Spy Trojan

Trojan.WinSpy removal

Malware Removal

The Trojan.WinSpy is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.WinSpy virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Spoofs its process name and/or associated pathname to appear as a legitimate process

How to determine Trojan.WinSpy?


File Info:

name: 1F670C53A0378D317103.mlw
path: /opt/CAPEv2/storage/binaries/8500e519fa44b2a7b6afee610e0f862b88a883788059924217eaade421e30e3b
crc32: 0E2796F8
md5: 1f670c53a0378d317103e30339c68990
sha1: e50698a180f61e2ccde72715fdd39a9d0481f0dd
sha256: 8500e519fa44b2a7b6afee610e0f862b88a883788059924217eaade421e30e3b
sha512: f5e1c7dd2e204827eb9c48266668839ed78b7a2ddd58ad9d857c2032b3b0fb9134d4137069947850c4b4761b3fea03cc0cc822d977836ec4f1f5280918ef58e0
ssdeep: 12288:ZvFO0f/Lr9ZofL1TIGPkCf8/4ICO+MrnAMTT:ZvFO0f/tZixTZcCf8nCDMrndTT
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1C1F49D13FA9284F7C134257121A65375FA7ADB420E218AA3E7B8DE397C325606E37335
sha3_384: ac91c66b1c054cafb31a48132bc2c6dd7ef33e10aeb47629571f99c408f991205fb6e22381fd42834f34933e47940491
ep_bytes: 558bec6aff68808a480068cc2c460064
timestamp: 2014-05-03 16:08:07

Version Info:

FileVersion: 1.0.0.0
FileDescription: 易语言程序
ProductName: 易语言程序
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
Translation: 0x0804 0x04b0

Trojan.WinSpy also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.lfbe
Elasticmalicious (high confidence)
DrWebTrojan.WinSpy.1014
FireEyeGeneric.mg.1f670c53a0378d31
K7AntiVirusTrojan ( 005246d51 )
K7GWTrojan ( 005246d51 )
CrowdStrikewin/malicious_confidence_70% (W)
BitDefenderThetaGen:NN.ZexaF.34638.Tq1@aGK89gcb
VirITTrojan.Win32.X-WinSpy.A
CyrenW32/Agent.EW.gen!Eldorado
SymantecML.Attribute.HighConfidence
tehtrisGeneric.Malware
ESET-NOD32a variant of Win32/Packed.FlyStudio.AA potentially unwanted
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-1120542
KasperskyHEUR:Trojan.Win32.Generic
NANO-AntivirusTrojan.Win32.RiskGen.czvfuc
TencentMalware.Win32.Gencirc.10b7a2b7
ComodoWorm.Win32.Dropper.RA@1qraug
ZillyaTool.Inject.Win32.2905
TrendMicroHKTL_INJECT_GA2503F9_UVPM
McAfee-GW-EditionBehavesLike.Win32.Generic.bh
SophosGeneric PUA OF (PUA)
JiangminTrojan/Generic.bfidb
Webroot
AviraTR/Rogue.11306977
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
GDataWin32.Application.PUPStudio.A
AhnLab-V3Unwanted/Win.Agent.R465836
McAfeeGenericRXAA-FA!1F670C53A037
MAXmalware (ai score=99)
VBA32Trojan.WinSpy
TrendMicro-HouseCallHKTL_INJECT_GA2503F9_UVPM
RisingTrojan.Generic!8.C3 (CLOUD)
YandexTrojan.Agent!AbzvyDK8BjI
SentinelOneStatic AI – Malicious PE
MaxSecureDropper.Dinwod.frindll
FortinetW32/Agent.EMSG!tr
Cybereasonmalicious.180f61
PandaTrj/Genetic.gen

How to remove Trojan.WinSpy?

Trojan.WinSpy removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment