Categories: Malware

Troj/Steale-EH removal instruction

The Troj/Steale-EH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Troj/Steale-EH virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Troj/Steale-EH?


File Info:

crc32: 36DBD573md5: e8ea6bc7445469d4983661aa9191313dname: jj.exesha1: 24eef89544e5e4ddd09b2be2a23358e9a01efe0asha256: 5ea9be9da45d91d00023e0f51b7c4d2578699886bb523017431d9cb0ad393b40sha512: d035e43d7165998661004d6f269dc7234731877338caf365c2db8c4ba1781f4ac0a8627d81d161ac7bc2b172e6eed10b0751f0b0ecbff5681b928d9961460bccssdeep: 3072:iU30zuJi/7sYopDqOmj3PrM7IknW1FT0QVqDWtc5IVlD+H+F:iU30yQ7qwj3PyIJFT1qDWt9a+Ftype: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Troj/Steale-EH also known as:

MicroWorld-eScan Gen:Variant.Razy.531330
FireEye Generic.mg.e8ea6bc7445469d4
CAT-QuickHeal Trojan.MsilFC.S8705961
Qihoo-360 Generic/Trojan.21a
McAfee GenericRXIQ-VS!E8EA6BC74454
Cylance Unsafe
VIPRE Trojan.Win32.Generic!BT
Sangfor Malware
CrowdStrike win/malicious_confidence_100% (W)
BitDefender Gen:Variant.Razy.531330
K7GW Trojan ( 0055807d1 )
K7AntiVirus Trojan ( 0055807d1 )
TrendMicro Trojan.Win32.PHOETEL.THJAFAI
F-Prot W32/Razy.DX.gen!Eldorado
Symantec Trojan Horse
APEX Malicious
Avast Win32:DropperX-gen [Drp]
GData Gen:Variant.Razy.531330
Kaspersky HEUR:Trojan.MSIL.Crypt.gen
Alibaba Trojan:Win32/Phoetel.42d7a987
NANO-Antivirus Trojan.Win32.Crypt.gcyeuc
ViRobot Trojan.Win32.S.Agent.124928.GE
AegisLab Trojan.MSIL.Crypt.4!c
Tencent Msil.Trojan.Crypt.Anpq
Ad-Aware Gen:Variant.Razy.531330
Emsisoft Gen:Variant.Razy.531330 (B)
Comodo Malware@#2ez7mnxmt1tyd
F-Secure Trojan.TR/Dropper.MSIL.Gen
DrWeb Trojan.MulDrop11.15850
Zillya Trojan.Kryptik.Win32.1788278
Invincea heuristic
McAfee-GW-Edition BehavesLike.Win32.Generic.cc
Trapmine malicious.moderate.ml.score
Sophos Troj/Steale-EH
Ikarus Trojan-Spy.Keylogger.Phoenix
Cyren W32/Trojan.TQLX-2252
Jiangmin Trojan.MSIL.oiql
Webroot W32.Trojan.Pheonixkl
Avira TR/Dropper.MSIL.Gen
MAX malware (ai score=80)
Antiy-AVL Trojan/MSIL.Crypt
Endgame malicious (high confidence)
Arcabit Trojan.Razy.D81B82
ZoneAlarm HEUR:Trojan.MSIL.Crypt.gen
Microsoft Trojan:Win32/Phoetel.ST!MTB
AhnLab-V3 Malware/Win32.RL_Generic.C3480943
Acronis suspicious
ALYac Trojan.MSIL.Crypt.gen
VBA32 TScope.Trojan.MSIL
Malwarebytes Trojan.KeyLogger.MSIL.Generic
Panda Trj/GdSda.A
ESET-NOD32 a variant of MSIL/Kryptik.SVQ
TrendMicro-HouseCall Trojan.Win32.PHOETEL.THJAFAI
Yandex Trojan.Crypt!gZOuYe6tei0
SentinelOne DFI – Malicious PE
eGambit Unsafe.AI_Score_98%
Fortinet MSIL/Kryptik.SVQ!tr
BitDefenderTheta Gen:NN.ZemsilF.34100.hiW@aOcBGki
AVG Win32:DropperX-gen [Drp]
Cybereason malicious.544e5e
Paloalto generic.ml
MaxSecure Trojan.Malware.300983.susgen

How to remove Troj/Steale-EH?

  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.
Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Recent Posts

Application.Generic.3678684 malicious file

The Application.Generic.3678684 is considered dangerous by lots of security experts. When this infection is active,…

57 mins ago

Malware.AI.1560801952 malicious file

The Malware.AI.1560801952 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago

Malware.AI.3778280684 removal tips

The Malware.AI.3778280684 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago

Should I remove “Jalapeno.777”?

The Jalapeno.777 is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago

MSIL/Kryptik.ALMH (file analysis)

The MSIL/Kryptik.ALMH is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago

Should I remove “Trojan.Win32.Agent.xbmkrx”?

The Trojan.Win32.Agent.xbmkrx is considered dangerous by lots of security experts. When this infection is active,…

3 hours ago