Spy Trojan

About “TrojanSpy.Ident” infection

Malware Removal

The TrojanSpy.Ident is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy.Ident virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • Behavioural detection: Injection (Process Hollowing)
  • Executed a process and injected code into it, probably while unpacking
  • Behavioural detection: Injection (inter-process)
  • Created a process from a suspicious location
  • Installs itself for autorun at Windows startup
  • CAPE detected the NetWire malware family
  • Anomalous binary characteristics

How to determine TrojanSpy.Ident?


File Info:

name: 47142E1CB20B5BC251BF.mlw
path: /opt/CAPEv2/storage/binaries/38370ee8da8c7b1fa1dcb52cbe568f360a1dea9f71358058b5a1ea49830b5996
crc32: 710EDDD7
md5: 47142e1cb20b5bc251bf4ae716b207c0
sha1: 7bb779d071056c79e6259f806e82bb1ba3613a93
sha256: 38370ee8da8c7b1fa1dcb52cbe568f360a1dea9f71358058b5a1ea49830b5996
sha512: 40a282d85118c0bac0afc2fe937f3df27edff44d9043c1083f8f09814bcedb8eaf9f86b358a2906fcfc50370cb385a430c0321d85f7bfd585113c63b5a40dbc8
ssdeep: 24576:XAHnh+eWsN3skA4RV1Hom2KXMmHaU8enAYm5:Kh+ZkldoPK8YaUY
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18C259C0273D1C036FFABA2739B6AF24556BC79254123852F13981DB9BD701B2263E763
sha3_384: 0722e602addac76d9c8b311259116d4c46e4560b49d04ba2a10da4bc81249833ee4a1692d1a89b6d89eb9f8bcf2554a6
ep_bytes: e8c8d00000e97ffeffffcccccccccccc
timestamp: 2019-08-26 14:19:37

Version Info:

FileDescription: Adobe Reader
OriginalFilename: AcroRd32.exe
CompanyName: Adobe Systems Incorporated
FileVersion: ...
LegalCopyright: Copyright 1984-2012 Adobe Systems Incorporated and its licensors. All rights reserved.
ProductName: Adobe Reader
ProductVersion: ...
Translation: 0x0409 0x04b0

TrojanSpy.Ident also known as:

BkavW32.AIDetect.malware1
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.32330837
FireEyeGeneric.mg.47142e1cb20b5bc2
ALYacTrojan.GenericKD.32330837
CylanceUnsafe
K7AntiVirusTrojan ( 700000111 )
AlibabaTrojan:Script/AutoitInject.1ca195e6
K7GWTrojan ( 700000111 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Generic.D1ED5455
BitDefenderThetaAI:Packer.81874BE317
CyrenW32/AutoIt.KQ.gen!Eldorado
SymantecInfostealer
ESET-NOD32a variant of Win32/Injector.Autoit.EGA
TrendMicro-HouseCallBackdoor.AutoIt.BLADABINDI.SMA.hp
Paloaltogeneric.ml
ClamAVWin.Malware.Autoit-7139548-0
KasperskyHEUR:Trojan.Script.Generic
BitDefenderTrojan.GenericKD.32330837
AvastWin32:Trojan-gen
TencentWin32.Trojan.Generic.Pavk
Ad-AwareTrojan.GenericKD.32330837
EmsisoftTrojan.GenericKD.32330837 (B)
TrendMicroBackdoor.AutoIt.BLADABINDI.SMA.hp
McAfee-GW-EditionBehavesLike.Win32.TrojanAitInject.fh
SophosMal/Generic-S
APEXMalicious
AviraDR/AutoIt.Gen8
MicrosoftTrojan:Win32/AutoitInject.BH!MTB
GDataTrojan.GenericKD.32330837
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Autoinj02.Exp
McAfeeArtemis!47142E1CB20B
MAXmalware (ai score=81)
VBA32TrojanSpy.Ident
MalwarebytesTrojan.MalPack.AutoIt
RisingTrojan.Obfus/Autoit!1.BB81 (CLASSIC)
IkarusTrojan-Spy.Azorult
FortinetAutoIt/Injector.EFY!tr
AVGWin32:Trojan-gen
Cybereasonmalicious.cb20b5
PandaTrj/Genetic.gen
MaxSecureTrojan.Malware.74529901.susgen

How to remove TrojanSpy.Ident?

TrojanSpy.Ident removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment