Spy

Spyware.Taurus information

Malware Removal

The Spyware.Taurus is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.Taurus virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Collects information about installed applications
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Spyware.Taurus?


File Info:

crc32: C7E12BA4
md5: 4141eca3c3f8fef9dd9386f5a97d1730
name: file0.exe
sha1: 0dcdf961da9fe9e4b3e1e70895a9e3bea43b8487
sha256: e5d73714c09ee0fe864523ce30b3bd1a77190adedd278861df0a3ba22bea2d9f
sha512: 9653de22a4a22e53e5c76a62dbcdfd1e67c40e61d172b085afd1bdd4e14505e70726a4a452f78865a8e2f0e7cda2589de65cd580749488758b8e39ce733e923a
ssdeep: 12288:qR7dtc1O3OkzOISVUQdnA5320udekj0I1y3dsz2+L/LAYaGDlK:qnu1jdIEHd0udekQrsS+LkYPxK
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Spyware.Taurus also known as:

BkavW32.AIDetectVM.malware2
MicroWorld-eScanGen:Variant.Razy.668796
BitDefenderThetaGen:NN.ZexaF.34108.1yW@aCb4q8ji
McAfeeRDN/Generic PWS.y
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusTrojan ( 0056687a1 )
BitDefenderGen:Variant.Razy.668796
K7GWTrojan ( 0056687a1 )
Cybereasonmalicious.1da9fe
ArcabitTrojan.Razy.DA347C
TrendMicroTrojan.Win32.MALREP.THEACBO
CyrenW32/Trojan.GUAI-7712
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:DangerousObject.Multi.Generic
AlibabaTrojan:Win32/Kryptik.e2833177
ViRobotTrojan.Win32.S.Agent.876032.JD
AegisLabTrojan.Win32.Razy.4!c
Endgamemalicious (high confidence)
SophosMal/Generic-S
ComodoMalware@#qhqejm2nej15
F-SecureTrojan.TR/Kryptik.pswtj
DrWebTrojan.Carberp.1985
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.ct
Trapminemalicious.moderate.ml.score
FireEyeGeneric.mg.4141eca3c3f8fef9
EmsisoftGen:Variant.Razy.668796 (B)
SentinelOneDFI – Malicious PE
AviraTR/Kryptik.pswtj
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.Occamy
MicrosoftTrojan:Win32/Occamy.C
ZoneAlarmUDS:DangerousObject.Multi.Generic
GDataGen:Variant.Razy.668796
Acronissuspicious
ALYacGen:Variant.Razy.668796
MAXmalware (ai score=100)
VBA32BScope.TrojanPSW.IBank.1512
MalwarebytesSpyware.Taurus
ESET-NOD32a variant of Win32/Kryptik.HDHO
TrendMicro-HouseCallTrojan.Win32.MALREP.THEACBO
RisingTrojan.GenKryptik!8.AA55 (CLOUD)
IkarusWin32.Outbreak
FortinetW32/GenKryptik.EKJE!tr
Ad-AwareGen:Variant.Razy.668796
AVGWin32:Trojan-gen
AvastWin32:Trojan-gen
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/HEUR/QVM20.1.2AE5.Malware.Gen

How to remove Spyware.Taurus?

Spyware.Taurus removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment