Spy

How to remove “Spyware.15497”?

Malware Removal

The Spyware.15497 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.15497 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • Mimics the system’s user agent string for its own requests
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Performs some HTTP requests
  • Unconventionial binary language: Russian
  • The binary likely contains encrypted or compressed data.
  • Network activity contains more than one unique useragent.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
tools.ip2location.com

How to determine Spyware.15497?


File Info:

crc32: 8720C345
md5: 3f60620e012a04f6707c4f3e7c195cec
name: 3F60620E012A04F6707C4F3E7C195CEC.mlw
sha1: 77eec0dd3616bc04060f335b2c9e8af5b9b2a466
sha256: 3c765bc68639a4798a0d4a73083a4f3ab28157f1814880fc2367e26e39e3d392
sha512: 41f21ac6ebeb349a0827e60bee224127d0dd16a3a1a89843bd64b94d74600bdcabaffc4608939051a17b648ab235a11952c0db4401a2c944d6638b7f76d06e70
ssdeep: 3072:loQkdWhWyrfQDd50KGNvwVmWri59LGEy:yQkdko50KswVNO5JGf
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: mpg4dmod.dll
FileVersion: 9.00.00.4503
ProductName: Microsoftxae Windows Media Services
ProductVersion: 9.00.00.4503
FileDescription: Windows Media MPEG-4 Video Decoder
Translation: 0x0419 0x04b0

Spyware.15497 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 0055e4091 )
LionicTrojan.Win32.HmBlocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.3260
CynetMalicious (score: 100)
ALYacSpyware.15497
CylanceUnsafe
ZillyaTrojan.HmBlocker.Win32.524
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaRansom:Win32/Genasom.e10bf75b
K7GWTrojan ( 0055e4091 )
Cybereasonmalicious.e012a0
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/LockScreen.AFR
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Hmblocker-1170
KasperskyHEUR:Hoax.Win32.FrauDrop.gen
BitDefenderSpyware.15497
NANO-AntivirusTrojan.Win32.HmBlocker.ecrjkj
ViRobotSpyware.Ransom.HmBlocker.118784
MicroWorld-eScanSpyware.15497
TencentWin32.Trojan.Hmblocker.Lmuq
Ad-AwareSpyware.15497
SophosMal/Generic-R + Troj/Zbot-ARU
ComodoTrojWare.Win32.Kryptik.MNM@4urmgy
BitDefenderThetaGen:NN.ZexaF.34050.hq0@aSNFi@ni
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_SPNR.30IN13
McAfee-GW-EditionPWS-Spyeye.av
FireEyeGeneric.mg.3f60620e012a04f6
EmsisoftSpyware.15497 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan/HmBlocker.auf
WebrootW32.Spyware.Gen
AviraTR/Crypt.ZPACK.Gen8
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.3CE8EE
KingsoftWin32.Troj.EncodeIe.ao.(kcloud)
MicrosoftRansom:Win32/Genasom.EY
ArcabitSpyware.D3C89
SUPERAntiSpywareTrojan.Agent/Gen-Downloader
GDataSpyware.15497
TACHYONTrojan/W32.HmBlocker.118784
AhnLab-V3Trojan/Win32.Lebag.C96134
McAfeePWS-Spyeye.av
MAXmalware (ai score=100)
PandaGeneric Malware
TrendMicro-HouseCallTROJ_SPNR.30IN13
YandexTrojan.HmBlocker.A
IkarusGen.Variant.Carberp
FortinetW32/HmBlocker.DSQ!tr
AVGWin32:Trojan-gen
Qihoo-360Win32/Ransom.Genasom.HgIASOYA

How to remove Spyware.15497?

Spyware.15497 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment