Malware

Troj/Disteal-R removal guide

Malware Removal

The Troj/Disteal-R is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Disteal-R virus can do?

  • Dynamic (imported) function loading detected
  • .NET executable is packed/obfuscated with ConfuserExMod BedsProtector
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Anomalous .NET characteristics
  • CAPE detected the Mercurial malware family

How to determine Troj/Disteal-R?


File Info:

name: 31DED47A5555CD9F3E79.mlw
path: /opt/CAPEv2/storage/binaries/9fc5b08d6f291841ee28c7fd0d14d4f92b169f35a51efb9953bd1f727381c55d
crc32: B81D6551
md5: 31ded47a5555cd9f3e79c5f1bce62057
sha1: d059fb39c5d0c60467611c2556a883af03a2fb6f
sha256: 9fc5b08d6f291841ee28c7fd0d14d4f92b169f35a51efb9953bd1f727381c55d
sha512: bee72a9566994bf8adbfdca95f833f82fbb2fc71f4e8de20fd352910e782f75b70175d9cb7c4f4d5f0082117750a9ad1c7d6fe447a532b56bded81156c4302ae
ssdeep: 12288:/Etjr3feOfi1pWQsPsQBXJGTTQVZwmfcvVe:MtPBXJGTbmfcNe
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T170A46DE41D8D38A1D065CA379CB59E34322BAE4667FE86C79BC2F46541726C3B43B10E
sha3_384: 54580a451a3c7f906e788420b3511984d9305188e76ebdf86fe052400260e5b1912cc9651b013374552a4bc6ddf73ce9
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-01-07 13:43:15

Version Info:

Translation: 0x0000 0x04b0
FileDescription:
FileVersion: 0.0.0.0
InternalName: output.exe
LegalCopyright:
OriginalFilename: output.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

Troj/Disteal-R also known as:

LionicTrojan.Win32.Convagent.b!c
Elasticmalicious (high confidence)
FireEyeGeneric.mg.31ded47a5555cd9f
CylanceUnsafe
SangforSuspicious.Win32.Save.a
K7AntiVirusSpyware ( 0057f64b1 )
AlibabaTrojanPSW:MSIL/Perseus.70d1ddbd
K7GWSpyware ( 0057f64b1 )
Cybereasonmalicious.a5555c
CyrenW32/MSIL_Agent.BJO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Spy.Agent.DKS
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Bulz-9868353-0
KasperskyHEUR:Trojan-PSW.MSIL.Disco.gen
AvastWin32:SpywareX-gen [Trj]
SophosTroj/Disteal-R
DrWebTrojan.PWS.Stealer.31708
TrendMicroTROJ_GEN.R002C0DA822
McAfee-GW-EditionBehavesLike.Win32.Generic.gh
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan-Stealer.Cordimik.31CA09
ViRobotTrojan.Win32.Z.Atraps.493568
MicrosoftVirTool:MSIL/Perseus.AB!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4555074
McAfeeArtemis!31DED47A5555
MalwarebytesSpyware.PasswordStealer
TrendMicro-HouseCallTROJ_GEN.R002C0DA822
RisingStealer.Mercurial!1.D7B6 (CLASSIC)
YandexTrojanSpy.Agent!xSyv4l8lZyI
IkarusTrojan.ATRAPS
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/CoinMiner.CMAH!tr
BitDefenderThetaGen:NN.ZemsilF.34114.Em0@a0Ceayp
AVGWin32:SpywareX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Troj/Disteal-R?

Troj/Disteal-R removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment