Spy

Spyware.BTCStealer removal instruction

Malware Removal

The Spyware.BTCStealer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.BTCStealer virus can do?

  • Creates RWX memory
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Anomalous binary characteristics

How to determine Spyware.BTCStealer?


File Info:

crc32: F97D4044
md5: 9d244535c622e9b9a7659666d54f38a4
name: 9D244535C622E9B9A7659666D54F38A4.mlw
sha1: 489a85f67b43d6e3c411b581e0adbe57b7e8fba8
sha256: 62b344f25f333cb84db480466eb5eddefc0a562fc63f93cfe928cdeeddea6af6
sha512: 19608649a94cde4e32f026ce3aded46687665559cdbb3438bb19eae679dc0c5ed7a431044c308899f9cd8cc284f1961162bd9d3e0b9532bb3b8fddbc55af1051
ssdeep: 6144:BMgDS0arrQFMTTDTL++ht9G9/YzfdRAK+UduZRqRG2paPv25Mn7KmsBQ7gQ8:BZrATPhXG9qdV+TaCv25Mn7KjU
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Spyware.BTCStealer also known as:

Elasticmalicious (high confidence)
DrWebTrojan.MulDrop6.38561
MicroWorld-eScanGeneric.MSIL.Ransomware.Jigsaw.97AB8B37
FireEyeGeneric.mg.9d244535c622e9b9
ALYacGeneric.MSIL.Ransomware.Jigsaw.97AB8B37
MalwarebytesSpyware.BTCStealer
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 700000121 )
BitDefenderGeneric.MSIL.Ransomware.Jigsaw.97AB8B37
K7GWTrojan ( 700000121 )
Cybereasonmalicious.5c622e
BitDefenderThetaGen:NN.ZemsilF.34608.AmW@a0ZfZt
APEXMalicious
AvastWin32:PWSX-gen [Trj]
ClamAVWin.Trojan.SatoshiBypass-6853426-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaTrojanSpy:MSIL/CoinStealer.c2fb974e
NANO-AntivirusTrojan.Win32.Drop.edvzba
TencentMalware.Win32.Gencirc.10c9c2b5
Ad-AwareGeneric.MSIL.Ransomware.Jigsaw.97AB8B37
SophosML/PE-A + Troj/Jigsaw-K
F-SecureHeuristic.HEUR/AGEN.1132047
ZillyaTrojan.CoinStealer.Win32.991
TrendMicroRansom.MSIL.JIGSAW.SMB
McAfee-GW-EditionGenericRXBK-OL!9D244535C622
EmsisoftGeneric.MSIL.Ransomware.Jigsaw.97AB8B37 (B)
IkarusTrojan.MSIL.PSW
eGambitUnsafe.AI_Score_100%
AviraHEUR/AGEN.1132047
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftTrojanSpy:MSIL/CoinStealer.C!bit
ArcabitGeneric.MSIL.Ransomware.Jigsaw.97AB8B37
AhnLab-V3Trojan/Win32.RL_Jigsaw.C4306635
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataMSIL.Trojan.ClipBanker.C
CynetMalicious (score: 85)
ESET-NOD32a variant of MSIL/PSW.CoinStealer.AH
McAfeeGenericRXBK-OL!9D244535C622
MAXmalware (ai score=82)
VBA32Trojan.MSIL.gen.11
TrendMicro-HouseCallRansom.MSIL.JIGSAW.SMB
RisingRansom.JigsawLocker!8.52DD (C64:YzY0Osh0VGhleOze)
YandexTrojan.Agent!/6iV9/Zp3HE
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Jigsaw.K!tr
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_90% (D)
Qihoo-360HEUR/QVM03.0.24B7.Malware.Gen

How to remove Spyware.BTCStealer?

Spyware.BTCStealer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment