Malware

Troj/Steal-AKS malicious file

Malware Removal

The Troj/Steal-AKS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Steal-AKS virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz

How to determine Troj/Steal-AKS?


File Info:

crc32: B3E45541
md5: f5e39324c5f457debfc29d337e8a892d
name: upload_file
sha1: 54916645656654d286fe5274a7015c1e95e59e57
sha256: c236cbc67f0375086f8b217b917cd5dfd5932e811f29a2b7cbf5cd29f2bab338
sha512: 8e5048f5e33c5a1ed7d80cd731b0c4bd66b479e15fe806adf44548b48e93e3ff2609c7dcdf1fdea2a3b0f0491444df40ada32cf0249b8d2c0df968014c10c879
ssdeep: 12288:k0KXCFUOY2H4VRUW8t8vR22rWLqjYNo1U0Vdpxhbl4oJ1R++qa:cXChY2Hi98tRNYU0VdzRtB
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Physical distancing (C) rights reserved
Assembly Version: 7.2.0.3
InternalName: n7XTtepwZbKqNRtYltIwgBQrhcyLfpp33.exe
FileVersion: 7.6.0.71
CompanyName: Physical distancing
LegalTrademarks:
Comments: Radisson Blu
ProductName: Radisson
ProductVersion: 7.6.0.71
FileDescription: Radisson
OriginalFilename: n7XTtepwZbKqNRtYltIwgBQrhcyLfpp33.exe

Troj/Steal-AKS also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.34375783
FireEyeGeneric.mg.f5e39324c5f457de
CAT-QuickHealBackdoor.MSIL
ALYacTrojan.GenericKD.34375783
CylanceUnsafe
AegisLabTrojan.Win32.Generic.m7QV
SangforMalware
K7AntiVirusTrojan ( 0056caea1 )
BitDefenderTrojan.GenericKD.34375783
K7GWTrojan ( 0056caea1 )
Cybereasonmalicious.565665
Invinceaheuristic
CyrenW32/MSIL_Kryptik.BKR.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
KasperskyHEUR:Backdoor.MSIL.Remcos.gen
AlibabaBackdoor:MSIL/NanoBot.77eba9ac
NANO-AntivirusTrojan.Win32.Remcos.hsfjla
ViRobotTrojan.Win32.S.Agent.612352.BB
RisingBackdoor.Remcos!8.B89E (CLOUD)
Ad-AwareTrojan.GenericKD.34375783
ComodoTrojWare.Win32.Genome.agent@0
F-SecureTrojan.TR/AD.AgentTesla.wfftk
DrWebBackDoor.SpyBotNET.25
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_FRS.VSNTHH20
SophosTroj/Steal-AKS
IkarusTrojan.MSIL.Inject
WebrootW32.Trojan.Gen
AviraTR/AD.AgentTesla.wfftk
MAXmalware (ai score=88)
Antiy-AVLTrojan[Spy]/MSIL.Agent
MicrosoftTrojan:MSIL/NanoBot.D!MTB
ArcabitTrojan.Generic.D20C8867
ZoneAlarmHEUR:Backdoor.MSIL.Remcos.gen
GDataTrojan.GenericKD.34375783
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Kryptik.R348110
McAfeeRDN/Generic BackDoor
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.MalPack.PNG.Generic
ESET-NOD32MSIL/Spy.Agent.AES
TrendMicro-HouseCallTROJ_FRS.VSNTHH20
TencentMsil.Backdoor.Remcos.Efkl
SentinelOneDFI – Malicious PE
FortinetW32/Remcos.EQMU!tr.bdr
BitDefenderThetaGen:NN.ZemsilF.34196.Lm0@am17VIk
AVGWin32:TrojanX-gen [Trj]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
Qihoo-360Generic/Backdoor.23a

How to remove Troj/Steal-AKS?

Troj/Steal-AKS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment