Spy

Spyware.KpotStealer malicious file

Malware Removal

The Spyware.KpotStealer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.KpotStealer virus can do?

  • The binary likely contains encrypted or compressed data.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Spyware.KpotStealer?


File Info:

crc32: 1526F3B4
md5: 0da17fefcf59d348e1ee437b3a9b4c05
name: some2403_soft_2cr10.exe
sha1: 86e5681dab4b6b03d23b09be557d3f14b920283d
sha256: 76f6b1c297fa0a223099ecaab47adc54cf8859e92da4395680d241c30a7c1e48
sha512: 0ace0efecffca69ad0cb8e6406ffac98c6a634394d6f131713d023e3a28b6be8384b6596e3f49f70aa51f9cbb60c2eb297df706607d90f9fbf4019becba90692
ssdeep: 12288:yL8aoxdHnrOz4JeNr4VHbcMcHtvEp61N09kziTfsnKfg:3OzzNroQMcHBc6U98wc8g
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9. All rights reserved. UNIPHIZ Lab
CompanyName: UNIPHIZ Lab
PrivateBuild: 5.4.3.7
ProductName: Minister
ProductVersion: 5.4.3.7
FileDescription: Tplgies Indentation Tfsreportsdefaultcollectionyourprojectname Hierarchyid
OriginalFilename: Minister
Translation: 0x0409 0x04b0

Spyware.KpotStealer also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.GenericKD.42893202
FireEyeGeneric.mg.0da17fefcf59d348
ALYacTrojan.GenericKD.42893202
MalwarebytesSpyware.KpotStealer
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056358e1 )
BitDefenderTrojan.GenericKD.42893202
K7GWTrojan ( 0056358e1 )
Cybereasonmalicious.dab4b6
TrendMicroTrojan.Win32.WACATAC.THCBGBO
BitDefenderThetaGen:NN.ZexaF.34104.zy0@aekjj@gi
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.ENDZWK
TrendMicro-HouseCallTrojan.Win32.WACATAC.THCBGBO
Paloaltogeneric.ml
GDataTrojan.GenericKD.42893202
KasperskyTrojan.Win32.Zenpak.xlh
AlibabaBackdoor:Win32/KZip.542668b0
ViRobotTrojan.Win32.Z.Zenpak.418816
AegisLabTrojan.Win32.Zenpak.4!c
TencentWin32.Trojan.Zenpak.Isn
Ad-AwareTrojan.GenericKD.42893202
SophosMal/Generic-S
F-SecureTrojan.TR/AD.Khalesi.rghtj
Invinceaheuristic
McAfee-GW-EditionRDN/Generic.dx
SentinelOneDFI – Suspicious PE
EmsisoftTrojan.GenericKD.42893202 (B)
APEXMalicious
AviraTR/AD.Khalesi.rghtj
Antiy-AVLTrojan/Win32.Zenpak
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D28E7F92
ZoneAlarmTrojan.Win32.Zenpak.xlh
Acronissuspicious
McAfeeArtemis!0DA17FEFCF59
MAXmalware (ai score=88)
VBA32BScope.TrojanPSW.Fareit
CylanceUnsafe
PandaTrj/CI.A
RisingTrojan.Generic@ML.95 (RDML:BbdlAj5Tijw9ET6N+jEWxQ)
IkarusTrojan-Ransom.Crysis
eGambitUnsafe.AI_Score_100%
FortinetW32/Zenpak.ENDZWK!tr
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360Win32/Trojan.78c

How to remove Spyware.KpotStealer?

Spyware.KpotStealer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment