Malware

How to remove “PWS:Win32/VidarStealer.MR!MTB”?

Malware Removal

The PWS:Win32/VidarStealer.MR!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What PWS:Win32/VidarStealer.MR!MTB virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine PWS:Win32/VidarStealer.MR!MTB?


File Info:

crc32: A37E967B
md5: e05dac87a849d5635b3aa9cb605c4685
name: E05DAC87A849D5635B3AA9CB605C4685.mlw
sha1: f88010d85033e58177dd2cf3e9c0c6574c43d9fd
sha256: 5e6bb9d357c6816c2d638af96e626fa71ec0cc151b34487dc70ec73f1ecf9b3c
sha512: 8b0fd95380053c2caf493033c27c8e0470f74f7c55bb7b350e2da0a01252052edde4122b39e5f24ffd9d992ff19b8fb27d51987a2a3cae55bbfb08b3bb523652
ssdeep: 3072:pq1OnifLyZ6ntAiXewa68YcTw5uXp5PB/J8ubw25rX/Z3lN5rq4rO0E:STL06nra68zTCy7BB8oZ/PfO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Xabitozecesaji. Pezamuhawumeb dayihariduca. Pobotiyayuta wicavakepiyepe femotofuv
InternalName: binokubino.exe
FileVersion: 28.0.0.45
Translation: 0x0409 0x04e4

PWS:Win32/VidarStealer.MR!MTB also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055b2e51 )
LionicTrojan.Win32.Upatre.a!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Stop.P6
ALYacTrojan.Ransom.Sodinokibi
CylanceUnsafe
ZillyaDownloader.Upatre.Win32.67799
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaMalware:Win32/km_2c971.None
K7GWTrojan ( 0055b2e51 )
Cybereasonmalicious.7a849d
CyrenW32/Kryptik.DMV.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GYDV
APEXMalicious
AvastWin32:TrojanX-gen [Trj]
ClamAVWin.Malware.Ulise-9855537-0
KasperskyHEUR:Trojan-PSW.Win32.Azorult.pef
BitDefenderGen:Heur.Mint.Titirez.pu0@QmKtkwk
NANO-AntivirusTrojan.Win32.Upatre.ghgrgn
MicroWorld-eScanGen:Heur.Mint.Titirez.pu0@QmKtkwk
TencentWin32.Trojan-qqpass.Qqrob.Ahej
Ad-AwareGen:Heur.Mint.Titirez.pu0@QmKtkwk
SophosMal/Generic-R + Mal/GandCrab-G
ComodoMalware@#iq31uphz7lf
BitDefenderThetaGen:NN.ZexaF.34236.pu0@amKtkwk
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.SMOKELOAD.SMC2.hp
McAfee-GW-EditionBehavesLike.Win32.VBobfus.dh
FireEyeGeneric.mg.e05dac87a849d563
EmsisoftGen:Heur.Mint.Titirez.pu0@QmKtkwk (B)
JiangminTrojanDownloader.Upatre.alav
AviraHEUR/AGEN.1102735
eGambitUnsafe.AI_Score_55%
Antiy-AVLTrojan/Generic.ASMalwS.2CF2B87
MicrosoftPWS:Win32/VidarStealer.MR!MTB
GDataGen:Heur.Mint.Titirez.pu0@QmKtkwk
AhnLab-V3Trojan/Win32.MalPe.R298432
Acronissuspicious
McAfeeGenericRXJB-XQ!E05DAC87A849
MAXmalware (ai score=89)
VBA32BScope.Trojan.Dynamer
MalwarebytesTrojan.MalPack.GS
PandaTrj/GdSda.A
TrendMicro-HouseCallTrojan.Win32.SMOKELOAD.SMC2.hp
RisingTrojan.Generic@ML.100 (RDML:bo7wpvFV5jWhdFZp9cAlZQ)
YandexTrojan.GenAsa!EThvi6unyLY
IkarusTrojan.Win32.CryptInject
MaxSecureTrojan.Malware.74652977.susgen
FortinetW32/Kryptik.GYEF!tr
AVGWin32:TrojanX-gen [Trj]
Paloaltogeneric.ml

How to remove PWS:Win32/VidarStealer.MR!MTB?

PWS:Win32/VidarStealer.MR!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment