Malware

Troj/Steale-ANX removal

Malware Removal

The Troj/Steale-ANX is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Steale-ANX virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Troj/Steale-ANX?


File Info:

crc32: A78D101B
md5: b360f61860a20de1b7d3ab18a1f457e2
name: B360F61860A20DE1B7D3AB18A1F457E2.mlw
sha1: 0e0a6b9832a6e494889ff7e27ad44f9369b1e34d
sha256: adade973f2e00db5fa5f2a95ee4c0ad09bc59911bce11e1824cd00aafd46d531
sha512: 34c95f51edd98ba74da620680cb2bbef3e6510e1a1dd3467bb48e154f989cdc9917cdf98c544d5e6fab3196586d19b27a63ae95585a3df479b2c1eb848ab9d4b
ssdeep: 12288:vLrEioRPavZAj8M9bvr6l24XekiFhGwTt6Xxhqb:vLNoRi+j1bv94OZFAwTt6XvS
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

FileVersion: 1.0.0.0
ProductName: cwRsyncUnofficial
Translation: 0x0000 0x04e4

Troj/Steale-ANX also known as:

K7AntiVirusTrojan ( 0057d19a1 )
DrWebTrojan.PWS.Stealer.30053
CynetMalicious (score: 100)
ALYacTrojan.GenericKD.46365594
SangforBackdoor.Win32.Androm.gen
AlibabaBackdoor:Win32/Androm.5a62eac9
K7GWTrojan ( 0057d19a1 )
CyrenW32/Wacapew.O.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32MSIL/Spy.Agent.AES
APEXMalicious
AvastFileRepMalware
ClamAVWin.Malware.Filerepmetagen-9865104-0
KasperskyHEUR:Backdoor.Win32.Androm.gen
BitDefenderTrojan.GenericKD.36982247
MicroWorld-eScanTrojan.GenericKD.36982247
Ad-AwareTrojan.GenericKD.36982247
SophosTroj/Steale-ANX
ComodoTrojWare.Win32.Agent.cdzyy@0
McAfee-GW-EditionRDN/Generic.dx
FireEyeTrojan.GenericKD.36982247
EmsisoftTrojan.GenericKD.46365594 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Trojan.Gen
AviraTR/Injector.btlga
MicrosoftTrojan:Win32/Remcos.VAM!MTB
ArcabitTrojan.Generic.D2C37B9A
AegisLabTrojan.Win32.Androm.m!c
GDataTrojan.GenericKD.36982247
AhnLab-V3Trojan/Win.Generic.R422684
McAfeeRDN/Generic.dx
MAXmalware (ai score=80)
MalwarebytesTrojan.Injector
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.F0D1C00EQ21
IkarusTrojan.Inject
FortinetW32/Kryptik.EPKV!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Troj/Steale-ANX?

Troj/Steale-ANX removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment