Trojan

Trojan-PSW.Win32.Stealer.aema removal instruction

Malware Removal

The Trojan-PSW.Win32.Stealer.aema is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-PSW.Win32.Stealer.aema virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • Drops a binary and executes it
  • Authenticode signature is invalid
  • Created a process from a suspicious location
  • CAPE detected the DLInjector04 malware family

How to determine Trojan-PSW.Win32.Stealer.aema?


File Info:

name: 66CAFC85818AEF14CC0C.mlw
path: /opt/CAPEv2/storage/binaries/17cf9c94a974ef99acb389cf604300890b39452f014ad1af5ce658f48a57bece
crc32: 404ABA58
md5: 66cafc85818aef14cc0cb2b3d4381400
sha1: 674d9a3fd63f714976b14e75a9fc1924ed68716f
sha256: 17cf9c94a974ef99acb389cf604300890b39452f014ad1af5ce658f48a57bece
sha512: 264b1218a5462da42087974e97559d5cb54c3b817544f5803caf8189f3b3529650e7cb04ac4259b5494d9191dc61620dd21087842de2c59997a448ae76bd03b6
ssdeep: 98304:JoYNl7MmccitPq+W0W1EzL6+Hswwp2Hfpwo6k0kMx5OxFcfmQ6C8E7kYo:JTl7MDcoM0W1EvIw5Wo6kzhzTQ6Cz71o
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16D56339A6829D545EA2F7F766F7BDA25D337064416D5A2C2F1139B0F3393008BB23B90
sha3_384: ba1e52facc608c36faf27211ddc900fe67a43a7dace94e7642710eeb939955d5fd537e88ef31854ae74e3197507e9339
ep_bytes: 81ecd40200005356576a205f33db6801
timestamp: 2020-08-01 02:44:18

Version Info:

0: [No Data]

Trojan-PSW.Win32.Stealer.aema also known as:

LionicTrojan.Win32.Mokes.m!c
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen3.10810
MicroWorld-eScanDropped:Trojan.GenericKD.48162823
FireEyeGeneric.mg.66cafc85818aef14
CAT-QuickHealTrojan.Smalldownloader
ALYacDropped:Trojan.GenericKD.48162823
MalwarebytesTrojan.MalPack.GS
SangforBackdoor.Win32.Mokes.gen
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Stealer.15cda96d
BitDefenderThetaGen:NN.ZemsilF.34182.am0@aOvQ9eg
CyrenW32/Kryptik.GAL.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32multiple detections
TrendMicro-HouseCallTROJ_GEN.R002C0WAN22
ClamAVWin.Dropper.Pswtool-9857535-0
KasperskyTrojan-PSW.Win32.Stealer.aema
BitDefenderDropped:Trojan.GenericKD.48162823
NANO-AntivirusRiskware.Win32.PSWTool.hqsnsl
AvastWin32:Trojan-gen
TencentWin32.Trojan.Multiple.Wqni
EmsisoftDropped:Trojan.GenericKD.48162823 (B)
ComodoMalware@#3excwn0owlbku
TrendMicroTrojan.MSIL.ANTILOADR.SMPAO
McAfee-GW-EditionBehavesLike.Win32.HToolPassView.vc
SentinelOneStatic AI – Suspicious PE
SophosTroj/Krypt-FV
IkarusTrojan-Downloader.MSIL.Tiny
GDataWin32.Trojan-Spy.BeamLoader.ZE058G
AviraHEUR/AGEN.1144141
Antiy-AVLTrojan[Downloader]/MSIL.Tiny
KingsoftWin32.Heur.KVMH017.a.(kcloud)
ArcabitTrojan.Generic.D2DEE807
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
CynetMalicious (score: 100)
McAfeeArtemis!66CAFC85818A
VBA32TScope.Trojan.MSIL
APEXMalicious
RisingDropper.Agent/NSIS!1.D805 (CLASSIC:bWQ1Ol3tHYOBav1SRjRuIxfEruI)
MAXmalware (ai score=81)
FortinetW32/Kryptik.HOEF!tr
AVGWin32:Trojan-gen
PandaTrj/CI.A

How to remove Trojan-PSW.Win32.Stealer.aema?

Trojan-PSW.Win32.Stealer.aema removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment