Spy

Spyware.Dybalom removal tips

Malware Removal

The Spyware.Dybalom is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Dybalom virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Sample contains Overlay data
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • Attempted to write directly to a physical drive

How to determine Spyware.Dybalom?


File Info:

name: 27FDA614B523EF1FD295.mlw
path: /opt/CAPEv2/storage/binaries/2b9da2971eda55d8d08a927596dc07f761126629425818fda05cc114cf83fe76
crc32: BD6A06FB
md5: 27fda614b523ef1fd2951720d124c5d8
sha1: 449936aad6140bc81a5a089cf04466283c66d019
sha256: 2b9da2971eda55d8d08a927596dc07f761126629425818fda05cc114cf83fe76
sha512: 2420faa9707162c7b6c8b74f052ba1c329434a5189c37b62a09215d425b607aad9f0dd0f947e0eee9f02548dd2492613edc08a55649b9e3615f13dc80179cb63
ssdeep: 6144:nQAR4fTrds1niG1vLGCqBXfFvUSWevqtExr/F6qLQu+tgw7DTZ1GvK:QnG1jGC2fFUBevcEF99j+tgfv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11E74120121A045F7CAF715B2BC6EBBF2C69D97204C31CA10D3921D6E9EF6876DB089A5
sha3_384: c5bef5685c94de5bbec90a0fe276ca0b2688537e09728f2dec114d8394e54f55a4c7497e349bdd554faec3a0292abd0f
ep_bytes: 558bec535657bb0080400066f7058a53
timestamp: 1970-01-01 03:25:45

Version Info:

Translation: 0x0409 0x04b0
CompanyName: AceSoft Corp all rights reserved
FileDescription: AceSoft Corp all rights reserved
LegalCopyright: AceSoft Corp all rights reserved
ProductName: AceSoft Corp all rights reserved
FileVersion: 2.00
ProductVersion: 2.00
InternalName: program
OriginalFilename: program.exe

Spyware.Dybalom also known as:

LionicTrojan.Win32.Buzus.to3l
tehtrisGeneric.Malware
MicroWorld-eScanTrojan.GenericKD.40528260
FireEyeGeneric.mg.27fda614b523ef1f
ALYacTrojan.GenericKD.40528260
CylanceUnsafe
VIPRETrojan.GenericKD.40528260
K7AntiVirusTrojan ( 00479de01 )
AlibabaTrojan:Win32/Buzus.73e4b2ab
K7GWTrojan ( 00479de01 )
Cybereasonmalicious.4b523e
VirITTrojan.Win32.Generic.ZIQ
CyrenW32/Risk.NLRC-1732
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.AJVQ
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Buzus-27396
KasperskyTrojan.Win32.Buzus.epmp
BitDefenderTrojan.GenericKD.40528260
NANO-AntivirusTrojan.Win32.Buzus.cquyy
SUPERAntiSpywareTrojan.Agent/Gen-FakeAV[Ace]
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.114d22f6
Ad-AwareTrojan.GenericKD.40528260
TACHYONTrojan/W32.Buzus.364545
EmsisoftTrojan.GenericKD.40528260 (B)
ComodoMalware@#3upel44545h16
DrWebWin32.HLLW.Autoruner2.47582
ZillyaTrojan.Buzus.Win32.65468
McAfee-GW-EditionBehavesLike.Win32.Trojan.fc
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
SentinelOneStatic AI – Suspicious PE
GDataTrojan.GenericKD.40528260
JiangminTrojan/Buzus.ajzh
WebrootW32.Trojan.Meredrop
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.AA
KingsoftWin32.Troj.Buzus.ep.(kcloud)
ArcabitTrojan.Generic.D26A6984
ViRobotTrojan.Win32.A.Buzus.364547
MicrosoftTrojan:Win32/Occamy.C2B
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Buzus.R1933
McAfeeGenericRXAA-AA!27FDA614B523
MAXmalware (ai score=100)
VBA32Trojan.Buzus
MalwarebytesSpyware.Dybalom
RisingTrojan.Generic@AI.95 (RDML:NcO8XqZ0YGOH/fHVZuoi6g)
IkarusTrojan.Win32.Buzus
FortinetW32/Generic.AC.218AA1
BitDefenderThetaGen:NN.ZexaF.34806.wu1@a4w8bVli
AVGWin32:Trojan-gen
PandaGeneric Malware
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Spyware.Dybalom?

Spyware.Dybalom removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment