Spy Trojan

How to remove “Trojan-Spy.Win32.Zbot.bcrj”?

Malware Removal

The Trojan-Spy.Win32.Zbot.bcrj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.bcrj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Zbot.bcrj?


File Info:

name: A6A834CDBCE9560656B9.mlw
path: /opt/CAPEv2/storage/binaries/91bbf00336e3faa664cda46c4d3a86ada0a32789162d54ea855cd1a3330f8376
crc32: E6778232
md5: a6a834cdbce9560656b94d5eef1ffc10
sha1: af2526b7118737dbb1cc2ac82f628dddfac87a5f
sha256: 91bbf00336e3faa664cda46c4d3a86ada0a32789162d54ea855cd1a3330f8376
sha512: e2bf3d034e862370a70e2c0919f0078f6aebc4515acad5c7e492bf18b4e10f0b6bead08af239743beffbd28f0d2daaa9506d29074aab70dce10a840ad38e9a43
ssdeep: 3072:bIwOQN5FV0/BaQHkSAOd0+wlQN4vqD69UQZTm:Ew0/0QHkSAOjN4vL9UQ
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16CD312512FF747A6F4CC71341974AA3F8FA1F05A5AE9A9971A69123F6C0420F923132B
sha3_384: 7aafcd5519711aa903cec408e300d8848b73fb74b4e81ded3fb08077b039607f310fc56aaf1ee157fef72d889a8efd4c
ep_bytes: 60be005042008dbe00c0fdff57eb0b90
timestamp: 2004-05-01 15:20:20

Version Info:

CompanyName: Cfkjfdmktv Lmubuw
FileDescription: Cfkjfdmktv Bpnyckyl Isighfxwp
FileVersion: 123,106,93,3
InternalName: Cfkjfdmktv
LegalCopyright: Copyright © Cfkjfdmktv Lmubuw 1999-2011
OriginalFilename: Cfkjfdmktv.exe
ProductName: Cfkjfdmktv Bpnyckyl Isighfxwp
ProductVersion: 111,34,14,81
Translation: 0x0409 0x04e4

Trojan-Spy.Win32.Zbot.bcrj also known as:

BkavW32.MosquitoQKK.Fam.Trojan
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebBackDoor.Qbot.80
MicroWorld-eScanGen:Heur.VIZ.2
FireEyeGeneric.mg.a6a834cdbce95606
CAT-QuickHealWorm.SlenfBot.Gen
ALYacGen:Heur.VIZ.2
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.33009
SangforTrojan.Win32.Kryptik.LBU
K7AntiVirusTrojan ( f1000f011 )
AlibabaTrojanSpy:Win32/Kryptik.9644f51f
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.dbce95
BitDefenderThetaAI:Packer.0885E8A021
VirITTrojan.Win32.Generic.YIY
CyrenW32/Zbot.CN.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Kryptik.LBU
TrendMicro-HouseCallTROJ_CRYPTR.SMAM
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Spy.Win32.Zbot.bcrj
BitDefenderGen:Heur.VIZ.2
NANO-AntivirusTrojan.Win32.Zbot.ckrvs
SUPERAntiSpywareTrojan.Agent/Gen-Faldesc[Cont]
AvastWin32:Trojan-gen
TencentMalware.Win32.Gencirc.114ba52c
Ad-AwareGen:Heur.VIZ.2
EmsisoftGen:Heur.VIZ.2 (B)
ComodoTrojWare.Win32.Trojan.XPACK.Gen@2ho5ur
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_CRYPTR.SMAM
McAfee-GW-EditionBehavesLike.Win32.Downloader.cc
SophosMal/Generic-R + Mal/FakeAV-IU
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Heur.VIZ.2
JiangminTrojanSpy.Zbot.avvv
WebrootW32.Infostealer.Zeus
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.3A54AD
ViRobotTrojan.Win32.A.Zbot.135680.BK[UPX]
MicrosoftPWS:Win32/Zbot
AhnLab-V3Trojan/Win32.Zbot.R6725
McAfeeW32/Pinkslipbot.gen.af
MAXmalware (ai score=100)
VBA32Trojan.Zeus.EA.0999
APEXMalicious
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.GenAsa!PsEgaakFxfg
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.1774115.susgen
FortinetW32/Kryptik.NAS!tr
AVGWin32:Trojan-gen
PandaBck/Qbot.AO
CrowdStrikewin/malicious_confidence_60% (D)

How to remove Trojan-Spy.Win32.Zbot.bcrj?

Trojan-Spy.Win32.Zbot.bcrj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment