Spy Trojan

Trojan.Spy.Zbot.FND removal tips

Malware Removal

The Trojan.Spy.Zbot.FND is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Zbot.FND virus can do?

  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Arabic (Libya)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Created a process from a suspicious location

How to determine Trojan.Spy.Zbot.FND?


File Info:

name: 0CD3279FE91211148276.mlw
path: /opt/CAPEv2/storage/binaries/86d3dd85fefb76001b6005db41898642a4b2c11e4064f2aabc128ad5a9f06e5c
crc32: B5145FF7
md5: 0cd3279fe91211148276606d7ebf45e9
sha1: c5b0e89e61031d8ce2d1a3003c4069b3bd824042
sha256: 86d3dd85fefb76001b6005db41898642a4b2c11e4064f2aabc128ad5a9f06e5c
sha512: 48fcdf1e027adb09beb220927fe8bcd648c731c8520c6e2b0946c0a9a8fc63762125cb5ecf055fcc0986a9bdd4c6141d8d96de2be6d7168e31b60fa609aa7b32
ssdeep: 384:CtJWacmw0ypZfld14ZN8lHUv0eNvtKVKXDISYwFhFQ:UJWaDw0yppxb+HdtFXhW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132F21179FACE1EB4F326CFF245B782979233FC20A162060F95817A3A5472D716719E90
sha3_384: 0836ca1410a2e5fbd9b93ce5d7c7cb3fdee05a68dac606966399f3abc6a0890f97acae25232e33b1c508151ea76d04bd
ep_bytes: 57565351e854f4ffffc3680000030068
timestamp: 1973-03-04 21:38:58

Version Info:

CompanyName: Landed
FileDescription: Landed company
FileVersion: Version 1.1.16
InternalName: Landed
LegalCopyright: Copyright by Landed
OriginalFilename: Landed
Translation: 0x0408 0x04e3

Trojan.Spy.Zbot.FND also known as:

BkavW32.FamVT.GeND.Trojan
tehtrisGeneric.Malware
DrWebTrojan.Upatre.87
MicroWorld-eScanTrojan.Spy.Zbot.FND
FireEyeGeneric.mg.0cd3279fe9121114
CAT-QuickHealTrojanDwnldr.Upatre.AA4
McAfeeDownloader-FSH
CylanceUnsafe
Sangfor[ARMADILLO V1.71]
K7AntiVirusTrojan-Downloader ( 0055c6c71 )
K7GWTrojan-Downloader ( 0055c6c71 )
Cybereasonmalicious.fe9121
BitDefenderThetaGen:NN.ZexaF.34806.cu2@a07JhTlG
VirITTrojan.Win32.Zbot.OAT
SymantecDownloader.Upatre!gen5
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.CLKJ
TrendMicro-HouseCallTROJ_UPATRE.SMNF
ClamAVWin.Malware.Upatre-5896042-0
KasperskyTrojan-Downloader.Win32.Upatre.fxzr
BitDefenderTrojan.Spy.Zbot.FND
NANO-AntivirusTrojan.Win32.MlwGen.dffywr
AvastWin32:Agent-AULS [Trj]
TencentTrojan-Downloader.Win32.Waski.16000151
Ad-AwareTrojan.Spy.Zbot.FND
EmsisoftTrojan.Spy.Zbot.FND (B)
ComodoTrojWare.Win32.TrojanDownloader.Upatre.AAL@5iclp5
BaiduWin32.Trojan-Downloader.Waski.a
VIPRETrojan.Spy.Zbot.FND
TrendMicroTROJ_UPATRE.SMNF
McAfee-GW-EditionBehavesLike.Win32.Downloader.nm
Trapminemalicious.high.ml.score
SophosML/PE-A + Troj/HkMain-AZ
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Downloader.Upatre.BK
JiangminHoax.ArchSMS.aipg
AviraHEUR/AGEN.1237752
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASBOL.C4DE
MicrosoftTrojan:Win32/PWSZbot.GSB!MTB
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4250356
VBA32BScope.TrojanDownloader.Upatre
ALYacTrojan.Spy.Zbot.FND
MalwarebytesUpatre.Trojan.Downloader.DDS
APEXMalicious
RisingDownloader.Waski!1.A489 (CLASSIC)
YandexTrojan.GenAsa!yHR/ZyXpGd8
IkarusVirTool.Obfuscator
MaxSecureTrojan.Upatre.Gen
FortinetW32/Waski.A!tr
AVGWin32:Agent-AULS [Trj]
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Spy.Zbot.FND?

Trojan.Spy.Zbot.FND removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment