Worm

Worm:Win32/Teribot.A removal tips

Malware Removal

The Worm:Win32/Teribot.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Teribot.A virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Unconventionial language used in binary resources: Russian
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Detects Sandboxie through the presence of a library
  • Installs itself for autorun at Windows startup
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Worm:Win32/Teribot.A?


File Info:

name: A007BACD2A91137B6317.mlw
path: /opt/CAPEv2/storage/binaries/e2381e011d8dfc1051d99e65d6d65e7f045a0fcfec4d4e7108b7a60a1d64ae2b
crc32: B7D3B395
md5: a007bacd2a91137b63174740380b6c2b
sha1: e4e1c64e569419aff84a6496bfaf0b903e230352
sha256: e2381e011d8dfc1051d99e65d6d65e7f045a0fcfec4d4e7108b7a60a1d64ae2b
sha512: 8c8d7eb60f75e00f31c4ae9306da46afecf9ce4269976f042faa7d8bc6398f242d5c53d01550fc8d12043f041ede23bcd00c55a100b7f5581f4509cb6e817af6
ssdeep: 6144:Wg5E2VmxrCDR8lcv9R++HYdTOzbl/p3RLUbSL32:W8u1CKlWxETGxBLUbg2
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13A140216BD279CB4D516CF3CE6A3E205556CE8F01FE25452328E9DACC33A2D2871A375
sha3_384: 750573eb34df5678dc2185422546fab896866155f0a72e753c2f66b3e703c62bcfde149b2a3f78559a5205240b9011e5
ep_bytes: 833d4bd4420000756a8b1d4bd4420085
timestamp: 1992-06-19 22:22:17

Version Info:

0: [No Data]

Worm:Win32/Teribot.A also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Jorik.4!c
Elasticmalicious (high confidence)
DrWebTrojan.SMSSend.2363
MicroWorld-eScanGen:Variant.Razy.567746
FireEyeGeneric.mg.a007bacd2a91137b
ALYacGen:Variant.Razy.567746
CylanceUnsafe
VIPRETrojan.Win32.Generic.pak!cobra
SangforSuspicious.Win32.Save.a
K7AntiVirusTrojan ( 7000000f1 )
AlibabaTrojanDownloader:Win32/EncPk.8ed40f5e
K7GWTrojan ( 7000000f1 )
Cybereasonmalicious.d2a911
BitDefenderThetaGen:NN.ZexaF.34232.mGX@aOiJ!Tmk
VirITTrojan.Win32.Zyx.MS
CyrenW32/DelfInject.AM.gen!Eldorado
SymantecPacked.Generic.382
ESET-NOD32Win32/TrojanDownloader.Small.OVZ
TrendMicro-HouseCallTROJ_GEN.R002C0CB822
Paloaltogeneric.ml
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.567746
NANO-AntivirusTrojan.Win32.SmsSend.cbobaq
AvastWin32:Small-HTXM [Trj]
TencentWin32.Trojan.Generic.Lhml
Ad-AwareGen:Variant.Razy.567746
EmsisoftGen:Variant.Razy.567746 (B)
ComodoTrojWare.Win32.Kryptik.AKFL@4r8ffy
ZillyaTrojan.Jorik.Win32.116412
TrendMicroTROJ_GEN.R002C0CB822
McAfee-GW-EditionBehavesLike.Win32.ZBot.ch
SophosMal/Generic-R + Mal/EncPk-AEH
IkarusTrojan-Spy.Win32.Zbot
GDataGen:Variant.Razy.567746
AviraDR/Delphi.Gen8
Antiy-AVLTrojan/Win32.Unknown
KingsoftWin32.Troj.Jorik.(kcloud)
GridinsoftRansom.Win32.Zbot.sa
ArcabitTrojan.Razy.D8A9C2
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftWorm:Win32/Teribot.A
CynetMalicious (score: 100)
AhnLab-V3Spyware/Win32.Zbot.R33893
Acronissuspicious
McAfeePWS-Zbot.gen.ahr
MAXmalware (ai score=100)
VBA32Malware-Cryptor.Limpopo
MalwarebytesSpyware.ZeuS
APEXMalicious
RisingSpyware.Voltar!1.AF1D (CLOUD)
YandexTrojan.GenAsa!8jgxszEMB90
SentinelOneStatic AI – Malicious PE
eGambitGeneric.Malware
FortinetW32/Zbot.EQPB!tr
AVGWin32:Small-HTXM [Trj]
PandaTrj/Pacrypt.D
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.4345975.susgen

How to remove Worm:Win32/Teribot.A?

Worm:Win32/Teribot.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment