Spy

Spyware.TheRat removal tips

Malware Removal

The Spyware.TheRat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware.TheRat virus can do?

  • Executable code extraction
  • Presents an Authenticode digital signature
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Spyware.TheRat?


File Info:

crc32: FB6681CE
md5: 92c266fc98140a485fb46d6cc41fc0fc
name: upload_file
sha1: cea7b67cf82c69105d34d18d8bdecc4f48ee33a7
sha256: 02d3e29c37af562636fd0020a6c586711fbbab3838a82dbd25987d14ed919c65
sha512: fbcc1ce06a6bc18fa0358cce2fc76ecb95cf9c1f839783c422e709f0c0e2e628f47728836693658a7fd64749f15ae9cc1e98c6eb8393a7476a4caeec24230119
ssdeep: 98304:RFz6qyJPDyKb1je7147wOzAjKrZv5RLHqUi9pHLt8kcqFX9t:rujPDyCxecwyAe95S9ZTcqbt
type: PE32 executable (GUI) Intel 80386, for MS Windows, InnoSetup self-extracting archive

Version Info:

LegalCopyright: Copyright xa9 2018 Stratis Group
InternalName: Breeze Wallet
FileVersion: 1.0.1.178
CompanyName: Stratis Group
SquirrelAwareVersion: 1
ProductName: Breeze Wallet
ProductVersion: 1.0.1.178
FileDescription: Breeze Wallet
OriginalFilename:
Translation: 0x0409 0x04b0

Spyware.TheRat also known as:

MicroWorld-eScanTrojan.GenericKD.44067879
FireEyeTrojan.GenericKD.44067879
CAT-QuickHealTrojan.Multi
McAfeeArtemis!92C266FC9814
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 005707621 )
BitDefenderTrojan.GenericKD.44067879
K7GWTrojan ( 005707621 )
TrendMicroTROJ_GEN.R002C0GJE20
SymantecTrojan.Gen.2
AvastWin32:Trojan-gen
KasperskyTrojan-Spy.Win32.TheRat.jp
AlibabaTrojanSpy:Win32/TheRat.bc5d33ae
NANO-AntivirusTrojan.Win32.TheRat.hyteaj
Ad-AwareTrojan.GenericKD.44067879
EmsisoftTrojan.GenericKD.44067879 (B)
F-SecureTrojan.TR/Spy.Agent.psxqz
DrWebTrojan.Siggen10.34000
InvinceaMal/Generic-S
McAfee-GW-EditionArtemis!Trojan
SophosMal/Generic-S
IkarusTrojan.Spy.Agent
JiangminTrojanSpy.TheRat.cl
AviraTR/Spy.Agent.psxqz
MAXmalware (ai score=90)
MicrosoftPUA:Win32/Presenoker
ArcabitTrojan.Generic.D2A06C27
ZoneAlarmTrojan-Spy.Win32.TheRat.jp
GDataTrojan.GenericKD.44067879
ALYacTrojan.GenericKD.44067879
VBA32Adware.Presenoker
MalwarebytesSpyware.TheRat
PandaTrj/CI.A
ESET-NOD32a variant of Generik.GMNATQM
TrendMicro-HouseCallTROJ_GEN.R002C0GJE20
TencentWin32.Trojan.Falsesign.Htvm
YandexTrojan.Igent.bUzNOx.21
eGambitPE.Heur.InvalidSig
FortinetPossibleThreat.MU
WebrootW32.Adware.Gen
AVGWin32:Trojan-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Spy.5d1

How to remove Spyware.TheRat?

Spyware.TheRat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment