Worm

Net-Worm.Win32.Kolab.btbe removal tips

Malware Removal

The Net-Worm.Win32.Kolab.btbe is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Net-Worm.Win32.Kolab.btbe virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid
  • Deletes its original binary from disk
  • Checks for the presence of known windows from debuggers and forensic tools
  • Likely virus infection of existing system binary
  • Attempts to identify installed analysis tools by a known file location
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Creates a copy of itself

How to determine Net-Worm.Win32.Kolab.btbe?


File Info:

name: E5715F682D3B1A90DB5D.mlw
path: /opt/CAPEv2/storage/binaries/52e65fa9e8e204eac9a6f61c3b4ceb428ba7fbcc9e604a0645096de69fccc6c3
crc32: 8C268612
md5: e5715f682d3b1a90db5d7cd4fe571b71
sha1: 802f3604f79f27408e370e42eb18afaba302ba15
sha256: 52e65fa9e8e204eac9a6f61c3b4ceb428ba7fbcc9e604a0645096de69fccc6c3
sha512: 8459f9b214c18cc1a47624a5e77457c108098ceeca8cabc3e5af9df9ce9c1ed884a1cd61be139873118115969ca2b102a9d76e67f0472d216fdb300fe4ad14c4
ssdeep: 6144:cFlDby9XWrnblDonFoKj9+hKwf/E7x4QMJgSW:c3NqPkhKwGx4FFW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C954123DA04878B4E2E53236B9457ABB8C2EB3315DCE4C277921614FBE656C33D4A139
sha3_384: 2ab25872fca91d57b20f65c3245800d17b71491d0580d9732cd46b77a7a2beba004354c009613b040253aaf1cc2caded
ep_bytes: 90558bec83c4a440f7d0ba282540008b
timestamp: 2004-04-25 02:29:14

Version Info:

CompanyName: AVG Technologies CZ, s.r.o.
FileDescription: AVG Tray Monitor
FileVersion: 9.0.0.871
InternalName: avgtray
LegalCopyright: Copyright © 2010 AVG Technologies CZ, s.r.o.
OriginalFilename: avgtray.exe
ProductName: AVG Internet Security
ProductVersion: 9.0.0.871
PrivateBuild: Win32 Release_Unicode
SpecialBuild: Avg8VC8_2010_1109_133319(871), SVNRev 145063 (/branches/release/SmallUpdate9-12)
Translation: 0x0409 0x04e4

Net-Worm.Win32.Kolab.btbe also known as:

BkavW32.AIDetect.malware2
LionicWorm.Win32.Kolab.p!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed.21467
MicroWorld-eScanGen:Variant.Ser.Razy.7890
FireEyeGeneric.mg.e5715f682d3b1a90
CAT-QuickHealWorm.SlenfBot.Gen
McAfeePWS-Spyeye.ff
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforExploit.Win32.ShellCode.gen
K7AntiVirusTrojan ( 004ae4e31 )
AlibabaWorm:Win32/Kolab.633d9b9d
K7GWTrojan ( 004ae4e31 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34212.rq1@aOG9Egac
VirITTrojan.Win32.Packed.BFTR
CyrenW32/S-3f083976!Eldorado
SymantecW32.Qakbot!gen5
ESET-NOD32a variant of Win32/Kryptik.KWA
TrendMicro-HouseCallBKDR_QAKBOT.SMG
Paloaltogeneric.ml
KasperskyNet-Worm.Win32.Kolab.btbe
BitDefenderGen:Variant.Ser.Razy.7890
NANO-AntivirusTrojan.Win32.DownLoad2.ifucs
SUPERAntiSpywareTrojan.Agent/Gen-FakeAVG
AvastWin32:Krajabot-G [Trj]
TencentWin32.Worm-net.Kolab.Ajuv
Ad-AwareGen:Variant.Ser.Razy.7890
SophosML/PE-A + Mal/FakeAV-IU
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
ZillyaTrojan.Kryptik.Win32.901262
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionPWS-Spyeye.ff
EmsisoftGen:Variant.Ser.Razy.7890 (B)
IkarusWorm.Win32.Slenfbot
GDataGen:Variant.Ser.Razy.7890
JiangminWorm.Kolab.ec
eGambitGeneric.Downloader
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan/Generic.ASMalwS.A59ED5
ArcabitTrojan.Ser.Razy.D1ED2
ViRobotTrojan.Win32.A.Downloader.205448
ZoneAlarmNet-Worm.Win32.Kolab.btbe
MicrosoftWorm:Win32/Slenfbot.gen!D
CynetMalicious (score: 100)
AhnLab-V3Worm/Win32.Kolab.R3715
VBA32Trojan.Zeus.EA.0999
ALYacGen:Variant.Ser.Razy.7890
MAXmalware (ai score=99)
MalwarebytesMalware.AI.1553884152
APEXMalicious
RisingExploit.ShellCode!8.2A (CLOUD)
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.NAS!tr
AVGWin32:Krajabot-G [Trj]
Cybereasonmalicious.82d3b1
PandaBck/Qbot.AO

How to remove Net-Worm.Win32.Kolab.btbe?

Net-Worm.Win32.Kolab.btbe removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment