Malware

How to remove “Spammer:Win32/Tedroo.AB”?

Malware Removal

The Spammer:Win32/Tedroo.AB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spammer:Win32/Tedroo.AB virus can do?

  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

How to determine Spammer:Win32/Tedroo.AB?


File Info:

crc32: FEA491F8
md5: b220d4d0d8d45883edb2909b0770d125
name: B220D4D0D8D45883EDB2909B0770D125.mlw
sha1: ba1b182c2a07c4b52a43b7789cc59c6b7995a60c
sha256: a5569ea52518e24b4dc62c5f69b00c3fcdb087e0ab7ccf996bcf851d16a83ae9
sha512: df54c3b2d1e878b17b8f1d2fdc865513c5c5898aa41b0f4d989f0ef36a369ba77d4bd4510dc1b6adf973bdb6bb88f40d5be051ce2d06fddcee9583da2a59e8f2
ssdeep: 768:C3c2PSLIxjjkJ2sSlYNMiwKIykD2AfCkMOPb+TyqAcMKQCI6n9Lo:GPSLIxvnsSlYNM3KIykD2SMOSKa9
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Spammer:Win32/Tedroo.AB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
DrWebTrojan.Spambot.6633
CynetMalicious (score: 100)
ALYacGeneric.FakeAV.10.D5BBCBB0
CylanceUnsafe
ZillyaWorm.Joleee.Win32.3492
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/Tedroo.7d98acdc
Cybereasonmalicious.0d8d45
CyrenW32/Tedroo.A.gen!Eldorado
SymantecTrojan Horse
ESET-NOD32a variant of Win32/SpamTool.Tedroo.AY
APEXMalicious
AvastWin32:KadrBot [Trj]
ClamAVWin.Worm.Joleee-586
KasperskyTrojan-Ransom.Win32.PornoAsset.cxlv
BitDefenderGeneric.FakeAV.10.D5BBCBB0
NANO-AntivirusTrojan.Win32.Spambot.lbqmn
MicroWorld-eScanGeneric.FakeAV.10.D5BBCBB0
TencentWin32.Trojan-dropper.Fraudrop.Pbye
Ad-AwareGeneric.FakeAV.10.D5BBCBB0
SophosMal/Generic-S
ComodoSuspicious@#wu65krcuegpk
BitDefenderThetaAI:Packer.254C8A9F1A
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.QLowZones.nh
FireEyeGeneric.mg.b220d4d0d8d45883
EmsisoftGeneric.FakeAV.10.D5BBCBB0 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/Joleee.dro
WebrootW32.Malware.Gen
AviraTR/Joleee.33792
eGambitUnsafe.AI_Score_83%
Antiy-AVLTrojan/Generic.ASMalwS.BD1388
KingsoftWin32.Troj.FrauDrop.(kcloud)
MicrosoftSpammer:Win32/Tedroo.AB
AegisLabWorm.Win32.Joleee.t!c
ZoneAlarmTrojan-Ransom.Win32.PornoAsset.cxlv
GDataGeneric.FakeAV.10.D5BBCBB0
AhnLab-V3Worm/Win32.Joleee.R2805
Acronissuspicious
McAfeeArtemis!B220D4D0D8D4
MAXmalware (ai score=99)
VBA32BScope.Worm.Joleee.1421
PandaGeneric Malware
RisingTrojan.Generic@ML.100 (RDML:u43Jl7fUYBASwJvdhCdLCg)
YandexTrojan.GenAsa!rQLDJBmbuPs
IkarusEmail-Worm.Win32.Joleee
MaxSecureTrojan.Malware.2258227.susgen
FortinetW32/Tedroo.AF!tr
AVGWin32:KadrBot [Trj]
Paloaltogeneric.ml

How to remove Spammer:Win32/Tedroo.AB?

Spammer:Win32/Tedroo.AB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment