Malware

Troj/Steal-ATD removal instruction

Malware Removal

The Troj/Steal-ATD is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Steal-ATD virus can do?

  • Attempts to connect to a dead IP:Port (2 unique times)
  • Presents an Authenticode digital signature
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Attempts to mimic the file extension of a JPEG image by having ‘jpeg’ in the file name.
  • Performs some HTTP requests
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

How to determine Troj/Steal-ATD?


File Info:

crc32: 99BDCAD2
md5: 60b5b7daf32a4f42c77eac89944cbed9
name: my photo jpeg jpeg.exe
sha1: ac4250e1fee56926ccfb4f4eb478ddfb531033fc
sha256: a85887d85d64f107d3801b3f7cd65b4d2e3d7ff742543162a8f087e52dac6607
sha512: 67bb5c75fe52f2027f1f4bfd9077ef40c4fb783f92fbfc90f6a1c5aeef3601758ab15efae977238bd3f8dfb03c213a049bc392e3ca0ba6b1424215f680ce2600
ssdeep: 1536:6psgVDfSy/0X81LuZ+NGp+UERLRsgy6nTnYZAIgKoPtUVv6Ufb:6/dKe0MtNGwUYL5y6TYZAIgKoPtUVvp
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

LegalCopyright: x928x93fx916x930 (C) 2020
Assembly Version: 4.0.4.21
FileVersion: 4.0.4.2145
CompanyName: x928jjc
LegalTrademarks: x915x93ex92cx93fx932
Comments: x95bx93fx928x94dx926x917x940tyr
ProductName: x924x942x95ex93ex928
ProductVersion: 4.0.4.21
FileDescription: x924x942x95ex93ex928jjt
OriginalFilename: x924x942x95ex93ex928.exe
Translation: 0x0409 0x0514

Troj/Steal-ATD also known as:

DrWebTrojan.Siggen10.36641
MicroWorld-eScanTrojan.GenericKD.44045012
FireEyeGeneric.mg.60b5b7daf32a4f42
ALYacTrojan.GenericKD.44045012
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 00570dbc1 )
BitDefenderTrojan.GenericKD.44045012
K7GWTrojan-Downloader ( 00570dbc1 )
InvinceaMal/Generic-R + Troj/Steal-ATD
CyrenW32/Trojan.WFOG-4054
SymantecML.Attribute.HighConfidence
TrendMicro-HouseCallTROJ_GEN.R03BC0RJF20
AvastWin32:DangerousSig [Trj]
AlibabaTrojan:MSIL/rwtjm.21490fab
Ad-AwareTrojan.GenericKD.44045012
SophosTroj/Steal-ATD
ComodoMalware@#31x0cif4zvygx
TrendMicroTROJ_GEN.R03BC0RJF20
McAfee-GW-EditionArtemis!Trojan
EmsisoftTrojan.GenericKD.44045012 (B)
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.108317594.susgen
AviraTR/Dldr.Agent.rwtjm
MicrosoftTrojan:Win32/Ymacco.AA8D
ArcabitTrojan.Generic.D2A012D4
GDataTrojan.GenericKD.44045012
McAfeeArtemis!60B5B7DAF32A
MAXmalware (ai score=89)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Downloader
ESET-NOD32MSIL/TrojanDownloader.Agent.GWL
IkarusTrojan-Downloader.MSIL.Agent
FortinetMSIL/Agent.GWL!tr.dldr
AVGWin32:DangerousSig [Trj]
Qihoo-360Trojan.Generic

How to remove Troj/Steal-ATD?

Troj/Steal-ATD removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment