Trojan

Trojan:Win32/Spawnt.B (file analysis)

Malware Removal

The Trojan:Win32/Spawnt.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Spawnt.B virus can do?

  • Reads data out of its own binary image
  • Installs itself for autorun at Windows startup
  • Network activity detected but not expressed in API logs
  • Creates a copy of itself
  • Attempts to interact with an Alternate Data Stream (ADS)
  • Anomalous binary characteristics

How to determine Trojan:Win32/Spawnt.B?


File Info:

crc32: 13705A9A
md5: e8a83cfe86fb70e65a47f3c66594fc64
name: E8A83CFE86FB70E65A47F3C66594FC64.mlw
sha1: 11fc0761cb301efc77a5712e15aa7789a5c362c5
sha256: ddf23b101da238550b62347a748c85e816ab0749ee7447fc97045b6e1757024e
sha512: de6ec5c3b5339cbcb76de028cadf6d9733eb7c62274f4f8922ea09644bb22bc39515eb89b0053a14e89a2b1719382547a0d59015ad3b8b7852906cf4021bcd3a
ssdeep: 384:8gtCIKJbqX10XDrjbxq2hxs4M9gym5bfaAD3H0zYiwHCFn1el9TSs3G8UyWh:8gL1wX+h9ipfaADEzxQSs3EV
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: (c) Microsoft Corp.
InternalName: Microsoft Installer
FileVersion: 6.0.2900.5512
CompanyName: (c) Microsoft Corp.
LegalTrademarks: (c) Microsoft Corp.
Comments: Microsoft Installer
ProductName: Microsoft Installer
ProductVersion: 6.0.2900.5512
FileDescription: Microsoft Installer
OriginalFilename: Microsoft Installer

Trojan:Win32/Spawnt.B also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Trojan.ProcessHijack.bu0@aCOxm@n
FireEyeGeneric.mg.e8a83cfe86fb70e6
ALYacGen:Trojan.ProcessHijack.bu0@aCOxm@n
CylanceUnsafe
VIPRETrojan.Win32.Spawnt.b (v) (not malicious)
AegisLabTrojan.Win32.Scar.mAGh
SangforMalware
K7AntiVirusTrojan ( 0040610c1 )
BitDefenderGen:Trojan.ProcessHijack.bu0@aCOxm@n
K7GWTrojan ( 0040610c1 )
Cybereasonmalicious.e86fb7
CyrenW32/Scar.C.gen!Eldorado
SymantecTrojan.Gen
TotalDefenseWin32/Tnega.NQTYQXB
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Scar-8449
KasperskyTrojan.Win32.Scar.vcb
NANO-AntivirusTrojan.Win32.Scar.cqhnxu
ViRobotTrojan.Win32.A.Scar.56832.D
TencentVirus.Win32.Scar.vcb
Ad-AwareGen:Trojan.ProcessHijack.bu0@aCOxm@n
SophosML/PE-A + Mal/Scar-T
ComodoTrojWare.Win32.Scar.CN@27rtzk
F-SecureMalware.W32/Prepender.Gen
DrWebTrojan.Siggen3.37641
ZillyaTrojan.Scar.Win32.82571
TrendMicroTROJ_SPAWNT.SMIA
McAfee-GW-EditionBackDoor-ENS.a
EmsisoftGen:Trojan.ProcessHijack.bu0@aCOxm@n (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Scar.mvy
WebrootW32.Trojan.Gen
AviraW32/Prepender.Gen
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=82)
Antiy-AVLTrojan/Win32.Scar
MicrosoftTrojan:Win32/Spawnt.B
ArcabitTrojan.ProcessHijack.E9A4EF
ZoneAlarmTrojan.Win32.Scar.vcb
GDataGen:Trojan.ProcessHijack.bu0@aCOxm@n
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Scar.R76008
McAfeeBackDoor-ENS.a
TACHYONTrojan/W32.Scar.26112.BP
VBA32Malware-Cryptor.Inject.gen
MalwarebytesMalware.AI.3063263691
PandaGeneric Malware
ZonerVirus.Win32.31759
ESET-NOD32a variant of Win32/AutoRun.NAS
TrendMicro-HouseCallTROJ_SPAWNT.SMIA
RisingVirus.Autorun!8.1A (CLOUD)
YandexTrojan.GenAsa!kzXK/2T7Gs4
IkarusTrojan.Win32.Scar
FortinetW32/Scar.VCB!tr
BitDefenderThetaAI:Packer.C991481E1E
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360Win32/Trojan.31e

How to remove Trojan:Win32/Spawnt.B?

Trojan:Win32/Spawnt.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment