Spy Trojan

What is “Trojan.Spy.Wsnpoem.AD (B)”?

Malware Removal

The Trojan.Spy.Wsnpoem.AD (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Wsnpoem.AD (B) virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Spy.Wsnpoem.AD (B)?


File Info:

name: 54C89E4D22D6707ABEA6.mlw
path: /opt/CAPEv2/storage/binaries/b86e8fce242f29b633c028ac869f555dc7941401028af4df0c54cf94d7f13eac
crc32: EF66C6F8
md5: 54c89e4d22d6707abea64d49a7f3f60d
sha1: c34a2941fa0c6023bf0d923178ebeae8f66ffa43
sha256: b86e8fce242f29b633c028ac869f555dc7941401028af4df0c54cf94d7f13eac
sha512: 05261b2164372415b8de7023531b2dec0ca7a26b5bd6aa52093ac2ac96a137d619538807b18938ec7c79f6806a1209c1c669f1e00830532a4b03ef11fa3f527c
ssdeep: 768:JY6IvuD0Qfq07QqvdFAIUohZfPbMtP4EmpcHnFsBEpXDwFQS3V4aLUKZZJq9XPYZ:JYlvumROFFhZfDKgcHnWBEpzw+SV4kyO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T137238DA67991CCF2DDA0043127D6BB7A67BFF83319255C87C3100DD02852DE2A21BB9B
sha3_384: 7a4769c00da585bd65104e3b971a20680422128a75041777ed59b32f02cdc4ab3b280cf58c28ddad3489e9a7beff6ecd
ep_bytes: 87df25c000000033c783c07133ff83c0
timestamp: 2003-09-02 07:48:56

Version Info:

0: [No Data]

Trojan.Spy.Wsnpoem.AD (B) also known as:

BkavW32.AIDetect.malware1
MicroWorld-eScanTrojan.Spy.Wsnpoem.AD
FireEyeGeneric.mg.54c89e4d22d6707a
ALYacTrojan.Spy.Wsnpoem.AD
CylanceUnsafe
ZillyaTrojan.Agent.Win32.2825710
BitDefenderTrojan.Spy.Wsnpoem.AD
CrowdStrikewin/malicious_confidence_90% (D)
CyrenW32/BankPack.A.gen!Eldorado
SymantecTrojan.Zbot!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Agent.NES
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Malware.Zbot-9951823-0
KasperskyTrojan-Spy.Win32.Zbot.aez
NANO-AntivirusTrojan.Win32.Zbot.jpuden
RisingSpyware.Agent!8.C6 (TFE:1:Ox057UaR9jM)
Ad-AwareTrojan.Spy.Wsnpoem.AD
SophosML/PE-A + Mal/Zbot-A
ComodoTrojWare.Win32.Spy.Zbot.ACA@1rkc1t
F-SecureTrojan.TR/Crypt.XPACK.Gen
DrWebTrojan.Proxy.2486
VIPRETrojan.Spy.Wsnpoem.AD
TrendMicroMal_Pai-1
McAfee-GW-EditionBehavesLike.Win32.Duptwux.ph
Trapminemalicious.high.ml.score
EmsisoftTrojan.Spy.Wsnpoem.AD (B)
IkarusTrojan-Spy.Win32.Zbot
JiangminTrojanSpy.Zbot.ftks
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=82)
Antiy-AVLTrojan[Spy]/Win32.Zbot
MicrosoftPWS:Win32/Bankrypt.gen
ZoneAlarmTrojan-Spy.Win32.Zbot.aez
GDataTrojan.Spy.Wsnpoem.AD
GoogleDetected
AhnLab-V3Win32/IRCBot3.worm.Gen
McAfeeGenericRXJG-JE!54C89E4D22D6
MalwarebytesMalware.AI.753106299
PandaMalicious Packer
ZonerProbably Heur.ExeHeaderL
TrendMicro-HouseCallMal_Pai-1
YandexTrojan.GenAsa!cU4Iaqxuoyc
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NES!tr.spy
BitDefenderThetaAI:Packer.2CCD74A11D
AVGSf:Zbot-JD [Trj]
Cybereasonmalicious.d22d67
AvastSf:Zbot-JD [Trj]

How to remove Trojan.Spy.Wsnpoem.AD (B)?

Trojan.Spy.Wsnpoem.AD (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment