Spy Trojan

TrojanSpy:Win32/Bebloh.A removal

Malware Removal

The TrojanSpy:Win32/Bebloh.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Bebloh.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Russian
  • Authenticode signature is invalid

How to determine TrojanSpy:Win32/Bebloh.A?


File Info:

name: 099BF6009EA75D9B0CDA.mlw
path: /opt/CAPEv2/storage/binaries/763f9add67db61912a4ee0d4cdd351dc928c9f19f038570d1183beddb044a6fe
crc32: F6CA0E71
md5: 099bf6009ea75d9b0cdab161fcee0634
sha1: 9880cc7c4f067fab19d602f410c3a9583382f33b
sha256: 763f9add67db61912a4ee0d4cdd351dc928c9f19f038570d1183beddb044a6fe
sha512: a93773eb76471cf180d582cf8eea165c622c2c0a25a3387c25e7dfa38235b2833851b1d0e1d45ea2dd0b9ef441c4747582eb5ba415a8a87ca9df6b9802e6ca73
ssdeep: 1536:WVrBu8PIHcIrBROc4E9/ZQ/wu/U+ssssbppFyj6QlrBciEvppq:WV9Nw8yBgcH9Rzu/U19eppAFrBcNHq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108837B1F44EAF27FEE784FB445683B841E2B9CB14BB32619EF6038CDD6196A42025F51
sha3_384: a5cf4b41b13e0914f8d8f00345b00ac46e098ffafba01d6c0ab8e8cd1bee86b4786d7de2275ae8d3d70f5f7b304084dd
ep_bytes: 837dd8000f84080000000bd74be99200
timestamp: 2004-05-02 16:22:31

Version Info:

CompanyName: урДЯПощШаЛъбпЧапФипмтЧШжЬСЖуБ
FileDescription: цпПиНшВЧвсюрСчУЧЪГвбйжЭХ
FileVersion: 62.69.9.67
InternalName: хЖЧОоТЗогэлЮдаМмЭЗхулъК
LegalCopyright: зТШЛйрТцвевчмЕДШЬАфМВшУвлкГ
OriginalFilename: hpgQylY.exe
ProductName: ЮСДзпяЯСлоВуМШейНфбРЕпЬ
ProductVersion: 62.69.9.67
Translation: 0x0008 0x0000

TrojanSpy:Win32/Bebloh.A also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.Krap.3!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Krypt.28
ALYacGen:Heur.Krypt.28
CylanceUnsafe
VIPRETrojan.Win32.Nedsym.f (v)
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanSpy:Win32/Bebloh.4f8356cb
K7GWRiskware ( 0040eff71 )
K7AntiVirusRiskware ( 0040eff71 )
VirITTrojan.Win32.Packed.BECL
CyrenW32/Qakbot.A.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Generik.MWSGDRF
APEXMalicious
AvastWin32:MalOb-IJ [Cryp]
BitDefenderGen:Heur.Krypt.28
NANO-AntivirusTrojan.Win32.Krap.ctvtjs
TencentWin32.Packed.Krap.Gvr
Ad-AwareGen:Heur.Krypt.28
SophosMal/Generic-S + Mal/Qbot-B
ComodoTrojWare.Win32.PkdKrap.Gx@27uldg
DrWebTrojan.Packed.20343
ZillyaTrojan.Katusha.Win32.47231
TrendMicroBKDR_QAKBOT.SMC
McAfee-GW-EditionPWS-Zbot.gen.aum
EmsisoftGen:Heur.Krypt.28 (B)
Paloaltogeneric.ml
GDataGen:Heur.Krypt.28
JiangminTrojanDownloader.Piker.azd
AviraTR/Dropper.Gen
ArcabitTrojan.Krypt.28
MicrosoftTrojanSpy:Win32/Bebloh.A
CynetMalicious (score: 100)
Acronissuspicious
MAXmalware (ai score=100)
MalwarebytesMachineLearning/Anomalous.100%
TrendMicro-HouseCallBKDR_QAKBOT.SMC
RisingDropper.Generic!8.35E (CLOUD)
YandexTrojan.Packed!b4HRzNDLuas
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Downloader
FortinetW32/Krap.HM!tr
BitDefenderThetaAI:Packer.360555BA1F
AVGWin32:MalOb-IJ [Cryp]
PandaTrj/Krapack.gen

How to remove TrojanSpy:Win32/Bebloh.A?

TrojanSpy:Win32/Bebloh.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment