Worm

Should I remove “Worm:Win32/Cambot.A”?

Malware Removal

The Worm:Win32/Cambot.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Cambot.A virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

www.emmek.altervista.org

How to determine Worm:Win32/Cambot.A?


File Info:

crc32: CCDD2177
md5: 8f2d02f5e023d1bf5550724556ad88db
name: 8F2D02F5E023D1BF5550724556AD88DB.mlw
sha1: 0e57c82c76f684e95fb2b748b0cf52981ce021c2
sha256: 80f8410a8f0042edad98dc1636d6cbd6c989d5159454d86fc212eb647d413850
sha512: 3cb8a141a26864b17578ac22be0032ceed55959e7a3b59517b7343128121a6f44d87554982792512b3ebc81223611741dd1649f3f87aee9360bca9aba68b57a3
ssdeep: 3072:CwBEmnWFnzBHv/xWFsg8WatP4pNAx6E14:Cw6hBHng5Ha5YKx6E1
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: emmek-http
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Microsoft
ProductVersion: 1.00
OriginalFilename: emmek-http.exe

Worm:Win32/Cambot.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusNetWorm ( 700000151 )
LionicWorm.Win32.VBNA.lnk6
Elasticmalicious (high confidence)
DrWebBackDoor.Blackshades.5
CynetMalicious (score: 100)
CAT-QuickHealTrojan.VBCrypt.MF.1942
ALYacGen:Trojan.Chinky.2
CylanceUnsafe
ZillyaWorm.VBNA.Win32.291457
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaWorm:Win32/Blocker.5326c99e
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.5e023d
SymantecW32.Cambot
ESET-NOD32a variant of Win32/Spy.VB.NXM
APEXMalicious
AvastWin32:Cambot-AN [Wrm]
ClamAVWin.Worm.Vobfus-7541859-0
KasperskyTrojan-Ransom.Win32.Blocker.bdok
BitDefenderGen:Trojan.Chinky.2
NANO-AntivirusTrojan.Win32.VB.ecatlj
MicroWorld-eScanGen:Trojan.Chinky.2
TencentWin32.Trojan.Blocker.Ecav
Ad-AwareGen:Trojan.Chinky.2
SophosMal/Generic-R + Mal/Agent-ADJ
ComodoMalware@#2e0j9tm72oyz2
BitDefenderThetaAI:Packer.21498D261C
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.VBObfus.ch
FireEyeGeneric.mg.8f2d02f5e023d1bf
EmsisoftGen:Trojan.Chinky.2 (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/VBNA.hcgx
AviraTR/Dropper.Gen
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.184DBAF
KingsoftWin32.Heur.KVM006.a.(kcloud)
MicrosoftWorm:Win32/Cambot.A
GDataGen:Trojan.Chinky.2
McAfeeArtemis!8F2D02F5E023
MAXmalware (ai score=100)
VBA32TrojanRansom.Blocker
MalwarebytesGeneric.Worm.Agent.DDS
PandaGeneric Malware
YandexTrojan.GenAsa!0lMHpjuy6LA
IkarusP2P-Worm.Win32.BlackControl
MaxSecureTrojan.Malware.1231436.susgen
FortinetW32/VBNA.BH!worm
AVGWin32:Cambot-AN [Wrm]
Paloaltogeneric.ml
Qihoo-360Win32/Worm.Cambot.HgIASOgA

How to remove Worm:Win32/Cambot.A?

Worm:Win32/Cambot.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment