Malware

Should I remove “Troj/Steal-AVI”?

Malware Removal

The Troj/Steal-AVI is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Steal-AVI virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

How to determine Troj/Steal-AVI?


File Info:

crc32: 8A3BCA46
md5: b78ee5b1c57bfc3cf49cc98d885b368d
name: B78EE5B1C57BFC3CF49CC98D885B368D.mlw
sha1: 9fdfa9e012e482601ed130634166e736a51e949d
sha256: 1348337fc31a0e54ea9a7d98fa5dd49a19f895294292a72c84d4af1b60d49eab
sha512: 3a3bb06a514e90839d16d08c448d6e3e3aaf58c4456f394b2d857fba978ed99354ec37c64c6fa5aa6d7aeb524cbdbd59fff520c2452bbec0857f9ccf2dd04c70
ssdeep: 6144:gJGltNpeapUqp9lL3sRP6gKxpE6Ja9FW4ztsNctHjNRdBHMlU8LF:m2aqt8Rt6JadWeNt8LF
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2011 - 2020
Assembly Version: 4.0.2.0
InternalName: x6a9x6b5.exe
FileVersion: 4.0.2.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: Space Invaders
ProductVersion: 4.0.2.0
FileDescription: Space Invaders
OriginalFilename: x6a9x6b5.exe

Troj/Steal-AVI also known as:

Elasticmalicious (high confidence)
DrWebTrojan.Inject4.4796
MicroWorld-eScanTrojan.GenericKD.35176657
FireEyeGeneric.mg.b78ee5b1c57bfc3c
CAT-QuickHealTrojan.Multi
Qihoo-360Generic/Backdoor.9cf
ALYacTrojan.GenericKD.35176657
MalwarebytesTrojan.MalPack
VIPRETrojan.Win32.Generic!BT
SangforMalware
K7AntiVirusRiskware ( 0040eff71 )
BitDefenderTrojan.GenericKD.35176657
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.012e48
TrendMicroBackdoor.MSIL.REMCOS.SM
BitDefenderThetaGen:NN.ZemsilF.34634.Cm0@aavZK!g
CyrenW32/MSIL_Kryptik.CDG.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Taskun-9791093-0
KasperskyHEUR:Backdoor.MSIL.Androm.gen
AlibabaBackdoor:MSIL/Androm.4bd8dfa2
AegisLabTrojan.Multi.Generic.4!c
AvastWin32:MalwareX-gen [Trj]
Ad-AwareTrojan.GenericKD.35176657
SophosTroj/Steal-AVI
ComodoMalware@#3tj1o49iir4t3
ZillyaTrojan.Kryptik.Win32.2638883
InvinceaMal/Generic-R + Troj/Steal-AVI
McAfee-GW-EditionBehavesLike.Win32.Generic.gc
EmsisoftTrojan.GenericKD.35176657 (B)
IkarusTrojan.MSIL.Inject
WebrootW32.Trojan.Gen
GridinsoftTrojan.Win32.Downloader.oa
ZoneAlarmHEUR:Backdoor.MSIL.Androm.gen
GDataTrojan.GenericKD.35176657
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.RL_Possible_smremcos.C4224625
McAfeePWS-FCSU!B78EE5B1C57B
MAXmalware (ai score=84)
VBA32TScope.Trojan.MSIL
ZonerTrojan.Win32.98148
ESET-NOD32a variant of MSIL/Kryptik.YPD
TrendMicro-HouseCallBackdoor.MSIL.REMCOS.SM
TencentWin32.Trojan.Inject.Auto
YandexTrojan.Igent.bUMYhO.11
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_85%
FortinetMSIL/GenKryptik.EWCI!tr
AVGWin32:MalwareX-gen [Trj]
PandaTrj/GdSda.A
MaxSecureTrojan.Malware.300983.susgen

How to remove Troj/Steal-AVI?

Troj/Steal-AVI removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment