Spy Trojan

Trojan-Spy.Win32.SpyEyes.blcf removal instruction

Malware Removal

The Trojan-Spy.Win32.SpyEyes.blcf is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.SpyEyes.blcf virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Norwegian (Nynorsk)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Installs itself for autorun at Windows startup
  • Contacts C&C server HTTP check-in (Banking Trojan)
  • Creates a copy of itself
  • Anomalous binary characteristics

Related domains:

gxd3fp7fe7cac6jzn2sac.online

How to determine Trojan-Spy.Win32.SpyEyes.blcf?


File Info:

crc32: EEC225CA
md5: 65fb07b5db93b0bcdb1844c9246d5f02
name: 65FB07B5DB93B0BCDB1844C9246D5F02.mlw
sha1: 5bcaa4d2a5adb447c7a075726ce4f68f34b06bab
sha256: 667248ffb3c5df982ffeda41f3f0dcf37ed42c227156bbc60e2df9c3ea5f1ab3
sha512: 64240e5088984031da41a169f910e287188afce86f26f7033a9f13c07e9f42d9069be0d5c532b8077a1455119014268b657254cea7d1458c6a99965b60b16e11
ssdeep: 12288:hpGmpOkPRq//EIqnK6kd1hc6fZ67eyy7mYW:fGZARGcIkKnd1C6fZ67
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

InternalName: triwilbifog.acs
FileVersion: 6.26.361
Copyright: Copyrighz (C) 2020, vodkafug
ProductVersion: 1.0.5
TranslationUsa: 0x0273 0x04d3

Trojan-Spy.Win32.SpyEyes.blcf also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.45252431
FireEyeGeneric.mg.65fb07b5db93b0bc
CAT-QuickHealTrojan.Multi
Qihoo-360Win32/Trojan.Spy.f8e
ALYacTrojan.GenericKD.45252431
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Multi.Generic.4!c
SangforMalware
K7AntiVirusTrojan ( 005757311 )
BitDefenderTrojan.GenericKD.45252431
K7GWTrojan ( 005757311 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.34742.CmKfamxO44pG
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R049C0PA321
Paloaltogeneric.ml
KasperskyTrojan-Spy.Win32.SpyEyes.blcf
AlibabaTrojanSpy:Win32/SpyEyes.f072d47a
ViRobotTrojan.Win32.Z.Kryptik.463872.AX
RisingTrojan.Kryptik!1.CFEE (CLASSIC)
Ad-AwareTrojan.GenericKD.45252431
SophosMal/Generic-S
F-SecureTrojan.TR/AD.TriumphLoader.hpdmh
TrendMicroTROJ_GEN.R049C0PA321
McAfee-GW-EditionBehavesLike.Win32.Trojan.gc
EmsisoftTrojan.GenericKD.45252431 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/AD.TriumphLoader.hpdmh
MicrosoftTrojan:Win32/Glupteba.NV!MTB
GridinsoftTrojan.Win32.Kryptik.oa
ArcabitTrojan.Generic.D2B27F4F
ZoneAlarmTrojan-Spy.Win32.SpyEyes.blcf
GDataTrojan.GenericKD.45252431
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Generic.R361497
McAfeeRDN/TriumphLoader
MAXmalware (ai score=87)
VBA32BScope.Backdoor.Mokes
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
APEXMalicious
ESET-NOD32a variant of Win32/Kryptik.HIMC
TencentWin32.Trojan-spy.Spyeyes.Wrhb
IkarusWorm.Win32.Peerfrag
eGambitUnsafe.AI_Score_92%
FortinetW32/Kryptik.HIFA!tr
AVGWin32:TrojanX-gen [Trj]
Cybereasonmalicious.2a5adb
AvastWin32:TrojanX-gen [Trj]

How to remove Trojan-Spy.Win32.SpyEyes.blcf?

Trojan-Spy.Win32.SpyEyes.blcf removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment