Malware

Troj/Steale-EH removal instruction

Malware Removal

The Troj/Steale-EH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Steale-EH virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Steale-EH?


File Info:

crc32: 36DBD573
md5: e8ea6bc7445469d4983661aa9191313d
name: jj.exe
sha1: 24eef89544e5e4ddd09b2be2a23358e9a01efe0a
sha256: 5ea9be9da45d91d00023e0f51b7c4d2578699886bb523017431d9cb0ad393b40
sha512: d035e43d7165998661004d6f269dc7234731877338caf365c2db8c4ba1781f4ac0a8627d81d161ac7bc2b172e6eed10b0751f0b0ecbff5681b928d9961460bcc
ssdeep: 3072:iU30zuJi/7sYopDqOmj3PrM7IknW1FT0QVqDWtc5IVlD+H+F:iU30yQ7qwj3PyIJFT1qDWt9a+F
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Troj/Steale-EH also known as:

MicroWorld-eScanGen:Variant.Razy.531330
FireEyeGeneric.mg.e8ea6bc7445469d4
CAT-QuickHealTrojan.MsilFC.S8705961
Qihoo-360Generic/Trojan.21a
McAfeeGenericRXIQ-VS!E8EA6BC74454
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderGen:Variant.Razy.531330
K7GWTrojan ( 0055807d1 )
K7AntiVirusTrojan ( 0055807d1 )
TrendMicroTrojan.Win32.PHOETEL.THJAFAI
F-ProtW32/Razy.DX.gen!Eldorado
SymantecTrojan Horse
APEXMalicious
AvastWin32:DropperX-gen [Drp]
GDataGen:Variant.Razy.531330
KasperskyHEUR:Trojan.MSIL.Crypt.gen
AlibabaTrojan:Win32/Phoetel.42d7a987
NANO-AntivirusTrojan.Win32.Crypt.gcyeuc
ViRobotTrojan.Win32.S.Agent.124928.GE
AegisLabTrojan.MSIL.Crypt.4!c
TencentMsil.Trojan.Crypt.Anpq
Ad-AwareGen:Variant.Razy.531330
EmsisoftGen:Variant.Razy.531330 (B)
ComodoMalware@#2ez7mnxmt1tyd
F-SecureTrojan.TR/Dropper.MSIL.Gen
DrWebTrojan.MulDrop11.15850
ZillyaTrojan.Kryptik.Win32.1788278
Invinceaheuristic
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
Trapminemalicious.moderate.ml.score
SophosTroj/Steale-EH
IkarusTrojan-Spy.Keylogger.Phoenix
CyrenW32/Trojan.TQLX-2252
JiangminTrojan.MSIL.oiql
WebrootW32.Trojan.Pheonixkl
AviraTR/Dropper.MSIL.Gen
MAXmalware (ai score=80)
Antiy-AVLTrojan/MSIL.Crypt
Endgamemalicious (high confidence)
ArcabitTrojan.Razy.D81B82
ZoneAlarmHEUR:Trojan.MSIL.Crypt.gen
MicrosoftTrojan:Win32/Phoetel.ST!MTB
AhnLab-V3Malware/Win32.RL_Generic.C3480943
Acronissuspicious
ALYacTrojan.MSIL.Crypt.gen
VBA32TScope.Trojan.MSIL
MalwarebytesTrojan.KeyLogger.MSIL.Generic
PandaTrj/GdSda.A
ESET-NOD32a variant of MSIL/Kryptik.SVQ
TrendMicro-HouseCallTrojan.Win32.PHOETEL.THJAFAI
YandexTrojan.Crypt!gZOuYe6tei0
SentinelOneDFI – Malicious PE
eGambitUnsafe.AI_Score_98%
FortinetMSIL/Kryptik.SVQ!tr
BitDefenderThetaGen:NN.ZemsilF.34100.hiW@aOcBGki
AVGWin32:DropperX-gen [Drp]
Cybereasonmalicious.544e5e
Paloaltogeneric.ml
MaxSecureTrojan.Malware.300983.susgen

How to remove Troj/Steale-EH?

Troj/Steale-EH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment