Spy Trojan

Trojan-Spy.Win32.Bobik.drm removal

Malware Removal

The Trojan-Spy.Win32.Bobik.drm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Bobik.drm virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Expresses interest in specific running processes
  • The binary likely contains encrypted or compressed data.
  • Detects Sandboxie through the presence of a library
  • Checks for the presence of known windows from debuggers and forensic tools
  • The following process appear to have been packed with Themida: spoofer_gamingforecast_free.exe
  • Network activity detected but not expressed in API logs
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects the presence of Wine emulator via registry key
  • Checks the version of Bios, possibly for anti-virtualization
  • Detects VirtualBox through the presence of a registry key
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Bobik.drm?


File Info:

crc32: 96292057
md5: 2a6699232e9cbfabfbd2ad6aeec0c498
name: spoofer_gamingforecast_free.exe
sha1: f52c865018d3412158ef90c668db0214479fde54
sha256: 564c6c0632ea38548c5a8453722cfd12e5260e3aed9acb9561dd47f2621d0d93
sha512: 99b0ab4e32d014f694440afc3aacb61843a79f276eec158c024b41fce86b5acab6004554668e135dd788e7eb871d5006d42b4aeb94a4954c06b213bd1dc67ddd
ssdeep: 24576:B2Md80+xCkfvzo2caObMcicvGEoatql5mOZlagna9VH8/GkZes27yHzixUQTxDJ:EKX+xCkfvMicicvGEfI5P69qVZGyHdI
type: PE32 executable (console) Intel 80386, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: XXXXXXXXXXXXXXXXX
Assembly Version: 1.1.1.2
InternalName: SPOOFER.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: SOOFER
ProductVersion: 1.1.1.2
FileDescription: SPOOFER
OriginalFilename: SPOOFER.exe

Trojan-Spy.Win32.Bobik.drm also known as:

BkavHW32.Packed.
MicroWorld-eScanTrojan.GenericKD.42863345
FireEyeGeneric.mg.2a6699232e9cbfab
Qihoo-360Win32/Trojan.Spy.99e
ALYacTrojan.GenericKD.42863345
MalwarebytesTrojan.MalPack.Themida
SangforMalware
K7AntiVirusTrojan ( 00559ab31 )
BitDefenderTrojan.GenericKD.42863345
K7GWTrojan ( 00559ab31 )
Cybereasonmalicious.018d34
Invinceaheuristic
BitDefenderThetaGen:NN.ZexaF.34100.RD0aaKDoghd
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.GenericKD.42863345
KasperskyTrojan-Spy.Win32.Bobik.drm
AlibabaPacked:Win32/Themida.5fc68d49
AegisLabTrojan.Win32.Generic.l!c
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Bobik.Hrza
Ad-AwareTrojan.GenericKD.42863345
SophosMal/Generic-S
ComodoMalware@#f8u6se0sxaqp
F-SecureTrojan.TR/Crypt.TPM.Gen
McAfee-GW-EditionBehavesLike.Win32.Trojan.tc
Trapminemalicious.high.ml.score
EmsisoftTrojan.GenericKD.42863345 (B)
IkarusTrojan.Win32.Themida
AviraTR/Crypt.TPM.Gen
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28E0AF1
ZoneAlarmTrojan-Spy.Win32.Bobik.drm
MicrosoftTrojan:Win32/Occamy.C
Acronissuspicious
McAfeeArtemis!2A6699232E9C
MAXmalware (ai score=89)
CylanceUnsafe
ESET-NOD32a variant of Win32/Packed.Themida.GZV
TrendMicro-HouseCallTROJ_GEN.R011H0CCL20
RisingSpyware.Generic!8.DC0E (CLOUD)
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetW32/PossibleThreat
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Trojan-Spy.Win32.Bobik.drm?

Trojan-Spy.Win32.Bobik.drm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment