Spy

What is “Win32/Spy.Kronosbot.A”?

Malware Removal

The Win32/Spy.Kronosbot.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Win32/Spy.Kronosbot.A virus can do?

  • Reads data out of its own binary image
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Win32/Spy.Kronosbot.A?


File Info:

crc32: 8458758C
md5: 41b93173a8b5583daaf090438fb05004
name: chapo777.exe
sha1: a0db1a8f024e95fbc5c4c4930a4f6f905bbcab24
sha256: b87cfba8a4f2329b0b372326a7f169f5896459a6bdae0ad8857b576129722204
sha512: a770ed85694301daa0b8f9c46dbc25207411b888d6d1a358a816590f0c3bbfad05bd438545554e6c3ce391be6b640acbf69819f38aab0dd235caf2d17962be57
ssdeep: 12288:kNi7Ynlwt1fL+RcGNh25nxXLZmW2PjlyjkvGha:kNk+lwrEcEc5nRLZj2PjlyTa
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Win32/Spy.Kronosbot.A also known as:

CAT-QuickHealTrojan.Wacatac
McAfeeRDN/Generic PUP.z
CylanceUnsafe
ZillyaTrojan.Kronosbot.Win32.20
SangforMalware
K7AntiVirusTrojan ( 00559dab1 )
BitDefenderGen:Variant.Graftor.659281
K7GWTrojan ( 00559dab1 )
CrowdStrikewin/malicious_confidence_60% (W)
TrendMicroTrojan.Win32.OCCAMY.USASHJP19
CyrenW32/Trojan.KZIV-5080
SymantecTrojan.Gen.MBT
ESET-NOD32Win32/Spy.Kronosbot.A
TrendMicro-HouseCallTrojan.Win32.OCCAMY.USASHJP19
AvastWin32:Malware-gen
GDataGen:Variant.Graftor.659281
KasperskyHEUR:Trojan-Downloader.Win32.Agent.gen
AlibabaTrojan:Win32/Injector.0b7e7015
NANO-AntivirusVirus.Win32.Gen-Crypt.ccnc
AegisLabTrojan.Win32.Agent.a!c
APEXMalicious
SophosMal/Generic-S
ComodoApplicUnwnt@#2ktgbwjkyosr0
F-SecureTrojan.TR/AD.NsisInject.ckfge
DrWebTrojan.PWS.Banker1.35811
VIPRETrojan.Win32.Generic!BT
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.ObfusRansom.hc
EmsisoftGen:Variant.Graftor.659281 (B)
F-ProtW32/Injector.INY
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1045148
MAXmalware (ai score=87)
Antiy-AVLGrayWare/Win32.Generic
ArcabitTrojan.Graftor.DA0F51
AhnLab-V3Malware/Win32.RL_Generic.R295216
ZoneAlarmHEUR:Trojan-Downloader.Win32.Agent.gen
MicrosoftTrojan:Win32/Tiggre!rfn
VBA32TrojanDownloader.Agent
MalwarebytesSpyware.LokiBot
PandaTrj/CI.A
ZonerTrojan.Win32.82810
YandexTrojan.Injector!BFfRIzZHZCM
IkarusTrojan.Win32.Injector
MaxSecureTrojan.Malware.74635160.susgen
FortinetW32/Injector.EIGK!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360HEUR/QVM42.3.BE17.Malware.Gen

How to remove Win32/Spy.Kronosbot.A?

Win32/Spy.Kronosbot.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment