Spy Trojan

Should I remove “Trojan.Spy.Wsnpoem.LZ (B)”?

Malware Removal

The Trojan.Spy.Wsnpoem.LZ (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Spy.Wsnpoem.LZ (B) virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • At least one process apparently crashed during execution
  • Creates RWX memory
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Trojan.Spy.Wsnpoem.LZ (B)?


File Info:

name: 3F96040A7DB012A1EA6E.mlw
path: /opt/CAPEv2/storage/binaries/43bd51e3f5fc941604b4a813822e793978549e7ceda404e5b64a571a3a68d975
crc32: 1D89A794
md5: 3f96040a7db012a1ea6e4add9b461f49
sha1: 1c11bdae0c47f5f668112dd4960d2f9a10c3b9ab
sha256: 43bd51e3f5fc941604b4a813822e793978549e7ceda404e5b64a571a3a68d975
sha512: e449a177e9f5456f4e04f1657447b328320ff43c12a7fd399e30f86c3fc310a362b896c03b86d2c8bb16320eb505fd0c1266b59884a32ed8671d211b7289bd1c
ssdeep: 6144:DYoFcTlB890FY1QgO3EsaUwJzXXkHOxsPLI02v1V3sQhKU1Jc+CIZ5Fe:8oFCB8aY1TaqnVysv1dvCILk
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17B6423115D3CCD4AF46F7EBF8AB3E49D0D5E2C29C60BE144460A93961E8B3B581F2463
sha3_384: ab52644a2cdd29217becf08ce2481c4307124ab729b49b6290bbe714e41efafd3d765733a34a6e747776199f0af51bdc
ep_bytes: e801000000c331f6ba000000006a00ff
timestamp: 2007-10-12 13:47:21

Version Info:

0: [No Data]

Trojan.Spy.Wsnpoem.LZ (B) also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
FireEyeGeneric.mg.3f96040a7db012a1
ALYacTrojan.Spy.Wsnpoem.LZ
CylanceUnsafe
VIPRETrojan-Spy.Win32.Zbot.gen (v)
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0054c19a1 )
AlibabaTrojanSpy:Win32/BScope.a4d1f7a2
K7GWSpyware ( 0054c19a1 )
Cybereasonmalicious.a7db01
VirITTrojan.Win32.ZBot.C
CyrenW32/Zbot.M.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32Win32/Spy.Zbot.JF
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Zbot-7055
KasperskyTrojan-Spy.Win32.Zbot.gen
BitDefenderTrojan.Spy.Wsnpoem.LZ
NANO-AntivirusTrojan.Win32.Zbot.dddeuz
MicroWorld-eScanTrojan.Spy.Wsnpoem.LZ
AvastWin32:Trojan-gen
TencentWin32.Trojan-spy.Zbot.Lnyk
Ad-AwareTrojan.Spy.Wsnpoem.LZ
SophosML/PE-A + Mal/Zbot-I
ComodoTrojWare.Win32.TrojanSpy.Zbot.~ACB@5502v
DrWebTrojan.PWS.Panda.114
ZillyaTrojan.Zbot.Win32.2918
TrendMicroTSPY_ZBOT.SMS
McAfee-GW-EditionBehavesLike.Win32.ZBot.fc
EmsisoftTrojan.Spy.Wsnpoem.LZ (B)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Spy.Zbot.DT
JiangminTrojanSpy.Zbot.fqu
WebrootW32.Trojan.Backdoor-Zbot
AviraTR/Dropper.Gen
MAXmalware (ai score=100)
Antiy-AVLTrojan[Spy]/Win32.Zbot
ArcabitTrojan.Spy.Wsnpoem.LZ
ViRobotTrojan.Win32.Zbot.62976.G
ZoneAlarmTrojan-Spy.Win32.Zbot.gen
MicrosoftPWS:Win32/Zbot.I
AhnLab-V3Spyware/Win32.Zbot.R1268
McAfeePWS-Zbot.gen.dl
VBA32BScope.Malware-Cryptor.Win32.Vals.22
MalwarebytesGeneric.Malware/Suspicious
TrendMicro-HouseCallTSPY_ZBOT.SMS
RisingTrojan.Spy.Win32.Agent.epp (CLOUD)
YandexTrojanSpy.Zbot!8MmpwUaqgLE
IkarusTrojan-Spy.Win32.Zbot
MaxSecureTrojan.Malware.7175482.susgen
FortinetW32/Zbot.gen!tr
BitDefenderThetaAI:Packer.65BBDA221E
AVGWin32:Trojan-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Trojan.Spy.Wsnpoem.LZ (B)?

Trojan.Spy.Wsnpoem.LZ (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment