Spy Trojan

Trojan-Spy.Win32.Teamspy (file analysis)

Malware Removal

The Trojan-Spy.Win32.Teamspy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Spy.Win32.Teamspy virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Anomalous file deletion behavior detected (10+)
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Performs HTTP requests potentially not found in PCAP.
  • Starts servers listening on 127.0.0.1:0, 127.0.0.1:6039
  • Enumerates running processes
  • Expresses interest in specific running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • CAPE extracted potentially suspicious content
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Attempts to modify desktop wallpaper
  • Tries to unhook or modify Windows functions monitored by Cuckoo
  • Created a process from a suspicious location
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Collects information to fingerprint the system

How to determine Trojan-Spy.Win32.Teamspy?


File Info:

name: 1C04FC590DF35E61DAE4.mlw
path: /opt/CAPEv2/storage/binaries/7ae7d117f6c258b36effeacd08daab4e82e2c37f336144e5018cfd3f2f9aad88
crc32: 97554E25
md5: 1c04fc590df35e61dae4831883414fc9
sha1: 8b63abf1785ed8ba19b539e9bcf385fb4850abe7
sha256: 7ae7d117f6c258b36effeacd08daab4e82e2c37f336144e5018cfd3f2f9aad88
sha512: ece460efc493c508da7e34737d37ff6f91f8c8bfac411b15c190f82ae0776819c55210007622bc563370a314f0434f8cebbee0ce3a07ed562aaa61f829990b0d
ssdeep: 49152:axtqiCTuxU6afCNCXaV23UYHiLGaCCguewX/QQdeHg58gYDAy36:axtITOjafCoaOUYHiLGalgQPQRA58gY+
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T148C533BBA3A81C47E506C970C36BBB37DD9FFE0D70560A232FB01D9E2A397516250946
sha3_384: c2d428d16f19470dd047350d746f600e6180d644f076f2dd8ecb73b85c25a8dbedea6ffc5ec7a3831d48989258078c05
ep_bytes: 81ec8001000053555633db57895c2418
timestamp: 2009-12-05 22:50:41

Version Info:

0: [No Data]

Trojan-Spy.Win32.Teamspy also known as:

MicroWorld-eScanTrojan.GenericKD.38005828
FireEyeTrojan.GenericKD.38005828
McAfeeArtemis!1C04FC590DF3
CylanceUnsafe
SangforTrojan.Win32.Teamspy.gen
K7AntiVirusSpyware ( 0055e3db1 )
AlibabaTrojanSpy:Win32/Teamspy.085c9b44
K7GWSpyware ( 0055e3db1 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecTrojan.Gen.2
Elasticmalicious (moderate confidence)
ESET-NOD32Win32/Spy.Pavica.A
TrendMicro-HouseCallTROJ_GEN.R002H05C422
Paloaltogeneric.ml
KasperskyHEUR:Trojan-Spy.Win32.Teamspy.gen
BitDefenderTrojan.GenericKD.38005828
AvastWin32:Malware-gen
TencentWin32.Trojan-spy.Teamspy.Dxmy
Ad-AwareTrojan.GenericKD.38005828
EmsisoftTrojan.GenericKD.38005828 (B)
ZillyaTrojan.Teamspy.Win32.86
McAfee-GW-EditionBehavesLike.Win32.Dropper.vc
SentinelOneStatic AI – Suspicious PE
SophosMal/Generic-R + Troj/Teambot-K
APEXMalicious
GDataTrojan.GenericKD.38005828
WebrootTrojan.Dropper.Gen
AviraTR/Spy.Pavica.teemd
KingsoftWin32.Troj.Generic_a.a.(kcloud)
MicrosoftTrojan:Win32/Ymacco.AB7A
CynetMalicious (score: 99)
AhnLab-V3Trojan/Win32.ZBot.R164837
VBA32TrojanSpy.Teamspy
ALYacTrojan.GenericKD.38005828
MalwarebytesMalware.AI.2511923702
AVGWin32:Malware-gen

How to remove Trojan-Spy.Win32.Teamspy?

Trojan-Spy.Win32.Teamspy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment