Spy Trojan

Trojan:Win32/Spybot.BK!MTB malicious file

Malware Removal

The Trojan:Win32/Spybot.BK!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Spybot.BK!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Creates a slightly modified copy of itself
  • Anomalous binary characteristics

Related domains:

redirector.gvt1.com
r1—sn-4g5e6ne6.gvt1.com
update.googleapis.com

How to determine Trojan:Win32/Spybot.BK!MTB?


File Info:

crc32: F9469661
md5: 402743ba7e009ddc180d17cad59a116a
name: 402743BA7E009DDC180D17CAD59A116A.mlw
sha1: e3dd52bcc9eeab3fc1aa7313fca11e0aa1a99ad8
sha256: 8cdb536378c7a12bb65333b52664cb99cd74a8b14afbc1b74ae73111b8edfc57
sha512: e17da7120b6011f2ef937d0e013973724d7a9d19784277c48b1f6c70f9a784b955813b1064a15da3571d2230e41054fc7357cd6d3f35e5fe8d901b39b83de373
ssdeep: 6144:8ZMrqx40J16pbzXYIiy0at42EDLIxL3G8fiZqhuyAHLELSiOg3C4wW/oUoa6UmK5:8ZMmb2dMLaV3J3RL2ExOgJRoUoa6vKVH
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Trojan:Win32/Spybot.BK!MTB also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.36032076
FireEyeGeneric.mg.402743ba7e009ddc
ALYacSpyware.AgentTesla
CylanceUnsafe
VIPREVirTool.Win32.Obfuscator.da!k (v)
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.36032076
K7GWRiskware ( 0040eff71 )
CyrenW32/Trojan.OFQD-4782
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
KasperskyTrojan.Win32.Zenpak.bczc
AlibabaBackdoor:Win32/Spybot.2519185a
NANO-AntivirusVirus.Win32.Gen.ccmw
ViRobotTrojan.Win32.Z.Spybot.320000
AegisLabTrojan.Win32.Zbot.lx9X
RisingDropper.Generic!8.35E (TFE:5:zmXUi4vfSnG)
Ad-AwareTrojan.GenericKD.36032076
EmsisoftTrojan.GenericKD.36032076 (B)
ComodoMalware@#1ysv8nef3ey79
F-SecureBackdoor.BDS/ZeroAccess.Gen7
DrWebBackDoor.SpyBotNET.25
TrendMicroTROJ_GEN.R002C0DA721
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
SophosMal/Generic-S
IkarusTrojan.Inject
WebrootW32.Trojan.Gen
AviraBDS/ZeroAccess.Gen7
MAXmalware (ai score=89)
Antiy-AVLTrojan/Win32.Zenpak
KingsoftWin32.Troj.Zenpak.bc.(kcloud)
MicrosoftTrojan:Win32/Spybot.BK!MTB
GridinsoftTrojan.Win32.Downloader.oa
ArcabitTrojan.Generic.D225CE4C
ZoneAlarmTrojan.Win32.Zenpak.bczc
GDataTrojan.GenericKD.36032076
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C4292285
McAfeeRDN/Spybot.worm.gen
VBA32Trojan.Zenpak
MalwarebytesSpyware.TelegramBot.TOR.Generic
PandaTrj/CI.A
ZonerTrojan.Win32.100493
ESET-NOD32a variant of Win32/Kryptik.HIQE
TrendMicro-HouseCallTROJ_GEN.R002C0DA721
TencentWin32.Trojan.Inject.Auto
YandexTrojan.Zenpak!GSyMK6eed+o
SentinelOneStatic AI – Malicious PE
FortinetW32/Kryptik.HIOZ!tr
BitDefenderThetaGen:NN.ZexaF.34760.tCZ@aueOP!di
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)
Qihoo-360Generic/Backdoor.7ae

How to remove Trojan:Win32/Spybot.BK!MTB?

Trojan:Win32/Spybot.BK!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment