spm.exe

The executable spm.exe has been detected as malware by 28 anti-virus scanners. Accoriding to the detections, it is a variant of Zbot (Zeus), a trojan that attempts to steal confidential information (online credentials, and banking details) from a compromised computer and send it to online criminals via a command-and-control server.
MD5:
a102c9b0903c4ba425b2855548ba052b

SHA-1:
8d6e79cafac0b47b2a6b98f447590535a8e0b8c7

Scanner detections:
28 / 68

Status:
Malware

Analysis date:
4/18/2024 10:15:13 AM UTC  (today)

Scan engine
Detection
Engine version

Lavasoft Ad-Aware
Trojan.GenericKD.1731620
856

AhnLab V3 Security
Dropper/Win32.Necurs
2014.07.03

Avira AntiVirus
TR/Crypt.Xpack.73455
7.11.158.30

avast!
Win32:Downloader-VMA [Trj]
2014.9-141002

AVG
SHeur4
2015.0.3334

Baidu Antivirus
Trojan.Win32.Tedroo
4.0.3.14102

Bitdefender
Trojan.GenericKD.1731620
1.0.20.1375

Comodo Security
UnclassifiedMalware
18744

Dr.Web
BackDoor.IRC.NgrBot.449
9.0.1.0275

Emsisoft Anti-Malware
Trojan.GenericKD.1731620
8.14.10.02.05

ESET NOD32
Win32/SpamTool.Tedroo.AZ
8.10034

Fortinet FortiGate
W32/Zbot.TIIW!tr
10/2/2014

F-Secure
Trojan.GenericKD.1731620
11.2014-02-10_5

G Data
Trojan.GenericKD.1731620
14.10.24

Kaspersky
Trojan-Spy.Win32.Zbot
14.0.0.3164

McAfee
Artemis!A102C9B0903C
5600.6990

Microsoft Security Essentials
Spammer:Win32/Tedroo
1.10701

MicroWorld eScan
Trojan.GenericKD.1731620
15.0.0.825

NANO AntiVirus
Trojan.Win32.Yakes.dbphmd
0.28.0.60577

Norman
Troj_Generic.UTHTT
11.20141002

Panda Antivirus
Trj/CI.A
14.10.02.05

Qihoo 360 Security
HEUR/Malware.QVM10.Gen
1.0.0.1015

Quick Heal
(Suspicious) - DNAScan
6.14.14.00

Sophos
Mal/Ransom-CR
4.98

Trend Micro House Call
TROJ_GEN.R0CBC0EFU14
7.2.275

Trend Micro
TROJ_GEN.R0CBC0EFU14
10.465.02

Vba32 AntiVirus
Malware-Cryptor.Ngrbot.gen
3.12.26.3

VIPRE Antivirus
Trojan.Win32.Generic
30890

File size:
196 KB (200,704 bytes)

File type:
Executable application (Win64 EXE)

Common path:
C:\Documents and Settings\{user}\Local settings\temporary internet files\content.ie5\{random}\spm.exe

File PE Metadata
OS bitness:
Win64

Remove spm.exe - Powered by Reason Core Security