Spy

Spyware.SurferStealer malicious file

Malware Removal

The Spyware.SurferStealer is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.SurferStealer virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • At least one process apparently crashed during execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Authenticode signature is invalid
  • Detects Avast Antivirus through the presence of a library
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library

How to determine Spyware.SurferStealer?


File Info:

name: 4C862C4D4C56371B3690.mlw
path: /opt/CAPEv2/storage/binaries/430e2671c0778a1790a68c72670b6f0c9e7562757b13b1d35f375cadb4bae502
crc32: 3D6CD2B6
md5: 4c862c4d4c56371b3690f9e5bd0bf7b4
sha1: d18e722e82742aa16d93b121c0ed8e0afd921235
sha256: 430e2671c0778a1790a68c72670b6f0c9e7562757b13b1d35f375cadb4bae502
sha512: 150913575fc4e359f809e06eb2e5fb546328b2fd0d67a004988da7d71c6f5cb5399f9c601354ea234f04425183388fbeb487a2b5fe4788804202b9487232f487
ssdeep: 49152:iRDnyEMjU68nJrYFMidUSs3BJOm1Q14U9dsfYd/zVv:iW4HJGMid8RJm9dSa/
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1F4B58E81BAC29030F4E715B1C9BBAE668CADBF30A73288DB6690157505311C255FFFDA
sha3_384: c95cf4ee8ca48b662ad963eccf2b0d8a262481996c4687e6c5f278f0033646256405efe19d9108e8a39b0e2019e4190a
ep_bytes: e83b0b0000e974feffffe8220000006a
timestamp: 2022-07-07 21:29:21

Version Info:

0: [No Data]

Spyware.SurferStealer also known as:

LionicTrojan.Win32.Mansabo.4!c
MicroWorld-eScanGen:Variant.Fragtor.115056
FireEyeGen:Variant.Fragtor.115056
McAfeeArtemis!4C862C4D4C56
SangforTrojan.Win32.Save.a
K7AntiVirusRiskware ( 0040eff71 )
K7GWRiskware ( 0040eff71 )
SymantecTrojan.Gen.2
TrendMicro-HouseCallTROJ_GEN.R002H0CGC22
KasperskyHEUR:Trojan.Win32.Mansabo.gen
BitDefenderGen:Variant.Fragtor.115056
AvastWin32:TrojanX-gen [Trj]
Ad-AwareGen:Variant.Fragtor.115056
EmsisoftGen:Variant.Fragtor.115056 (B)
VIPREGen:Variant.Fragtor.115056
McAfee-GW-EditionArtemis
GDataGen:Variant.Fragtor.115056
JiangminTrojan.Mansabo.civ
Antiy-AVLTrojan/Generic.ASMalwS.4CF1
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.TrojanX-gen.C5199110
ALYacGen:Variant.Fragtor.115056
MalwarebytesSpyware.SurferStealer
RisingTrojan.Generic@AI.87 (RDML:SeXWkDlV+jcnS+Ds+BSUEg)
MAXmalware (ai score=87)
FortinetW32/PossibleThreat
AVGWin32:TrojanX-gen [Trj]

How to remove Spyware.SurferStealer?

Spyware.SurferStealer removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment