Trojan

How to remove “TrojanDownloader:Win32/Beebone.KC”?

Malware Removal

The TrojanDownloader:Win32/Beebone.KC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanDownloader:Win32/Beebone.KC virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Behavioural detection: Injection (inter-process)
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • Attempts to modify proxy settings
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine TrojanDownloader:Win32/Beebone.KC?


File Info:

name: 6D9B433DCB940F825A47.mlw
path: /opt/CAPEv2/storage/binaries/b46356060e0a6a10f44a0e890dff471a0d409c041566a81081130181f9070e10
crc32: 6B0568AA
md5: 6d9b433dcb940f825a47221fa822d570
sha1: 45d80dafa0670877a5e3291f3ab04f9395e9c14b
sha256: b46356060e0a6a10f44a0e890dff471a0d409c041566a81081130181f9070e10
sha512: 187707928b20b8a9afbc673a786cbd24a7430e5e41701285655f46c01efbd682dca88b48ee56124a24ab6749f2d3b393303ce97a7054780871dea3eff36472dd
ssdeep: 1536:ohKRwCmfoI/cnN2A6ZhMQBPZXSCS3+Zkm7uFHtGQnPMb:ohUmfoGcnUxCHWp
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1FBA3D413E784996BC9266BF3157E1324E727E93016C38B43F5C16A783E336A18E253C6
sha3_384: 5ec5743fa6a8f689f788caaafb6f0cd632033118c5bc259275d2c286000a9f8161361ee00d98a51a7ccc06002a849e99
ep_bytes: 68101d4000e8f0ffffff000040000000
timestamp: 1970-01-01 00:00:00

Version Info:

LegalTrademarks: ouumr
ProductName: vazyais
FileVersion: 6.11
ProductVersion: 6.11
InternalName: fjff
OriginalFilename: fjff.exe

TrojanDownloader:Win32/Beebone.KC also known as:

BkavW32.AIDetectMalware
LionicWorm.Win32.VBNA.lKmM
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader9.33267
MicroWorld-eScanGen:Variant.Symmi.27262
ClamAVWin.Dropper.Nanocore-7780275-0
CAT-QuickHealTrojan.Beebone.D
MalwarebytesMalware.AI.1617876847
VIPREGen:Variant.Symmi.27262
SangforSuspicious.Win32.Save.vb
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Symmi.27262
K7GWTrojan ( 005042e71 )
K7AntiVirusTrojan ( 005042e71 )
BitDefenderThetaGen:NN.ZevbaF.36662.gm0@a0PMcAii
VirITTrojan.Win32.VBCrypt.FMB
CyrenW32/Vobfus.NT.gen!Eldorado
SymantecW32.Changeup!gen44
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/VBObfus.QF
AvastWin32:Downloader-VGN [Trj]
CynetMalicious (score: 99)
KasperskyWorm.Win32.WBNA.ipa
AlibabaWorm:Win32/VBInject.5b808f35
NANO-AntivirusTrojan.Win32.WBNA.crgjbo
ViRobotWorm.Win32.WBNA.102400
RisingWorm.WBNA!8.321 (TFE:3:hWEbRIl8ijR)
SophosMal/SillyFDC-S
F-SecureTrojan.TR/Beebone.1024005
BaiduWin32.Trojan.Inject.ab
ZillyaTrojan.VBObfus.Win32.7366
McAfee-GW-EditionVBObfus.g
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.6d9b433dcb940f82
EmsisoftGen:Variant.Symmi.27262 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Symmi.27262
JiangminWorm.WBNA.akoj
WebrootW32.WBNA.ipa
AviraTR/Beebone.1024005
Antiy-AVLWorm/Win32.WBNA.gen
XcitiumTrojWare.Win32.Beebone.KC@50vruk
ArcabitTrojan.Symmi.D6A7E
SUPERAntiSpywareTrojan.Agent/Gen-Injector
ZoneAlarmWorm.Win32.WBNA.ipa
MicrosoftTrojanDownloader:Win32/Beebone.KC
GoogleDetected
AhnLab-V3Worm/Win32.WBNA.R78665
VBA32BScope.Trojan.Diple
MAXmalware (ai score=100)
DeepInstinctMALICIOUS
Cylanceunsafe
PandaGeneric Malware
APEXMalicious
TencentWin32.Worm.Wbna.Cplw
TACHYONWorm/W32.VB-WBNA.102400.B
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Refroso.AGEA!tr
AVGWin32:Downloader-VGN [Trj]
Cybereasonmalicious.dcb940

How to remove TrojanDownloader:Win32/Beebone.KC?

TrojanDownloader:Win32/Beebone.KC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment