Spy Trojan

What is “Trojan-Spy.Win32.Zbot.bfok”?

Malware Removal

The Trojan-Spy.Win32.Zbot.bfok is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Zbot.bfok virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid

How to determine Trojan-Spy.Win32.Zbot.bfok?


File Info:

name: C8DD66AE05C705676AED.mlw
path: /opt/CAPEv2/storage/binaries/5896a7165eebc3b744c7ba85919870fe3aa78959479188d97a31bcce9ae37e94
crc32: 5ED3BBC4
md5: c8dd66ae05c705676aed1caa88b3afdb
sha1: b93c0e4aa98a1783415509daf035d6123377dedc
sha256: 5896a7165eebc3b744c7ba85919870fe3aa78959479188d97a31bcce9ae37e94
sha512: 8aa045aa2d9c58a8ffd67578460e9cb68c7e41f61943a4994cc1509555745d6556045b094566200a7fc4b7ca7a0bf4b211d98b40bf00c3c9745dc78a72023620
ssdeep: 3072:ZjbkeanQ4spU8rfUjo3sP6MpeRMMG3Iv2juVIdyraCNWR1:+ean5ojOoDMpAMHwFIErzN2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18CD3022BF7852C71EBEC2476A2C6193DE3A077B9DBB45023997D2F4540A678323E0685
sha3_384: 877091dd8ed5c03657cfca98c74c9dcae06fb27d4d44f1ce37e1b10e91bdefcfc9970386b9e4b33108e8171e303b7e82
ep_bytes: 60be150072008dbeeb0fceff5783cdff
timestamp: 2008-12-28 17:14:57

Version Info:

CompanyName: Qwwyvukm Gruocu
FileDescription: Qwwyvukm Exgtjvu Hdiilgqt
FileVersion: 122, 27, 43, 114
InternalName: Qwwyvukm
LegalCopyright: Copyright © Qwwyvukm Gruocu 2003-2011
OriginalFilename: Qwwyvukm.exe
ProductName: Qwwyvukm Exgtjvu Hdiilgqt
ProductVersion: 45, 71, 43, 123
Translation: 0x0409 0x04e4

Trojan-Spy.Win32.Zbot.bfok also known as:

BkavW32.MosquitoQKB.Fam.Trojan
LionicTrojan.Win32.Zbot.l!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.c8dd66ae05c70567
McAfeeW32/Pinkslipbot.gen.af
ZillyaTrojan.Zbot.Win32.32048
SangforTrojan.Win32.Spy.Zbot
K7AntiVirusTrojan ( f1000f011 )
BitDefenderGen:Heur.VIZ.2
K7GWTrojan ( f1000f011 )
Cybereasonmalicious.e05c70
VirITTrojan.Win32.Crypt.AGOG
CyrenW32/Zbot.CN.gen!Eldorado
SymantecW32.Qakbot!gen5
ESET-NOD32Win32/Spy.Zbot.YW
APEXMalicious
KasperskyTrojan-Spy.Win32.Zbot.bfok
AlibabaTrojanSpy:Win32/Pinkslipbot.0477b965
NANO-AntivirusTrojan.Win32.Zbot.cgruz
ViRobotTrojan.Win32.Cryptic.139776
MicroWorld-eScanGen:Heur.VIZ.2
RisingTrojan.Kryptik!8.8 (CLOUD)
Ad-AwareGen:Heur.VIZ.2
SophosMal/Generic-R + Troj/ZBot-AMR
ComodoMalware@#1tnumuyz9iayb
DrWebTrojan.Packed.21467
VIPRETrojan.Win32.Kryptik.mcf (v)
TrendMicroBKDR_QAKBOT.SMG
EmsisoftGen:Heur.VIZ.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.bcmx
AviraTR/Spy.Zbot.bkn
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.184BF38
MicrosoftPWS:Win32/Zbot!ml
GDataGen:Heur.VIZ.2
AhnLab-V3Trojan/Win32.Zbot.R3496
BitDefenderThetaGen:NN.ZexaF.34212.imKfaaZJAacc
ALYacBackdoor.Zbot.al
VBA32Trojan.Zeus.EA.0999
CylanceUnsafe
PandaBck/Qbot.AO
TrendMicro-HouseCallBKDR_QAKBOT.SMG
TencentWin32.Trojan-spy.Zbot.Tbir
YandexTrojan.GenAsa!uZ2LKbecRJ8
IkarusNet-Worm.Win32.Kolab
MaxSecureTrojan.Malware.1721151.susgen
FortinetW32/Kryptik.WCH!tr
AVGWin32:Spyware-gen [Spy]
AvastWin32:Spyware-gen [Spy]
CrowdStrikewin/malicious_confidence_60% (W)

How to remove Trojan-Spy.Win32.Zbot.bfok?

Trojan-Spy.Win32.Zbot.bfok removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment