How to remove Shiotob Spyware from PC?

In this article, I am going to tell you about the signs of Shiotob spyware presence, as well as the way to remove Shiotob spyware virus from your PC.

GridinSoft Anti-Malware
Editor's choice
GridinSoft Anti-Malware
Manual Shiotob removal might be a lengthy and complicated process that requires expert skills. GridinSoft Anti-Malware is a professional antivirus tool that is recommended to get rid of this Shiotob spyware trojan.
By downloading any software listed on this website you agree to our Privacy Policy and Terms of Use. To use full-featured product, you have to purchase a license for GridinSoft Anti-Malware. 6 days free trial available.

Describing Shiotob spyware

Shiotob TrojanSpy as the virus is not a solitary app, but a component of much larger as well as tricky malware – trojan-stealer. It’s a sort of trojan, which is targeted on your personal data, and also collects totally everything relating to you and also your PC. Normally, stealers have keylogger capabilities1, which let them to catch your keystrokes. Besides that, this virus can collect your cookie files, your phone number, location; it likewise can thieve all your passwords from the keychain within the web browser.

Name Shiotob
Infection Type Spyware
  • Behavioural detection: Executable code extraction – unpacking;
  • Yara rule detections observed from a process memory dump/dropped files/CAPE;
  • Creates RWX memory;
  • Dynamic (imported) function loading detected;
  • CAPE extracted potentially suspicious content;
  • Unconventionial language used in binary resources: Russian;
  • The binary contains an unknown PE section name indicative of packing;
  • Authenticode signature is invalid;
Similar behavior Bebloh, Chaori, Tinclex
Fix Tool

See If Your System Has Been Affected by Shiotob spyware

Nevertheless, the significant share of Shiotob spy are hunting for your banking data: credit card number, safety codes as well as expiration date. In situation if you utilize online banking, the Shiotob stealer virus is able to jeopardize your login and password, so the thugs will get access to your account. Different business information might likewise be an item of attention of Shiotob virus distributors, and in case of large companies such information leakage may create catastrophic results.

Statistics of spyware activity in 2020
TrojanSpy activity in 2020, compared to backdoor viruses activity

The major dispersal manners of Shiotob spyware are very similar to other trojans. Nowadays, most of such programs are spread out via e-mail additions. These attachments (. docx,. pdf files) include infected macroses, which are utilized by Shiotob spy to corrupt your system. Sometimes, these letters consist of web links to the phishing clones of official websites, like Facebook, Twitter, LinkedIn or so.

Rating of different spyware activity

Most popular spyware in 20202

It is very important to point out that there is a separate group of spywarefor Android operating system. Such apps have the same capabilities as the PC version does, however, mobile malware is distributed as a legit program for checking the girlfriend’s or kids’s area. However, besides thieving various individual data, it can also demonstrate to you a completely incorrect place of the device you are trying to track. Such situations might cause beefs out of the blue.

How can I understand that my computer is infected with Shiotob spyware?

Shiotob spy is an extremely stealth malware, simply because its efficiency depends on how long it can operate prior to being spotted. So, Shiotob spyware producers made everything to make their app existence as insensible as possible. Certainly, you will discover that your accounts in social networks are stolen, as well as cash from your bank account is moving away, but it is too late.

Shiotob also known as

Bkav W32.AIDetect.malware2
Elastic malicious (high confidence)
DrWeb BackDoor.Siggen.52049
MicroWorld-eScan Gen:Variant.Mikey.112007
FireEye Generic.mg.ec89a41ac88cb62a
McAfee PWS-Zbot-FATG!EC89A41AC88C
Cylance Unsafe
Zillya Trojan.Bublik.Win32.10582
Sangfor Trojan.Win32.Save.a
K7AntiVirus Trojan ( 005110401 )
Alibaba TrojanSpy:Win32/Shiotob.4dac41a4
K7GW Trojan ( 005110401 )
Cybereason malicious.ac88cb
BitDefenderTheta Gen:[email protected]
Symantec Packed.Generic.459
ESET-NOD32 Win32/Spy.Bebloh.J
TrendMicro-HouseCall TROJ_SPNR.11EF13
Paloalto generic.ml
Kaspersky HEUR:Trojan.Win32.Generic
BitDefender Gen:Variant.Mikey.112007
NANO-Antivirus Trojan.Win32.Bublik.bqfwae
SUPERAntiSpyware Trojan.Agent/Gen-Zusy
Avast Win32:Bublik-L [Spy]
Rising Spyware.Bebloh!8.790 (CLOUD)
Ad-Aware Gen:Variant.Mikey.112007
Sophos ML/PE-A + Mal/EncPk-AMF
Comodo [email protected]
VIPRE Trojan.Win32.ZAccess.n (v)
TrendMicro TROJ_SPNR.11EF13
McAfee-GW-Edition BehavesLike.Win32.Dropper.fm
Emsisoft Gen:Variant.Mikey.112007 (B)
SentinelOne Static AI – Malicious PE
GData Gen:Variant.Mikey.112007
Jiangmin Trojan.Generic.dwxiu
eGambit Generic.Malware
Antiy-AVL Trojan/Generic.ASMalwS.1E3064
Kingsoft Win32.Troj.Bublik.av.(kcloud)
Gridinsoft Ransom.Win32.Zbot.sa
ZoneAlarm HEUR:Trojan.Win32.Generic
Microsoft TrojanSpy:Win32/Shiotob.A
AhnLab-V3 Trojan/Win32.Yakes.R65751
VBA32 BScope.Malware-Cryptor.Hlux
ALYac Gen:Variant.Mikey.112007
MAX malware (ai score=100)
Malwarebytes Malware.AI.455547103
APEX Malicious
Tencent Win32.Trojan.Generic.Amvx
Yandex Trojan.GenAsa!wUaHU75V0p8
Fortinet W32/Bebloh.J!tr
AVG Win32:Bublik-L [Spy]
Panda Trj/Hexas.HEU
CrowdStrike win/malicious_confidence_100% (D)

Domains that associated with Shiotob:

What are the symptoms of Shiotob trojan?

  • Behavioural detection: Executable code extraction – unpacking;
  • Yara rule detections observed from a process memory dump/dropped files/CAPE;
  • Creates RWX memory;
  • Dynamic (imported) function loading detected;
  • CAPE extracted potentially suspicious content;
  • Unconventionial language used in binary resources: Russian;
  • The binary contains an unknown PE section name indicative of packing;
  • Authenticode signature is invalid;

To avoid infiltration of Shiotob spyware, minimize setting up any type of attachments to the emails from dubious addresses. These days, throughout quarantine, email-distributed malware gets way more active. People (particularly ones that started buying everything on online-marketplaces) do not take note to the odd email addresses, and open everything which reaches their e-mail. And Shiotob stealer is directly in these emails.

How to remove Shiotob spyware?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • “Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

You can attempt to do it manually, nonetheless, like any other trojan, Shiotob TrojanSpy puts into effect the modifications extremely deep within the system. Hence, it’s very difficult to locate all these modifications, and even harder to clean up them out. To take care of this dangerous malware totally, I can suggest you to utilize GridinSoft Anti-Malware.


To detect and remove all malicious programs on your computer with GridinSoft Anti-Malware, it’s better to use Standard or Full scan. Quick Scan is not able to find all malicious items, because it checks only the most popular registry entries and folders.

Scan types in Gridinsoft Anti-Malware

You can observe the detected malicious programs sorted by their possible hazard during the scan process. But to perform any actions against malicious programs, you need to wait until the scan is finished, or to stop the scan.

GridinSoft Anti-Malware during the scan

To choose the action for every detected malicious or unwanted program, click the arrow in front of the name of detected malicious app. By default, all malware will be moved to quarantine.

List of detected malware after the scan

How to remove Shiotob Spyware?

Name: Shiotob

Description: Shiotob TrojanSpy is classified as a type of malware — malicious software designed to gain access to or damage your computer, often without your knowledge. The Shiotob gathers your personal information and relays it to advertisers, data firms, or external users. The Shiotob can install additional software and change the security settings on your PC.

Operating System: Windows

Application Category: Spyware

User Review
4.13 (8 votes)
Comments Rating 0 (0 reviews)
  1. What is Spyware: https://en.wikipedia.org/wiki/Spyware
  2. ESET quaterly report: ESET_Threat_Report_Q22020.pdf

William Reddy

I am from Ireland. My parents bought me a computer when I was 11, and several month after I have got a virus on this PC. I decided to enter the INSA Centre Val de Loire university after being graduated from the school. This French educational institution was offering a brand-new cybersecurity course. After getting the master degree in cybersecurity, I've started working in as virus analyst in a little anti-malware vendor. In 2018, I've decided to start Virus Removal project. The main target of this site is to help people to deal with PC viruses of any kind.

Leave a Reply

Your email address will not be published. Required fields are marked *


Back to top button