Spy Trojan

TrojanSpy:Win32/Shiotob.B removal instruction

Malware Removal

The TrojanSpy:Win32/Shiotob.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Shiotob.B virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Deletes its original binary from disk
  • Behavioural detection: Injection (inter-process)
  • Collects information to fingerprint the system

How to determine TrojanSpy:Win32/Shiotob.B?


File Info:

name: FD8FB17BF341AD683662.mlw
path: /opt/CAPEv2/storage/binaries/20be1be9e8d5df0b7da35928312b6b092516213f40c27fd706b16aee3657d5e8
crc32: 0167AFC9
md5: fd8fb17bf341ad683662166162cb23df
sha1: e670d31d0ea954b890f54fea54a30678b114444a
sha256: 20be1be9e8d5df0b7da35928312b6b092516213f40c27fd706b16aee3657d5e8
sha512: 3869b9f12313828b4cf21b1a9b5746a1891866b1429b9c2ae05421bf5d7e371029cfd49671bebd77dc8d4ad9602aaebfa793175d026e515d9f4525387648f372
ssdeep: 3072:pbo5HuMvr3WtJqB+gIR9Si/oOWTHZ1oyRzjJqaJe:a5OMvrmtJqBA95/oFkytJqaJe
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CC64CE265F938073C65E0BFF291A44678EF0BF240B27C6B3224256DDA7E79510EB924D
sha3_384: 98204dd2ada8a5ab0c0467c1f5f270ff37b82503ae75d90dd80cf395368f205fbb55f64108516963d2f27d4e5da94ae5
ep_bytes: 558bec518bcd8bc18945fc8bc9ff75fc
timestamp: 2013-08-23 12:16:08

Version Info:

0: [No Data]

TrojanSpy:Win32/Shiotob.B also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.fd8fb17bf341ad68
McAfeeGenericRXLO-WJ!FD8FB17BF341
CylanceUnsafe
VIPRETrojan.Win32.Reveton.a (v)
SangforTrojan.Win32.Save.a
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaTrojanSpy:Win32/Shiotob.42688e97
K7GWSpyware ( 0055e3db1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecPacked.Generic.459
ESET-NOD32Win32/Spy.Bebloh.K
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Symmi.28722
NANO-AntivirusTrojan.Win32.Inject1.eadjqv
MicroWorld-eScanGen:Variant.Symmi.28722
AvastWin32:Bublik-L [Spy]
TencentWin32.Trojan.Generic.Egep
Ad-AwareGen:Variant.Symmi.28722
EmsisoftGen:Variant.Symmi.28722 (B)
ComodoTrojWare.Win32.Kryptik.BVPL@57uzhp
DrWebTrojan.Inject1.28125
ZillyaTrojan.Bebloh.Win32.412
TrendMicroPossible_MALSTRC
McAfee-GW-EditionBehavesLike.Win32.Generic.fm
SophosMal/Generic-R + Mal/Zbot-FG
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Symmi.28722
JiangminWorm/Delf.yj
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1227089
MAXmalware (ai score=100)
Antiy-AVLTrojan/Generic.ASMalwS.3C28EE
KingsoftWin32.Troj.Generic_a.a.(kcloud)
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftTrojanSpy:Win32/Shiotob.B
AhnLab-V3Trojan/Win32.Yakes.R103003
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.34212.s8W@amF4Vfl
ALYacGen:Variant.Symmi.28722
TACHYONTrojan/W32.Yakes.309760.B
VBA32Trojan.Yakes
TrendMicro-HouseCallPossible_MALSTRC
RisingSpyware.Bebloh!8.790 (CLOUD)
YandexTrojan.GenAsa!uXICmT2qfKI
IkarusTrojan.Win32.Yakes
eGambitGeneric.Malware
FortinetW32/Zbot.FG!tr
AVGWin32:Bublik-L [Spy]
Cybereasonmalicious.bf341a
PandaTrj/Dtcontx.G
MaxSecureTrojan.Malware.6349382.susgen

How to remove TrojanSpy:Win32/Shiotob.B?

TrojanSpy:Win32/Shiotob.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment