Spy Trojan

Trojan-Spy.Win32.Stealer.bbec removal guide

Malware Removal

The Trojan-Spy.Win32.Stealer.bbec is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Stealer.bbec virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • NtSetInformationThread: attempt to hide thread from debugger
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Checks for the presence of known windows from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Detects VirtualBox through the presence of a device
  • Anomalous binary characteristics

How to determine Trojan-Spy.Win32.Stealer.bbec?


File Info:

name: 7984F27F2E6AB04C99F5.mlw
path: /opt/CAPEv2/storage/binaries/0e99290d6c11c868581ea26460f34c142eb60797c7a42fdc35e56fe4091ecce0
crc32: 2918C3A7
md5: 7984f27f2e6ab04c99f576e2c775fc7a
sha1: 89171d4ab4f5e7534a97f4ac34ed0f53ed7599f0
sha256: 0e99290d6c11c868581ea26460f34c142eb60797c7a42fdc35e56fe4091ecce0
sha512: e362417b219797b63536fa7d9e3a9df43391835f56434b8a9e50a19047651adb7d697f4503bd439da32e21c14184c6bcb9eb654c5ebf65ba1d14345ae26c6751
ssdeep: 12288:FbTC23GHJIkMUFBZLw4KqUykU+d9uJ8PK1d+86/Glac9W4SIC:FfCDHzW5qUnUEuJw2ghG7I4Q
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1F5B4128BE21255C2DA89267111761B9CB73BDFEC1D36C387302C7AB22F727DA1C16616
sha3_384: 73e9b2f06a91562a4969bc28cf7c96cea6abd2f1a87b733cd1ee93dcabd46ff196604384972917d8232c821323e774e3
ep_bytes: eb05ff9b0fe24650eb01f6e812000000
timestamp: 2022-01-30 09:56:57

Version Info:

CompanyName: greRatlTy
FileDescription: 1cele8rehstory
FileVersion: 76.86.35.46
InternalName: quarvsteKr(a)
LegalCopyright: Copyright (C) 2016-2022.
OriginalFilename: cRharlYotteItown.exe
ProductName: aerEograpphGy
ProductVersion: 42.13.43.82
Translation: 0x0000 0x04b0

Trojan-Spy.Win32.Stealer.bbec also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Midie.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Midie.107106
FireEyeGeneric.mg.7984f27f2e6ab04c
ALYacGen:Variant.Midie.107106
CylanceUnsafe
SangforSpyware.Win32.Stealer.bbec
K7AntiVirusTrojan ( 0058db741 )
K7GWTrojan ( 0058db741 )
Cybereasonmalicious.ab4f5e
BitDefenderThetaGen:NN.ZexaF.34182.Fq3@a0Vy8Up
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Packed.Obsidium.FS
TrendMicro-HouseCallTROJ_GEN.R049C0PB222
AvastWin32:Trojan-gen
KasperskyTrojan-Spy.Win32.Stealer.bbec
BitDefenderGen:Variant.Midie.107106
TrendMicroTROJ_GEN.R049C0PB222
McAfee-GW-EditionRDN/Generic.rp
EmsisoftGen:Variant.Midie.107106 (B)
APEXMalicious
GridinsoftRansom.Win32.Occamy.sa
MicrosoftExploit:Win32/ShellCode!ml
ZoneAlarmTrojan-Spy.Win32.Stealer.bbec
GDataGen:Variant.Midie.107106
SentinelOneStatic AI – Suspicious PE
AhnLab-V3Trojan/Win.Generic.R469765
McAfeeRDN/Generic.rp
MAXmalware (ai score=82)
VBA32BScope.Trojan.Fuery
MalwarebytesTrojan.MalPack
PandaTrj/CI.A
RisingTrojan.Occamy!8.F1CD (CLOUD)
YandexTrojan.GenAsa!0B4ddvRpm/c
FortinetPossibleThreat.MU
AVGWin32:Trojan-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Trojan-Spy.Win32.Stealer.bbec?

Trojan-Spy.Win32.Stealer.bbec removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment