Malware

Troj/Steal-CAF removal tips

Malware Removal

The Troj/Steal-CAF is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Steal-CAF virus can do?

  • Presents an Authenticode digital signature
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Troj/Steal-CAF?


File Info:

crc32: B7E5A2C0
md5: 2af952280c0ec3723136cfdf195a0e4f
name: 2AF952280C0EC3723136CFDF195A0E4F.mlw
sha1: 215ef3b73bc9221a84959681895f2dac9e18dad8
sha256: f657473052da6d9435ef7604646a7d027b1252ae6860a4a3bab7e791c5e41913
sha512: ae9becd575721846649a7323c35938ccf13489e338413113e26d8336b6da6eaa2d26f911ff18d8a47addd43381b187423d4dbc66b4d3a010290d8840f650ef9d
ssdeep: 12288:IkuoqUvAlwjMOIyyQnQyzbJirbbk5vuF1y:LuoaAIlQQyzd4+vu3y
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: xa9 Microsoft Corporation. All rights reserved.
Assembly Version: 5.8.0.6930
InternalName: NuGet.Versioning.dll
FileVersion: 5.8.0.6930
CompanyName: Microsoft Corporation
Comments: NuGet's implementation of Semantic Versioning.
ProductName: NuGet
ProductVersion: 5.8.0-rc.6930+830c8be45dbbccd411ecf6080abff0c2c98079cf.830c8be45dbbccd411ecf6080abff0c2c98079cf
FileDescription: NuGet.Versioning
OriginalFilename: NuGet.Versioning.dll

Troj/Steal-CAF also known as:

LionicTrojan.MSIL.Agentb.4!c
DrWebBackDoor.Remcos.336
ALYacTrojan.GenericKD.37480949
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (W)
AlibabaTrojan:MSIL/Agentb.19aed637
K7GWTrojan ( 005818e31 )
K7AntiVirusTrojan ( 005818e31 )
CyrenW32/MSIL_Troj.BLY.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of MSIL/Kryptik.ACRI
AvastWin32:DangerousSig [Trj]
CynetMalicious (score: 99)
KasperskyHEUR:Trojan.MSIL.Agentb.gen
BitDefenderTrojan.GenericKD.37480949
MicroWorld-eScanTrojan.GenericKD.37480949
TencentMalware.Win32.Gencirc.11cba750
Ad-AwareTrojan.GenericKD.37480949
SophosTroj/Steal-CAF
TrendMicroTROJ_FRS.0NA103IE21
FireEyeGeneric.mg.2af952280c0ec372
EmsisoftMalCert-S.LO (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.MSIL.agpcz
AviraTR/Kryptik.qakxj
Antiy-AVLTrojan/Generic.ASMalwS.3488D25
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Woreflint.A!cl
GridinsoftTrojan.Win32.Agent.oa!s1
ArcabitTrojan.Generic.D23BE9F5
GDataTrojan.GenericKD.37480949
AhnLab-V3Trojan/Win.Generic.C4622013
McAfeeRDN/Generic.grp
MAXmalware (ai score=85)
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.Crypt
PandaTrj/CI.A
YandexTrojan.Agentb!8hijKERRdvo
IkarusTrojan.Win32.Generic
MaxSecureTrojan.Malware.73701643.susgen
FortinetMSIL/GenCBL.ATD!tr
AVGWin32:DangerousSig [Trj]

How to remove Troj/Steal-CAF?

Troj/Steal-CAF removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment