Worm

Worm:Win32/Cambot.B removal instruction

Malware Removal

The Worm:Win32/Cambot.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Worm:Win32/Cambot.B virus can do?

  • Executable code extraction
  • The binary likely contains encrypted or compressed data.
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
rtrforums.com

How to determine Worm:Win32/Cambot.B?


File Info:

crc32: 1B63CCA4
md5: a6abd1fcb7bfcbce61c4edd7f496b53b
name: A6ABD1FCB7BFCBCE61C4EDD7F496B53B.mlw
sha1: c095388159b2f8711a72ce161ee2a5254a9dfc88
sha256: 3bd1ed52b57837cbc2b072c23f9de501a7d0ed5bd3ce93d3ca7022aada5ea13f
sha512: fbb78a1f92ae456ea9d57dc74ae6576224f661b10cd3339b3665a049ce7e8028cc0dce815c4c71d1bba2a6000f44105ffea10fa5151dfb1350d92cfb08b021de
ssdeep: 3072:lgLHWSnWFnzBHv/xWFsg8WatiOVWPE5ac0Jrh1NT:lgrWBHng5HaIrrh1N
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0409 0x04b0
InternalName: 483268R2
FileVersion: 1.00
CompanyName: Microsoft
ProductName: Microsoft
ProductVersion: 1.00
OriginalFilename: 483268R2.exe

Worm:Win32/Cambot.B also known as:

BkavW32.AIDetect.malware1
K7AntiVirusNetWorm ( 700000151 )
LionicTrojan.Win32.Blocker.j!c
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader4.49040
CynetMalicious (score: 100)
CAT-QuickHealTrojan.VBCrypt.MF.1942
ALYacGen:Trojan.Heur.hm0@sCH2v!li
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.34110
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.5c0969e8
K7GWNetWorm ( 700000151 )
Cybereasonmalicious.cb7bfc
SymantecW32.Cambot
ESET-NOD32a variant of Win32/Spy.VB.NXM
APEXMalicious
AvastWin32:Cambot-AN [Wrm]
ClamAVWin.Worm.Vobfus-7541859-0
KasperskyTrojan-Ransom.Win32.Blocker.blet
BitDefenderGen:Trojan.Heur.hm0@sCH2v!li
NANO-AntivirusTrojan.Win32.Blocker.ebxsyk
MicroWorld-eScanGen:Trojan.Heur.hm0@sCH2v!li
TencentWin32.Trojan.Blocker.Lnod
Ad-AwareGen:Trojan.Heur.hm0@sCH2v!li
ComodoMalware@#2awearzwcat1b
BitDefenderThetaAI:Packer.0D5DEFBA1C
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.a6abd1fcb7bfcbce
EmsisoftGen:Trojan.Heur.hm0@sCH2v!li (B)
SentinelOneStatic AI – Malicious PE
JiangminWorm/VBNA.hcgx
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.1839D35
MicrosoftWorm:Win32/Cambot.B
GDataGen:Trojan.Heur.hm0@sCH2v!li
McAfeeGenericRXAA-AA!A6ABD1FCB7BF
MAXmalware (ai score=100)
VBA32TrojanRansom.Blocker
MalwarebytesGeneric.Worm.Agent.DDS
PandaGeneric Malware
YandexTrojan.GenAsa!0lMHpjuy6LA
IkarusP2P-Worm.Win32.BlackControl
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/VBNA.BH!worm
AVGWin32:Cambot-AN [Wrm]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Blocker.HgIASOQA

How to remove Worm:Win32/Cambot.B?

Worm:Win32/Cambot.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment