Spy

How to remove “Spyware:Win32/Socelars.G!MTB”?

Malware Removal

The Spyware:Win32/Socelars.G!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Spyware:Win32/Socelars.G!MTB virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Queries information on disks, possibly for anti-virtualization
  • Attempts to modify proxy settings

Related domains:

z.whorecord.xyz
a.tomx.xyz
www.ipcode.pw

How to determine Spyware:Win32/Socelars.G!MTB?


File Info:

crc32: F679C293
md5: 5d27cb7e04a67ad0aab6438a72d6eb82
name: readerpdf.exe
sha1: 3c67060bd1cdad0cad6ffcbb233cef640cff37ac
sha256: c100d2feb497c454b766fe011ea25d3fd9f99afce274d29c6e5269a1e2f5ee66
sha512: 31c9b520bdf7b1c8d8575cb87b8333ecbbaeaf42e469693306e32eca7f21a5e638240320e10ff33a491f706a0d0b13f5f7cad5a9f10b00645ecd0ac423821fea
ssdeep: 24576:UTfEWQMHi9jzdDnAdxDzdztXD67WzfbipUhi9+byncfvH8O9rB+BrsaTn+Sj9Eo8:ecW4fQlzyCfuihpbKlEe+Sj+0nB2VX
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright:
FileVersion:
CompanyName:
Comments: This installation was built with Inno Setup.
ProductName: pdfreader2019
ProductVersion: 20.01
FileDescription: pdfreader2019 Setup
OriginalFileName:
Translation: 0x0000 0x04b0

Spyware:Win32/Socelars.G!MTB also known as:

MicroWorld-eScanTrojan.GenericKD.32815205
FireEyeTrojan.GenericKD.32815205
McAfeeDropper-FWS!5D27CB7E04A6
ALYacSpyware.Socelars.gen
MalwarebytesSpyware.Socelars
VIPRETrojan.Win32.Generic!BT
AegisLabTrojan.Win32.Ekstak.4!e
SangforMalware
K7AntiVirusSpyware ( 005484541 )
BitDefenderTrojan.GenericKD.32815205
K7GWSpyware ( 005484541 )
TrendMicroTROJ_GEN.R002C0DLF19
SymantecOSX.Trojan.Gen
APEXMalicious
AvastWin32:PWSX-gen [Trj]
GDataTrojan.GenericKD.32815205
KasperskyHEUR:Trojan-PSW.Win32.Disbuk.gen
AlibabaTrojanSpy:Win32/Socelars.3a67457a
NANO-AntivirusTrojan.Win32.Stealer.glinrc
ViRobotTrojan.Win32.Z.Stealer.1884024
SophosMal/Generic-S
ComodoMalware@#1j30bjqnw3d55
F-SecureTrojan.TR/AD.DisSteal.javlv
DrWebTrojan.PWS.Stealer.27643
McAfee-GW-EditionBehavesLike.Win32.Spybot.tc
EmsisoftTrojan-Spy.Socelars (A)
IkarusTrojan-Spy.Agent
CyrenW32/Trojan.UAUN-1983
WebrootW32.Malware.gen
AviraTR/AD.DisSteal.javlv
MAXmalware (ai score=80)
ArcabitTrojan.Generic.D1F4B865
ZoneAlarmHEUR:Trojan-PSW.Win32.Disbuk.gen
MicrosoftSpyware:Win32/Socelars.G!MTB
AhnLab-V3Trojan/Win32.Disbuk.R302815
Ad-AwareTrojan.GenericKD.32815205
CylanceUnsafe
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Spy.Socelars.S
TrendMicro-HouseCallTROJ_GEN.R002C0DLF19
SentinelOneDFI – Suspicious PE
FortinetW32/Socelars.S!tr.spy
AVGWin32:PWSX-gen [Trj]
CrowdStrikewin/malicious_confidence_60% (W)
Qihoo-360Win32/Trojan.e75

How to remove Spyware:Win32/Socelars.G!MTB?

Spyware:Win32/Socelars.G!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment