Spy Trojan

Trojan.Spy.Wsnpoem.EL removal guide

Malware Removal

The Trojan.Spy.Wsnpoem.EL is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Wsnpoem.EL virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan.Spy.Wsnpoem.EL?


File Info:

name: A0F2F883FBA5D03B313C.mlw
path: /opt/CAPEv2/storage/binaries/b86362f1b6e8152739d1abfaa7df78e354a1f339a0d8146d3e3580cadfea7c95
crc32: 64DC31AB
md5: a0f2f883fba5d03b313c8c877c9e3a0c
sha1: 16cf170b54e58f9cd0f5e9852e8a2deb97c47343
sha256: b86362f1b6e8152739d1abfaa7df78e354a1f339a0d8146d3e3580cadfea7c95
sha512: 3fc30a9687287c64ec94b2395c68f688adccd46729cd96be8aa7f9680e89509058b6db624aa4713b5ab22bf6b595df04253be2aa2a7afdf33abd7e5d945bfe5b
ssdeep: 3072:MQTwa8OPxtTJRhWBQTwa8OPxtTJRhWS0sG:MQz7tTJRhMQz7tTJRh0sG
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T119E39D2671D1D8F2CA9200312698BB7767BFF8373D65ACC3D3144E8A5661CD2A12F64B
sha3_384: 78e59d1af3b5822b55e1e305c5821e22e311b32c47ce2bdd73ce2b9cbb5b1af5d6b7763eff42224a0859397e684a52f7
ep_bytes: ff15800d4100830d540b4100ff6869a3
timestamp: 2001-10-06 20:52:51

Version Info:

0: [No Data]

Trojan.Spy.Wsnpoem.EL also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Zbot.kZAq
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.a0f2f883fba5d03b
ALYacTrojan.Spy.Wsnpoem.EL
CylanceUnsafe
ZillyaTrojan.Zbot.Win32.5363
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
AlibabaTrojanPSW:Win32/Generic.af6bfe66
K7GWSpyware ( 000bad281 )
K7AntiVirusSpyware ( 000bad281 )
VirITTrojan.Win32.Panda.EF
CyrenW32/Injector.A.gen!Eldorado
SymantecTrojan.Zbot
ESET-NOD32a variant of Win32/Spy.Zbot.JF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-3207
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Spy.Wsnpoem.EL
NANO-AntivirusTrojan.Win32.Panda.cvjhuv
MicroWorld-eScanTrojan.Spy.Wsnpoem.EL
AvastSf:Zbot-JD [Trj]
TencentWin32.Trojan.Spy.Lndy
Ad-AwareTrojan.Spy.Wsnpoem.EL
EmsisoftTrojan.Spy.Wsnpoem.EL (B)
ComodoTrojWare.Win32.Spy.Zbot.ABA@1pe611
DrWebTrojan.PWS.Panda.109
VIPRETrojan-Spy.Win32.Zbot.gen (fs)
McAfee-GW-EditionBehavesLike.Win32.Generic.cm
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataTrojan.Spy.Wsnpoem.EL
JiangminTrojanSpy.Zbot.xlu
WebrootW32.InfoStealer.Zeus
AviraTR/Spy.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Zbot
ArcabitTrojan.Spy.Wsnpoem.EL
ZoneAlarmHEUR:Trojan.Win32.Generic
MicrosoftPWS:Win32/Zbot.gen!B
Acronissuspicious
McAfeeGenericRXJG-JE!A0F2F883FBA5
TACHYONTrojan-Spy/W32.ZBot.153989
VBA32BScope.TrojanPSW.Panda
MalwarebytesMalware.Heuristic.1003
RisingSpyware.Zbot!8.16B (CLOUD)
YandexTrojan.NTos.Gen.2
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.7164915.susgen
FortinetW32/Zbot.UWE!tr
BitDefenderThetaGen:NN.ZexaF.34212.juW@aav7B@j
AVGSf:Zbot-JD [Trj]
Cybereasonmalicious.3fba5d
PandaTrj/Sinowal.VXU

How to remove Trojan.Spy.Wsnpoem.EL?

Trojan.Spy.Wsnpoem.EL removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment