Malware

What is “Win32/TrickBot.CC”?

Malware Removal

The Win32/TrickBot.CC is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/TrickBot.CC virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Unconventionial language used in binary resources: Greek
  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Win32/TrickBot.CC?


File Info:

crc32: CA5A8C65
md5: 3f122e1ce7a0d1340f528908703e14e0
name: 765655964.exe
sha1: 5c046212f01b8de16e12169f90ade6c80be06c27
sha256: 466180307577b710f3953cb9a8996dbc5c72e906d311b0e85f3c5dcc47b3da83
sha512: f26bc31b283e3afc8ea5508970bd3157cbfa63f155f86570c8cdfdc86e66829f7ebfc02c0f1254d071026b54ed86c1372d1640597d14f7973729ee634cf751d9
ssdeep: 6144:IfcsEUZ6iRyvTkvJoofi2AlRl8iRBpNUXd6c3Hb5wt6k/6hL3jgVsU:F5vwJoT2AlR2W2Xdv50GQVN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: Bismillah RI
FileVersion: 1.0.0.0
CompanyName: AZM TECHNOLOGY GROUP
LegalTrademarks:
ProductName: BRI V1.1.0
ProductVersion: 1.0.0.0
OriginalFilename: Bismillah RI.exe

Win32/TrickBot.CC also known as:

FireEyeGeneric.mg.3f122e1ce7a0d134
McAfeeArtemis!3F122E1CE7A0
MalwarebytesTrojan.TrickBot
AegisLabTrojan.Multi.Generic.4!c
Cybereasonmalicious.2f01b8
BitDefenderThetaGen:NN.ZevbaF.32515.Iq1@a8XZGjhG
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/TrickBot.CC
TrendMicro-HouseCallTROJ_FRS.VSNW1BK19
GDataWin32.Trojan.Agent.T9QHLE
KasperskyUDS:DangerousObject.Multi.Generic
F-SecureTrojan.TR/AD.TrickBot.batw
DrWebTrojan.Inject3.31100
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.hh
SentinelOneDFI – Malicious PE
APEXMalicious
WebrootW32.Trojan.Gen
AviraTR/AD.TrickBot.batw
Endgamemalicious (high confidence)
ZoneAlarmUDS:DangerousObject.Multi.Generic
MicrosoftTrojan:Win32/Zpevdo.A
Acronissuspicious
AVGFileRepMetagen [Malware]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.BO.24d

How to remove Win32/TrickBot.CC?

Win32/TrickBot.CC removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment