Trojan

Trojan:Win32/Spaeshill information

Malware Removal

The Trojan:Win32/Spaeshill is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Spaeshill virus can do?

  • Sample contains Overlay data
  • Unconventionial language used in binary resources: Arabic (Qatar)
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics

How to determine Trojan:Win32/Spaeshill?


File Info:

name: 42DDB6DCEEF4FF5A8CE2.mlw
path: /opt/CAPEv2/storage/binaries/ba63aab1fd337b78df8da941c036e4c15ac1c638df1327b84380e4eb0a4dbd3b
crc32: 694922B4
md5: 42ddb6dceef4ff5a8ce200f71c97c68f
sha1: c5b632a4fa167a83f70c55c3c57c52b89af92d01
sha256: ba63aab1fd337b78df8da941c036e4c15ac1c638df1327b84380e4eb0a4dbd3b
sha512: f2357e4b78d11671bbc8da109c513727360ff1d20d8b3ebe1340cf8a5115c6ab4477e21654cb8e0ea50db6eabd865a63e4a7689cd37fc39c8ff9ccaebf113228
ssdeep: 1536:F5rnVmg+tFj/EcN57G7d3Dvzj4LKD2GsfvH3NdYA8vUi5L0jBXV0:F5rVmg+tWW7Gx3HkLUI9dSUi5LqBl0
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10AA37B127A90C0B2C0562D704856DBB19B7EB9321F79D587BB941B3EDF312C19A3728B
sha3_384: 0d7210f540ea38f751a469502336ad0b2ac135812341daaf3290af1ebfb457fdb35f9ba85e8f7f5180e2760a68b0e44b
ep_bytes: e87c6d0000e979feffffcccccccccccc
timestamp: 2015-08-13 11:41:33

Version Info:

CompanyName: Microsoft © Windows
FileDescription: Spooler Application
FileVersion: 16, 95, 2156, 456
InternalName: spooler
LegalCopyright: Microsoft Windows © 2013
OriginalFilename: splsrv.exe
ProductName: Spooler Application
ProductVersion: 16, 195, 2356, 476
Translation: 0x4009 0x04b0

Trojan:Win32/Spaeshill also known as:

BkavW32.AIDetectMalware
LionicTrojan.Multi.Generic.mBLK
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader15.50842
MicroWorld-eScanTrojan.Agent.BLXP
McAfeeGenericRXVQ-TG!42DDB6DCEEF4
MalwarebytesMalware.AI.2938904392
SangforTrojan.Win32.Small.V14a
K7AntiVirusTrojan ( 005a3ac21 )
AlibabaTrojan:Win32/Johnnie.e32aa76d
K7GWTrojan ( 004e07eb1 )
Cybereasonmalicious.ceef4f
BitDefenderThetaAI:Packer.0F635A6420
VirITTrojan.Win32.DownLoader15.CXFM
CyrenW32/Agent.FSI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Small.NPF
APEXMalicious
ClamAVWin.Trojan.Agent-6827379-0
KasperskyHEUR:Trojan.Win32.Johnnie.gen
BitDefenderTrojan.Agent.BLXP
AvastWin32:Numeriq-AC [Trj]
TencentTrojan-Dropper.Win32.Dapato.hc
EmsisoftTrojan.Agent.BLXP (B)
F-SecureHeuristic.HEUR/AGEN.1303379
VIPRETrojan.Agent.BLXP
TrendMicroTROJ_GEN.R002C0DEJ23
McAfee-GW-EditionBehavesLike.Win32.KuaiZip.nh
FireEyeGeneric.mg.42ddb6dceef4ff5a
SophosMal/Generic-R
GDataTrojan.Agent.BLXP
JiangminTrojan/Agentb.bqj
AviraHEUR/AGEN.1303379
MAXmalware (ai score=84)
ArcabitTrojan.Agent.BLXP
ZoneAlarmHEUR:Trojan.Win32.Johnnie.gen
MicrosoftTrojan:Win32/Spaeshill
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Spaeshill.C5395408
VBA32Trojan.Downloader
ALYacTrojan.Agent.BLXP
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0DEJ23
RisingTrojan.Small!8.A9 (TFE:5:cJKroxrM0DO)
YandexTrojan.GenAsa!LCR9Zd2YZSU
IkarusTrojan.Win32.Small
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Small.NPF!tr
AVGWin32:Numeriq-AC [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan:Win32/Spaeshill?

Trojan:Win32/Spaeshill removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment