-BT [Trj]
AvastSf:Crypt-BT [Trj]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Trojan.Spy.Zbot.FJB (B)?

Trojan.Spy.Zbot.FJB (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment