Spy

About “Spyware.RozbehStealer” infection

Malware Removal

The Spyware.RozbehStealer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.RozbehStealer virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Spyware.RozbehStealer?


File Info:

name: 95CD1D400F0983E13075.mlw
path: /opt/CAPEv2/storage/binaries/b74f4970792031e4aef4b6e36a65874954ba6d9d850d03fb0d561cec842b777c
crc32: 88EE58F9
md5: 95cd1d400f0983e130758700101ab5dd
sha1: 83192d6ca0d8d4e35a8489325b71c8943e5780a8
sha256: b74f4970792031e4aef4b6e36a65874954ba6d9d850d03fb0d561cec842b777c
sha512: 4a11ff407cc807e7b01e0739d41cefccf5c40d731245b1740b04c941f2825fc09bb27e84c5577173359c5533f59cea459c25d3b6d76db45600534b25ebab1ad3
ssdeep: 12288:YSdF36fmW44vDjE4hMu60CXyoZItpjOwib6HU2hcEiP/3IWVJ/uxecO0H:YSdF36fmW0PyoZipsD/K
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11DA4D7532ACA0CF6C8A327F495872776A7389E348517CB6AA744CD3ADFA36C07D59301
sha3_384: 80785064a0976f93353709d8283a990c44bc9380b87657ea812e591eb356fe78ea4d95efc6ac10401bc4d54cd0f631d3
ep_bytes: 5589e583ec08c7042402000000ff152c
timestamp: 2022-06-25 09:03:13

Version Info:

0: [No Data]

Spyware.RozbehStealer also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.i!c
Elasticmalicious (moderate confidence)
MicroWorld-eScanTrojan.Generic.31538988
FireEyeTrojan.Generic.31538988
ALYacTrojan.Generic.31538988
CylanceUnsafe
VIPRETrojan.Generic.31538988
SangforInfostealer.Win32.Agent.Vt6e
K7AntiVirusPassword-Stealer ( 00594e481 )
BitDefenderTrojan.Generic.31538988
K7GWPassword-Stealer ( 00594e481 )
Cybereasonmalicious.ca0d8d
CyrenW32/ABPWS.MQPD-6510
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/PSW.Agent.OOY
TrendMicro-HouseCallTROJ_GEN.R03BC0PFU22
Paloaltogeneric.ml
KasperskyHEUR:Trojan-PSW.Win32.Agent.gen
AlibabaTrojanPSW:Win32/Generic.29ace036
NANO-AntivirusTrojan.Win32.Generic.jpvcdd
CynetMalicious (score: 100)
APEXMalicious
RisingStealer.Agent!8.C2 (TFE:5:dM6VaDvN8wR)
Ad-AwareTrojan.Generic.31538988
EmsisoftTrojan.Generic.31538988 (B)
ZillyaTrojan.Agent.Win32.2815884
TrendMicroTROJ_GEN.R03BC0PFU22
McAfee-GW-EditionRDN/Generic PWS.y
SophosMal/Generic-S
IkarusTrojan-PSW.Agent
JiangminTrojan.PSW.Agent.dda
AviraTR/PSW.Agent.tlqbt
Antiy-AVLTrojan/Generic.ASMalwS.720E
KingsoftWin32.PSWTroj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan-PSW.Win32.Agent.gen
GDataTrojan.Generic.31538988
GoogleDetected
AhnLab-V3Trojan/Win.PWS.R502760
McAfeeRDN/Generic PWS.y
MAXmalware (ai score=83)
MalwarebytesSpyware.RozbehStealer
PandaTrj/Chgt.AB
TencentMalware.Win32.Gencirc.11fca521
FortinetW32/PossibleThreat
AVGWin32:PWSX-gen [Trj]
AvastWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Spyware.RozbehStealer?

Spyware.RozbehStealer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment