Malware

Troj/Steal-IS information

Malware Removal

The Troj/Steal-IS is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Steal-IS virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Steals private information from local Internet browsers
  • Network activity detected but not expressed in API logs
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed mail clients

How to determine Troj/Steal-IS?


File Info:

crc32: 1A9F3E2A
md5: 55a6373881e1775a5ec1cd882940bbd7
name: elb.exe
sha1: bec8538ca443a5d82ad870dd6efa4421573c8949
sha256: 1e4c34728a0399f0ecac88c0f25d48442dba2816dee44134cf2deaa0e9ecc2ac
sha512: 61e6c4e818eb589f1f3abaaf085c7053e47eadbf950699ff877e8d0304df2210510196ee9b7557155554bf6fd63eae678475f28730f31d78a8e9ac27daf1c297
ssdeep: 6144:DQNcN6vNNOdKi6hQF/1o2yo84jVMq2UNxI/qZ5bcmoKTV:DQ+6O62/1XyANA4oKTV
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: jpFrMqAAxrhEMYcRyoonzcQkJlPjMAUWFzOH.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: jpFrMqAAxrhEMYcRyoonzcQkJlPjMAUWFzOH.exe

Troj/Steal-IS also known as:

DrWebTrojan.PWS.AgenslaNET.1
MicroWorld-eScanGen:Variant.Razy.577898
FireEyeGeneric.mg.55a6373881e1775a
McAfeeArtemis!55A6373881E1
MalwarebytesSpyware.PasswordStealer
SangforMalware
BitDefenderGen:Variant.Razy.577898
Cybereasonmalicious.881e17
TrendMicroTROJ_FRS.0NA103C620
BitDefenderThetaAI:Packer.137CC4BF20
CyrenW32/MSIL_Troj.RC.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Packed.Razy-7426372-0
KasperskyHEUR:Trojan-PSW.MSIL.Agensla.a
AlibabaTrojan:Win32/thief.ali2000020
AegisLabTrojan.MSIL.Agensla.i!c
RisingSpyware.AgentTesla!1.B864 (CLOUD)
Ad-AwareGen:Variant.Razy.577898
SophosTroj/Steal-IS
F-SecureTrojan.TR/Spy.Gen8
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
Trapminemalicious.high.ml.score
EmsisoftTrojan-Spy.Agent (A)
IkarusWorm.MSIL.Autorun
GDataGen:Variant.Razy.577898
eGambitUnsafe.AI_Score_100%
AviraTR/Spy.Gen8
MicrosoftBackdoor:MSIL/Remcos!MTB
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D8D16A
ZoneAlarmHEUR:Trojan-PSW.MSIL.Agensla.a
AhnLab-V3Trojan/Win32.AgentTesla.C3450450
ALYacGen:Variant.Razy.577898
MAXmalware (ai score=84)
ESET-NOD32a variant of MSIL/Autorun.Spy.Agent.DF
TrendMicro-HouseCallTROJ_FRS.0NA103C620
TencentWin32.Trojan.Spy.Swla
SentinelOneDFI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Agent.AES!tr.spy
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM03.0.B625.Malware.Gen

How to remove Troj/Steal-IS?

Troj/Steal-IS removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment