Spy Trojan

Trojan-Spy.Win32.Zbot.bfcj removal tips

Malware Removal

The Trojan-Spy.Win32.Zbot.bfcj is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.bfcj virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Zbot.bfcj?


File Info:

name: 8CD6BB8B8DB866381F6D.mlw
path: /opt/CAPEv2/storage/binaries/a687c781c04566c98d73690914a35aa6139b29ba440f66486de4434ba7049494
crc32: 4DAB9845
md5: 8cd6bb8b8db866381f6de42b92d88e41
sha1: 29e071f16267d13b0d8bca1391d61aaf6be87789
sha256: a687c781c04566c98d73690914a35aa6139b29ba440f66486de4434ba7049494
sha512: f60290c8ff89a1ef0fc48823600e23b7391cf2539bccb4d4133bf6f646f486cebf7bdb0b5f78ebd94cdc4f9441931956dee4039b3539a3d51181baf6be021f44
ssdeep: 3072:0qEoPcIf5BAAP9ChjpwyLcPL5YNgzADwwX:NDkcHP9CfLu9A0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12AC31393E7FD0652E99CE2F631630091978BDD0946354A917FABF2523C338A25B4DBB0
sha3_384: 112afff7c28ab13c93235378a898a099fa50144c47169f18e5bb32761bc66cdd829e4b4ae632a741b780efe22540f81a
ep_bytes: 60be15e041008dbeeb2ffeff57eb0b90
timestamp: 2005-04-25 00:50:25

Version Info:

CompanyName: Vsjdoag Nwxvsrpec
FileDescription: Vsjdoag Mibcerccba Xlvcxclkri
FileVersion: 2, 19, 21, 46
InternalName: Vsjdoag
LegalCopyright: Copyright © Vsjdoag Nwxvsrpec 2003-2011
OriginalFilename: Vsjdoag.exe
ProductName: Vsjdoag Mibcerccba Xlvcxclkri
ProductVersion: 42, 84, 31, 97
Translation: 0x0409 0x04e4

Trojan-Spy.Win32.Zbot.bfcj also known as:

BkavW32.MosquitoQKK.Fam.Trojan
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
DrWebTrojan.Packed.21467
MicroWorld-eScanGen:Heur.VIZ.2
FireEyeGeneric.mg.8cd6bb8b8db86638
CAT-QuickHealWorm.SlenfBot.Gen
ALYacGen:Heur.VIZ.2
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.32514
SangforTrojan.Win32.Gen.2
K7AntiVirusTrojan ( f1000f011 )
AlibabaTrojanSpy:Win32/Kryptik.7882b1ad
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.b8db86
BitDefenderThetaAI:Packer.3B2308D321
VirITTrojan.Win32.Zyx.B
CyrenW32/Zbot.CN.gen!Eldorado
SymantecW32.Qakbot!gen5
ESET-NOD32a variant of Win32/Kryptik.LFX
TrendMicro-HouseCallBKDR_QAKBOT.SMG
ClamAVWin.Trojan.Zbot-55685
KasperskyTrojan-Spy.Win32.Zbot.bfcj
BitDefenderGen:Heur.VIZ.2
NANO-AntivirusTrojan.Win32.Zbot.cgsij
SUPERAntiSpywareTrojan.Agent/Gen-Cryptic
AvastFileRepMalware
TencentWin32.Trojan-spy.Zbot.Efbi
Ad-AwareGen:Heur.VIZ.2
SophosMal/Generic-R + Mal/FakeAV-BW
ComodoTrojWare.Win32.TrojanSpy.Zbot.G@2tckk5
F-SecureTrojan.TR/Crypt.XPACK.Gen
VIPREBackdoor.Win32.Qakbot.ax (v)
TrendMicroBKDR_QAKBOT.SMG
McAfee-GW-EditionBehavesLike.Win32.MultiDropper.cc
SentinelOneStatic AI – Malicious PE
EmsisoftGen:Heur.VIZ.2 (B)
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Heur.VIZ.2
JiangminTrojanSpy.Zbot.awbn
WebrootW32.Malware.Gen
AviraTR/Crypt.XPACK.Gen
Antiy-AVLTrojan[Spy]/Win32.Zbot
ArcabitTrojan.VIZ.2
ViRobotTrojan.Win32.A.Zbot.129536.W
ZoneAlarmTrojan-Spy.Win32.Zbot.bfcj
MicrosoftPWS:Win32/Zbot.gen!Y
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Zbot.R3226
McAfeeW32/Pinkslipbot.gen.af
VBA32Trojan.Zeus.EA.0999
MalwarebytesMalware.Heuristic.1003
APEXMalicious
YandexTrojan.GenAsa!Hc4b0d5ZneU
MAXmalware (ai score=100)
MaxSecureTrojan.Malware.1964693.susgen
FortinetW32/Kryptik.NAS!tr
AVGFileRepMalware
PandaBck/Qbot.AO

How to remove Trojan-Spy.Win32.Zbot.bfcj?

Trojan-Spy.Win32.Zbot.bfcj removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment