Spy Trojan

TrojanSpy:Win32/Embed.A malicious file

Malware Removal

The TrojanSpy:Win32/Embed.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What TrojanSpy:Win32/Embed.A virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

How to determine TrojanSpy:Win32/Embed.A?


File Info:

name: 39E8B70D33CD48575FB4.mlw
path: /opt/CAPEv2/storage/binaries/11ff762b4b369cb80985c240610d826edc47c5f9b9a12f4840850b7d085cac79
crc32: F90E4A8C
md5: 39e8b70d33cd48575fb4d4c594356bbb
sha1: f45aec3b1634a4b98157acbf96ddf78ef0dd3547
sha256: 11ff762b4b369cb80985c240610d826edc47c5f9b9a12f4840850b7d085cac79
sha512: fa4c4f951b1dfcc6a59e455d49b2736f76079f8b8bc46644f08c7fc0209de88eec9c32c8ef3958d787bd77c061c9c442333d9b1627b2a6c8fc9ff13c5f62b018
ssdeep: 384:tyyBhKYqf5mOAYGhlhqFETjO09OFf4Uz+zDKi0690r0Jbf5Lqn3:vBhKYqAOAJqOAf4SMKBr0tBY
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
tlsh: T1DFF25C429A5900F6FD5B6275316BF3778B3B695C5E8128836BF5CCA7286320CE334746
sha3_384: b3f37dc47ba2c7592368abe104de97bddac611ed1eff759c2169299f376d7e52f2094d7446b915f5c8c263c1a8afbaac
ep_bytes: 558bec538b5d08568b750c578b7d1085
timestamp: 2009-07-23 06:37:32

Version Info:

0: [No Data]

TrojanSpy:Win32/Embed.A also known as:

AVGWin32:Trojan-gen
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.50041663
FireEyeGeneric.mg.39e8b70d33cd4857
SkyhighBehavesLike.Win32.Ransomware.nm
McAfeeBackDoor-FBCO!39E8B70D33CD
Cylanceunsafe
VIPRETrojan.GenericKD.50041663
SangforSuspicious.Win32.Save.ins
AlibabaTrojanSpy:Win32/Embed.c02a9abe
K7GWTrojan ( 0055e3dd1 )
K7AntiVirusTrojan ( 0055e3dd1 )
VirITTrojan.Win32.Agent2.CHWE
SymantecBackdoor.Layork
ESET-NOD32Win32/Agent.RMB
CynetMalicious (score: 100)
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Trojan.Agent-868379
KasperskyTrojan.Win32.Agent.cxhf
BitDefenderTrojan.GenericKD.50041663
NANO-AntivirusTrojan.Win32.Agent.crqxfa
RisingSpyware.Embed!8.14B54 (TFE:5:PzaRjE2OYqD)
EmsisoftTrojan.GenericKD.50041663 (B)
F-SecureHeuristic.HEUR/AGEN.1322862
DrWebTrojan.Siggen3.39671
ZillyaTrojan.Agent.Win32.128592
TrendMicroTROJ_ORSAM.BIX
SophosMal/Generic-S
JiangminTrojan/Agent.dgfj
WebrootW32.Orsam.Gen
VaristW32/Risk.LKBE-3332
AviraHEUR/AGEN.1322862
MAXmalware (ai score=100)
Antiy-AVLTrojan/Win32.Agent
KingsoftWin32.Trojan.Agent.cxhf
MicrosoftTrojanSpy:Win32/Embed.A
XcitiumMalware@#166ws6ic944q1
ArcabitTrojan.Generic.D2FB933F
ZoneAlarmTrojan.Win32.Agent.cxhf
GDataTrojan.GenericKD.50041663
GoogleDetected
AhnLab-V3Trojan/Win32.Agent.R25205
BitDefenderThetaGen:NN.ZedlaF.36802.cu4@aOEIg2j
ALYacTrojan.GenericKD.50041663
VBA32Trojan.Agent
PandaGeneric Malware
TrendMicro-HouseCallTROJ_ORSAM.BIX
TencentWin32.Trojan.Agent.Hjgl
YandexTrojan.GenAsa!HCbtX4Vsko8
IkarusTrojan-Dropper.Agent
MaxSecureTrojan.Malware.1401359.susgen
FortinetW32/Agent.CXHF!tr
DeepInstinctMALICIOUS
alibabacloudTrojan:Win/Agent.RMB

How to remove TrojanSpy:Win32/Embed.A?

TrojanSpy:Win32/Embed.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment