Categories: Spy

About “Spyware.RozbehStealer” infection

The Spyware.RozbehStealer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.RozbehStealer virus can do?

  • Sample contains Overlay data
  • Authenticode signature is invalid

How to determine Spyware.RozbehStealer?


File Info:

name: 95CD1D400F0983E13075.mlwpath: /opt/CAPEv2/storage/binaries/b74f4970792031e4aef4b6e36a65874954ba6d9d850d03fb0d561cec842b777ccrc32: 88EE58F9md5: 95cd1d400f0983e130758700101ab5ddsha1: 83192d6ca0d8d4e35a8489325b71c8943e5780a8sha256: b74f4970792031e4aef4b6e36a65874954ba6d9d850d03fb0d561cec842b777csha512: 4a11ff407cc807e7b01e0739d41cefccf5c40d731245b1740b04c941f2825fc09bb27e84c5577173359c5533f59cea459c25d3b6d76db45600534b25ebab1ad3ssdeep: 12288:YSdF36fmW44vDjE4hMu60CXyoZItpjOwib6HU2hcEiP/3IWVJ/uxecO0H:YSdF36fmW0PyoZipsD/Ktype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T11DA4D7532ACA0CF6C8A327F495872776A7389E348517CB6AA744CD3ADFA36C07D59301sha3_384: 80785064a0976f93353709d8283a990c44bc9380b87657ea812e591eb356fe78ea4d95efc6ac10401bc4d54cd0f631d3ep_bytes: 5589e583ec08c7042402000000ff152ctimestamp: 2022-06-25 09:03:13

Version Info:

0: [No Data]

Spyware.RozbehStealer also known as:

Bkav W32.AIDetect.malware2
Lionic Trojan.Win32.Agent.i!c
Elastic malicious (moderate confidence)
MicroWorld-eScan Trojan.Generic.31538988
FireEye Trojan.Generic.31538988
ALYac Trojan.Generic.31538988
Cylance Unsafe
VIPRE Trojan.Generic.31538988
Sangfor Infostealer.Win32.Agent.Vt6e
K7AntiVirus Password-Stealer ( 00594e481 )
BitDefender Trojan.Generic.31538988
K7GW Password-Stealer ( 00594e481 )
Cybereason malicious.ca0d8d
Cyren W32/ABPWS.MQPD-6510
Symantec ML.Attribute.HighConfidence
ESET-NOD32 a variant of Win32/PSW.Agent.OOY
TrendMicro-HouseCall TROJ_GEN.R03BC0PFU22
Paloalto generic.ml
Kaspersky HEUR:Trojan-PSW.Win32.Agent.gen
Alibaba TrojanPSW:Win32/Generic.29ace036
NANO-Antivirus Trojan.Win32.Generic.jpvcdd
Cynet Malicious (score: 100)
APEX Malicious
Rising Stealer.Agent!8.C2 (TFE:5:dM6VaDvN8wR)
Ad-Aware Trojan.Generic.31538988
Emsisoft Trojan.Generic.31538988 (B)
Zillya Trojan.Agent.Win32.2815884
TrendMicro TROJ_GEN.R03BC0PFU22
McAfee-GW-Edition RDN/Generic PWS.y
Sophos Mal/Generic-S
Ikarus Trojan-PSW.Agent
Jiangmin Trojan.PSW.Agent.dda
Avira TR/PSW.Agent.tlqbt
Antiy-AVL Trojan/Generic.ASMalwS.720E
Kingsoft Win32.PSWTroj.Undef.(kcloud)
Microsoft Trojan:Win32/Wacatac.B!ml
ZoneAlarm HEUR:Trojan-PSW.Win32.Agent.gen
GData Trojan.Generic.31538988
Google Detected
AhnLab-V3 Trojan/Win.PWS.R502760
McAfee RDN/Generic PWS.y
MAX malware (ai score=83)
Malwarebytes Spyware.RozbehStealer
Panda Trj/Chgt.AB
Tencent Malware.Win32.Gencirc.11fca521
Fortinet W32/PossibleThreat
AVG Win32:PWSX-gen [Trj]
Avast Win32:PWSX-gen [Trj]
CrowdStrike win/malicious_confidence_100% (W)

How to remove Spyware.RozbehStealer?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Share
Published by
Paul Valéry

Recent Posts

Win32/StartPage.OUR information

The Win32/StartPage.OUR is considered dangerous by lots of security experts. When this infection is active,…

19 mins ago

How to remove “Trojan.Generic.33997309”?

The Trojan.Generic.33997309 is considered dangerous by lots of security experts. When this infection is active,…

34 mins ago

Cerbu.190164 (file analysis)

The Cerbu.190164 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Win32/Adware.Adposhel.AR information

The Win32/Adware.Adposhel.AR is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Trojan.Generic.35266640 malicious file

The Trojan.Generic.35266640 is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago

Should I remove “TrojanDownloader:Win32/Beebone.AC”?

The TrojanDownloader:Win32/Beebone.AC is considered dangerous by lots of security experts. When this infection is active,…

1 hour ago