Spy

Win32/Spy.Bebloh.J removal tips

Malware Removal

The Win32/Spy.Bebloh.J is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Bebloh.J virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Win32/Spy.Bebloh.J?


File Info:

name: 23405B70218A5A989757.mlw
path: /opt/CAPEv2/storage/binaries/32a62d64d0c6afc5c3e2bd4a6867232e3ca4111e80a7124625750f094db7759f
crc32: 343F64EA
md5: 23405b70218a5a9897573bc8c6ff6573
sha1: 06e0bf5bc32e5a122fbb131d38d5d02929b185e5
sha256: 32a62d64d0c6afc5c3e2bd4a6867232e3ca4111e80a7124625750f094db7759f
sha512: cd3717750870c2f38892c691b00b07d7dd7ee285c90d2654272429cc8a2106eb3d6c3f88c3d92d52ac54b6f353b0522c1af288f9bab1b4c98d0036969040cd41
ssdeep: 3072:clK44Y3ZXhsPX1ROir6QBiA1BcbB2gUgoTxD1rWxpWfMn1OGfQeu/duHAjmcWGq8:PDCQX1ROjQB/fOq7dD1yR1OxEHTGq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10B94F1C07A44AAD7E456B4F94447DEB0AC605CA90C92FB57F180FE3EB0D1BA1C1A6B1D
sha3_384: 75f7970aff2422d56327d9a4b3e752bfb9f9375f7034ff3b5db97f7b9c0f5d9a75f4b94578f594cce976256e6484a93e
ep_bytes: 558bec518bcd8bc18945fc8bc9ff75fc
timestamp: 2013-04-18 06:55:23

Version Info:

CompanyName: Hilgraeve, Inc.
FileDescription: HyperTerminal Applet
FileVersion: 5.1.2600.0
InternalName: HyperTrm
LegalCopyright: Copyright © Hilgraeve, Inc. 2001
LegalTrademarks: HyperTerminal ® is a registered trademark of Hilgraeve, Inc.
OriginalFilename: HYPERTRM.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.1.2600.0
Comments: HyperTerminal ® was developed by Hilgraeve, Inc. for Microsoft
Translation: 0x0409 0x0000

Win32/Spy.Bebloh.J also known as:

BkavW32.AIDetectMalware
tehtrisGeneric.Malware
CynetMalicious (score: 100)
FireEyeGeneric.mg.23405b70218a5a98
McAfeeZeroAccess-FBQU!23405B70218A
VIPRETrojan.GenericKDZ.17116
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 004bcce41 )
K7AntiVirusTrojan ( 004bcce41 )
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Spy.Bebloh.J
APEXMalicious
BitDefenderTrojan.GenericKDZ.17116
MicroWorld-eScanTrojan.GenericKDZ.17116
AvastWin32:Bublik-L [Spy]
EmsisoftTrojan.GenericKDZ.17116 (B)
F-SecureTrojan.TR/Crypt.EPACK.Gen2
DrWebBackDoor.Siggen.52049
ZillyaTrojan.Bublik.Win32.9921
McAfee-GW-EditionBehavesLike.Win32.Generic.gt
Trapminemalicious.high.ml.score
SophosMal/ZAccess-CG
IkarusTrojan.Win32.Reveton
GDataTrojan.GenericKDZ.17116
AviraTR/Crypt.EPACK.Gen2
Antiy-AVLTrojan/Win32.Bublik
ArcabitTrojan.Generic.D42DC
MicrosoftTrojanSpy:Win32/Shiotob.A
GoogleDetected
BitDefenderThetaGen:NN.ZexaF.36196.Aq0@aG5JYSpi
ALYacTrojan.GenericKDZ.17116
MAXmalware (ai score=86)
VBA32BScope.Malware-Cryptor.SB.01798
Cylanceunsafe
PandaTrj/Hexas.HEU
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.121218.susgen
AVGWin32:Bublik-L [Spy]
Cybereasonmalicious.0218a5
DeepInstinctMALICIOUS

How to remove Win32/Spy.Bebloh.J?

Win32/Spy.Bebloh.J removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment