Spy Trojan

Trojan.Spy.Wsnpoem.AD removal

Malware Removal

The Trojan.Spy.Wsnpoem.AD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Wsnpoem.AD virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine Trojan.Spy.Wsnpoem.AD?


File Info:

name: 224F231A1B695F966868.mlw
path: /opt/CAPEv2/storage/binaries/897711bcd7fc05cd683f0c8ac4274aa75fdc90453b1c9871acda4223c40a2678
crc32: E9E85F72
md5: 224f231a1b695f966868931b943365d4
sha1: 74de66d0bccb1509048c77071bb7ac58e92616d7
sha256: 897711bcd7fc05cd683f0c8ac4274aa75fdc90453b1c9871acda4223c40a2678
sha512: cfefdb72caaf351d107514a2562862d2f430334a60c6027618fdf29af3241446b14b42347cd802cae7909ac1eef3c525b5f034c3c5204ea93c14a5fb4547f599
ssdeep: 768:OLY6IvuD0Qfq07NZhZcS45BeZfProTPKmrpnY5pzK91DtJFQx3V4aLUKZZlquHgy:IYlvumwZISAeZfDI1nY5deFtJ+ZV4kG0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11A238D62B9D1CDE2DD90443127DABB7A27BFF83329295C87C314099024A1DE2E51B79B
sha3_384: 9bc00d26d6f151159089e30bc6b79c10edb62bb169502ad8ee5bfdeb7bb61b03fc15b06ba9e5cc2c9a768328b237bb0d
ep_bytes: 83e17987df33cf4183e97933ff81c1e5
timestamp: 2007-01-11 18:30:39

Version Info:

0: [No Data]

Trojan.Spy.Wsnpoem.AD also known as:

BkavW32.AIDetect.malware1
DrWebTrojan.Proxy.2486
MicroWorld-eScanTrojan.Spy.Wsnpoem.AD
FireEyeGeneric.mg.224f231a1b695f96
ALYacTrojan.Spy.Wsnpoem.AD
CylanceUnsafe
VIPRETrojan.Spy.Wsnpoem.AD
K7AntiVirusTrojan ( 0051918e1 )
K7GWTrojan ( 0051918e1 )
Cybereasonmalicious.a1b695
BitDefenderThetaAI:Packer.2CCD74A11D
CyrenW32/Zbot.ABQ.gen!Eldorado
SymantecTrojan.Zbot!gen
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Spy.Agent.NES
APEXMalicious
TrendMicro-HouseCallMal_Pai-1
ClamAVWin.Malware.Zbot-9951823-0
KasperskyTrojan-Spy.Win32.Zbot.aez
BitDefenderTrojan.Spy.Wsnpoem.AD
NANO-AntivirusTrojan.Win32.Zbot.jqmwpk
AvastSf:Zbot-JD [Trj]
Ad-AwareTrojan.Spy.Wsnpoem.AD
SophosML/PE-A + Troj/Zbot-CE
ComodoTrojWare.Win32.Spy.Zbot.ACA@1rkc1t
ZillyaTrojan.Zbot.Win32.216764
TrendMicroMal_Pai-1
McAfee-GW-EditionBehavesLike.Win32.Duptwux.ph
Trapminemalicious.high.ml.score
EmsisoftTrojan.Spy.Wsnpoem.AD (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanSpy.Zbot.ftlc
GoogleDetected
AviraTR/Crypt.XPACK.Gen
MAXmalware (ai score=81)
Antiy-AVLTrojan/Generic.ASMalwS.31
MicrosoftPWS:Win32/Bankrypt.gen
GDataTrojan.Spy.Wsnpoem.AD
CynetMalicious (score: 100)
AhnLab-V3Win32/IRCBot3.worm.Gen
McAfeeGenericRXJG-JE!224F231A1B69
MalwarebytesMalware.AI.753106299
ZonerProbably Heur.ExeHeaderL
RisingStealer.Zbot!8.109D7 (TFE:1:XR5Uzak4SMT)
YandexTrojan.GenAsa!h2s90ViloDE
IkarusTrojan-Spy.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Agent.NES!tr.spy
AVGSf:Zbot-JD [Trj]
PandaMalicious Packer
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Spy.Wsnpoem.AD?

Trojan.Spy.Wsnpoem.AD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment