Spy Trojan

Trojan.Spy.Zbot.FNM removal tips

Malware Removal

The Trojan.Spy.Zbot.FNM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Zbot.FNM virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Chinese
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Spy.Zbot.FNM?


File Info:

name: 44ED75A680D9A0F151EF.mlw
path: /opt/CAPEv2/storage/binaries/dd1b42fee9f50cb5493a5730eb7e3b8d40233ce153e219ff3e23dad7b9b51186
crc32: D0D5EEA1
md5: 44ed75a680d9a0f151efc9d3ffea7a90
sha1: 0b2dcaa417b2589068d5d1de6a9603bbe1938019
sha256: dd1b42fee9f50cb5493a5730eb7e3b8d40233ce153e219ff3e23dad7b9b51186
sha512: f26b1f0ff59dd32bb36abd2dc5f9caa0e1aa4a414bd15e78421483eab959aabd61b17f1b68e62c452888e684910f105af3a514f6bd06db0234c269ce6efe77ee
ssdeep: 12288:j7WuFh+3yAV7LUEbCzauHIfmbSaBn4GrrvUNs:nWk+3yAV7dluHIfa4G3UK
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A942313134DE600F2B26730E89B7764405D288B3F37D66EA51B239FAB59B84F235726
sha3_384: ae9f1c69117113ef69b2efd18fe2bbb8d7139056c2d63d58f59964140f124bd53ec68c512b7d2e8ee6b20c4b21a4bbb2
ep_bytes: 558bec81ec14010000b936000000eb0a
timestamp: 2011-08-05 01:55:42

Version Info:

CompanyName: Masnesaft Corporation
FileDescription: Masnesaft Visual Studie 2010
FileVersion: 1.9.43074.5121 built by: SP1Rel
InternalName: devenv.exe
LegalCopyright: © Masnesaft Corporation. All rights reserved.
OriginalFilename: devenv.exe
ProductName: Masnesaft® Visual Studio® 2010
ProductVersion: 1.9.43074.5121
Translation: 0x0409 0x04b0

Trojan.Spy.Zbot.FNM also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Zbot.l!c
MicroWorld-eScanTrojan.Spy.Zbot.FNM
FireEyeGeneric.mg.44ed75a680d9a0f1
CAT-QuickHealFraudTool.Security
McAfeePWSZbot-FBTA!44ED75A680D9
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.161961
SangforTrojan.Win32.olyse.5
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.Spy.Zbot.FNM
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaAI:Packer.2FF5A5F420
VirITTrojan.Win32.Zbot.LSB
CyrenW32/Trojan.BFUO-4374
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.ABP
BaiduWin32.Trojan.Kryptik.je
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-59479
KasperskyTrojan-Spy.Win32.Zbot.toor
NANO-AntivirusTrojan.Win32.Crypted.dcmkpc
CynetMalicious (score: 100)
RisingSpyware.Zbot!8.16B (TFE:1:7eSXlg0rTkS)
Ad-AwareTrojan.Spy.Zbot.FNM
TACHYONTrojan-Spy/W32.ZBot.433190
SophosML/PE-A + Troj/Zbot-IPP
ComodoTrojWare.Win32.Kryptik.CHIQ@5dpgs3
DrWebTrojan.Siggen6.15132
VIPRETrojan.Spy.Zbot.FNM
TrendMicroTSPY_ZBOT.SMRAP
McAfee-GW-EditionPWSZbot-FBTA!44ED75A680D9
Trapminemalicious.high.ml.score
EmsisoftTrojan.Spy.Zbot.FNM (B)
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojanSpy.Zbot.effv
WebrootTrojan.Dropper.Gen
AviraTR/Crypt.XPACK.olyse.5
Antiy-AVLTrojan/Generic.ASMalwS.31
KingsoftWin32.Troj.Zbot.to.(kcloud)
MicrosoftPWS:Win32/Zbot.CF
SUPERAntiSpywareTrojan.Agent/Gen-FalComp
GDataTrojan.Spy.Zbot.FNM
GoogleDetected
AhnLab-V3Dropper/Win32.Necurs.R113664
VBA32TrojanSpy.Zbot
ALYacTrojan.Spy.Zbot.FNM
MAXmalware (ai score=86)
MalwarebytesTrojan.Zbot.Gen
PandaTrj/Genetic.gen
TrendMicro-HouseCallTSPY_ZBOT.SMRAP
TencentMalware.Win32.Gencirc.10c55c47
YandexTrojanSpy.Zbot!WaoQkWfTqVc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.CJJL!tr
AVGWin32:Mystic
Cybereasonmalicious.680d9a
AvastWin32:Mystic

How to remove Trojan.Spy.Zbot.FNM?

Trojan.Spy.Zbot.FNM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment