Trojan

Trojan.SpamBot removal

Malware Removal

The Trojan.SpamBot is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.SpamBot virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Created a service that was not started

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Trojan.SpamBot?


File Info:

crc32: 1C6C6754
md5: 954e5bfc83812346d1cd11a59f7d205d
name: 32.exe
sha1: 179dd32769c491758ff2e418c9b20efc94af5725
sha256: 38d3f45c15d354a76eaa73d2da717165dee22b8207fa87088685486019ff482d
sha512: 1d9eb7e3548e9082cccff9823ef7c205d9f161e35b66be22cc9737cfbf013781e56647fb54941945614310ba91f44904fe3341d03cb39779bbc41a1951503feb
ssdeep: 49152:mshUlx6PWNfwfFtSYlvenkSH9J/Djs6IIIIIIIR:rUloaUtSAvgNH9JXjIIIIIIIR
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
InternalName: PkgMgr.exe
FileVersion: 6.1.7601.23505 (win7sp1_ldr.160722-0600)
CompanyName: Microsoft Corporation
ProductName: Microsoftxae Windowsxae Operating System
ProductVersion: 6.1.7601.23505
FileDescription: Windows Package Manager
OriginalFilename: PkgMgr.exe
Translation: 0x0409 0x04b0

Trojan.SpamBot also known as:

BkavW32.AIDetectVM.malware
MicroWorld-eScanTrojan.Lupus.Gen.1
FireEyeGeneric.mg.954e5bfc83812346
CAT-QuickHealTrojan.Generic
McAfeeArtemis!954E5BFC8381
ALYacTrojan.Lupus.Gen.1
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 005534121 )
BitDefenderTrojan.Lupus.Gen.1
K7GWTrojan ( 005534121 )
Cybereasonmalicious.769c49
TrendMicroRansom.Win32.SHADE.SMB.hp
F-ProtW32/Agent.BAE.gen!Eldorado
APEXMalicious
Paloaltogeneric.ml
GDataTrojan.Lupus.Gen.1
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojan:Win32/Morphisil.1216d606
NANO-AntivirusTrojan.Win32.Morphisil.ftulri
Endgamemalicious (high confidence)
EmsisoftTrojan.Lupus.Gen.1 (B)
ComodoMalware@#2w5vm2k53l7kt
F-SecureTrojan.TR/Crypt.Agent.ervvk
DrWebTrojan.Ssebot.2
ZillyaTrojan.Generic.Win32.917026
Invinceaheuristic
McAfee-GW-EditionArtemis!Trojan
Trapminemalicious.moderate.ml.score
SophosMal/Generic-S
IkarusTrojan.Win32.Crypt
CyrenW32/Agent.BAE.gen!Eldorado
JiangminTrojan.Generic.eexee
WebrootW32.Trojan.Gen
AviraTR/Crypt.Agent.ervvk
MAXmalware (ai score=100)
ArcabitTrojan.Lupus.Gen.1
AegisLabTrojan.Win32.Lupus.4!c
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPUA:Win32/OpenDownloadManager
Acronissuspicious
VBA32BScope.Trojan.Yakes
Ad-AwareTrojan.Lupus.Gen.1
MalwarebytesTrojan.SpamBot
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.GUSX
TrendMicro-HouseCallRansom.Win32.SHADE.SMB.hp
TencentWin32.Trojan.Falsesign.Hrys
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.74446422.susgen
FortinetW32/Kryptik.GLWT!tr
BitDefenderThetaGen:NN.ZexaF.34090.Yr1@aGcW@Mki
AVGWin32:DangerousSig [Trj]
AvastWin32:DangerousSig [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.604

How to remove Trojan.SpamBot?

Trojan.SpamBot removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment