Trojan

Trojan.Win32.Bublik.cfct removal tips

Malware Removal

The Trojan.Win32.Bublik.cfct is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Win32.Bublik.cfct virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Created a process from a suspicious location
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

How to determine Trojan.Win32.Bublik.cfct?


File Info:

name: 6168C3F74CEC5288ECC5.mlw
path: /opt/CAPEv2/storage/binaries/e8b62a3c938d4090f551a356030b1bef70cf52ae52eadca96104a46c76cbbfde
crc32: 2D00D502
md5: 6168c3f74cec5288ecc519359f3ca64e
sha1: 725443ac8b234570fcbdb55d259b72f6c34d4ffc
sha256: e8b62a3c938d4090f551a356030b1bef70cf52ae52eadca96104a46c76cbbfde
sha512: a6fd5a420cf0b82be92452a9ad007dfa1b6e0b07c9176806f23d8c8ccc8a36af7093d72d72f21c4c22b3708956450098c551b4e2de8b76fefaac9df907aa787f
ssdeep: 192:zkBKt7bnGFPpHuBp3RGKTxW8YMcvdQgkyAd+6zrPf51JHyqOuEQnU03FDNEm:zk6dvGD8hcv7kyAPzJSjuEQn
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T12DB222FAEBC71EB0D22B8AFA64BB56B34021B01DCD130EDD45E536340C23796586DD9A
sha3_384: 70d9c092efbe47128aac712ecacd74815d3878941d790227ef1b690fb5f86f848550d0b82d498aa8a66e663764c712b9
ep_bytes: e8cbfdffffe97f01000033c0c3558bec
timestamp: 2005-10-12 07:53:35

Version Info:

0: [No Data]

Trojan.Win32.Bublik.cfct also known as:

BkavW32.FamVT.GeND.Trojan
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.1596624
FireEyeGeneric.mg.6168c3f74cec5288
CAT-QuickHealTrojanDownloader.Upatre.A4
McAfeeDownloader-FSH
CylanceUnsafe
VIPRETrojan.Win32.Upatre.jr (v)
K7AntiVirusTrojan-Downloader ( 0048f6391 )
BitDefenderTrojan.GenericKD.1596624
K7GWTrojan-Downloader ( 0048f6391 )
Cybereasonmalicious.74cec5
BaiduWin32.Trojan-Downloader.Waski.a
VirITTrojan.Win32.Zbot.GDD
CyrenW32/Trojan.LLKN-5319
SymantecDownloader.Upatre!gen5
ESET-NOD32Win32/TrojanDownloader.Waski.A
APEXMalicious
ClamAVWin.Downloader.Upatre-5744087-0
KasperskyTrojan.Win32.Bublik.cfct
NANO-AntivirusTrojan.Win32.Bublik.cufcrr
RisingDownloader.Waski!1.A489 (RDMK:cmRtazq62COUow3zEXH7bRihmIqE)
Ad-AwareTrojan.GenericKD.1596624
EmsisoftTrojan.GenericKD.1596624 (B)
ComodoTrojWare.Win32.Upatre.O@58re0o
DrWebTrojan.DownLoader9.41241
ZillyaTrojan.Bublik.Win32.13395
TrendMicroTROJ_UPATRE.SM37
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.mm
SophosML/PE-A + Mal/Upatre-A
IkarusTrojan-Downloader.Win32.Upatre
JiangminTrojan/Bublik.gss
AviraTR/Rogue.AI.14361
MAXmalware (ai score=84)
Antiy-AVLTrojan/Generic.ASMalwS.8DF612
MicrosoftTrojanDownloader:Win32/Upatre.O
ArcabitTrojan.Generic.D185CD0
SUPERAntiSpywareTrojan.Agent/Gen-Dialer
GDataWin32.Trojan-Downloader.Upatre.BK
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Agent.R100612
Acronissuspicious
VBA32BScope.Trojan.Cloxer
ALYacTrojan.GenericKD.1596624
MalwarebytesMalware.AI.1997875158
PandaGeneric Malware
TrendMicro-HouseCallTROJ_UPATRE.SM37
TencentTrojan-Downloader.Win32.Waski.16000151
YandexTrojan.Bublik!NyFZeIRGXo4
SentinelOneStatic AI – Malicious PE
FortinetW32/Waski.A!tr
BitDefenderThetaGen:NN.ZexaF.34182.bqX@aOaIfiki
AVGWin32:Agent-AUID [Trj]
AvastWin32:Agent-AUID [Trj]
CrowdStrikewin/malicious_confidence_100% (D)
MaxSecureTrojan.Upatre.Gen

How to remove Trojan.Win32.Bublik.cfct?

Trojan.Win32.Bublik.cfct removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment