Spy

Win32/Spy.Agent.PTM (file analysis)

Malware Removal

The Win32/Spy.Agent.PTM is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Agent.PTM virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Win32/Spy.Agent.PTM?


File Info:

crc32: 8474ADB8
md5: ad1bf40823d0a5a80710772173ee3e23
name: pak444.exe
sha1: 22a55dc00d77e8f0d92e7299cd4781ff2154d1f8
sha256: a1ae27c556ffb43e4a6826db470a0f43b09055235e959c3bb144dff0ab7fca51
sha512: ebbb9d6316b2d36289b1a744bbb5ee85dc6e1c485c971eb0ae59ebea2d78efd9c408035d3b71f53c4960869685b59007ce7bc35fc7f5cb50f8f2f322914d251a
ssdeep: 24576:lQbuDLxqwhLb1XqwsklS7FWhPNW8C8h8M:QIxqwtJXqqA5gJJ8
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9Rickard Johansson.
InternalName: ManageabilityDescibed
FileVersion: 2.9.9.384
CompanyName: Rickard Johansson
FileDescription: Weblog Compilers
LegalTrademarks: Copyright xa9Rickard Johansson.
Comments: Weblog Compilers
ProductName: ManageabilityDescibed
ProductVersion: 2.9.9.384
PrivateBuild: 2.9.9.384
OriginalFilename: ManageabilityDescibed
Translation: 0x0409 0x04b0

Win32/Spy.Agent.PTM also known as:

MicroWorld-eScanTrojan.GenericKD.41836636
FireEyeGeneric.mg.ad1bf40823d0a5a8
CAT-QuickHealTrojanpws.Predator
McAfeeRDN/Generic PWS.vo
MalwarebytesSpyware.PredatorTheThief
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Generic.4!c
SangforMalware
K7AntiVirusSpyware ( 005520611 )
BitDefenderTrojan.GenericKD.41836636
K7GWSpyware ( 005520611 )
Cybereasonmalicious.00d77e
TrendMicroMal_HPGen-37b
BitDefenderThetaGen:NN.ZexaF.33550.1y0@aOkH!!gi
F-ProtW32/Kryptik.ABE.gen!Eldorado
SymantecTrojan.Gen.2
ESET-NOD32Win32/Spy.Agent.PTM
TrendMicro-HouseCallMal_HPGen-37b
Paloaltogeneric.ml
ClamAVWin.Trojan.Agent-7188594-0
GDataTrojan.GenericKD.41836636
KasperskyTrojan-PSW.Win32.Predator.cnx
AlibabaTrojanPSW:Win32/Predator.95f94493
NANO-AntivirusTrojan.Win32.Predator.gbjqvw
ViRobotTrojan.Win32.Z.Predator.868352
AvastWin32:Malware-gen
RisingSpyware.Agent!8.C6 (TFE:5:ZZ88R1rnd8B)
Ad-AwareTrojan.GenericKD.41836636
SophosMal/Generic-S
ComodoMalware@#3ulltpqea9e1d
F-SecureTrojan.TR/Spy.Agent.zstoe
DrWebTrojan.PWS.Siggen2.32551
ZillyaTrojan.Agent.Win32.1157885
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Dropper.cc
SentinelOneDFI – Malicious PE
EmsisoftTrojan.GenericKD.41836636 (B)
APEXMalicious
CyrenW32/Kryptik.ABE.gen!Eldorado
JiangminTrojan.PSW.Predator.sv
WebrootW32.Malware.Gen
AviraTR/Spy.Agent.zstoe
Antiy-AVLTrojan[PSW]/Win32.Predator
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D27E605C
AhnLab-V3Trojan/Win32.MalPacked.R287551
ZoneAlarmTrojan-PSW.Win32.Predator.cnx
MicrosoftTrojan:Win32/Occamy.C
TACHYONTrojan/W32.Agent.868352.KL
Acronissuspicious
VBA32BScope.TrojanPSW.Predator
ALYacTrojan.PSW.Predator
MAXmalware (ai score=83)
CylanceUnsafe
IkarusPacked.Win32.Crypt
FortinetW32/Predator.CNX!tr.pws
AVGWin32:Malware-gen
PandaTrj/CI.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360HEUR/QVM10.2.327B.Malware.Gen

How to remove Win32/Spy.Agent.PTM?

Win32/Spy.Agent.PTM removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment